RE: SQL Smuggling

2008-09-11 Thread Gary Oleary-Steele
+ URI.escape(c) end end return newstr end print Enter string to URL Unicode: puts unicode_url(gets) From: Tim [EMAIL PROTECTED] Sent: 10 September 2008 00:34 To: [EMAIL PROTECTED] Cc: bugtraq@securityfocus.com Subject: Re: SQL Smuggling

Re: SQL Smuggling

2008-09-10 Thread Tim
We released a research paper a few months ago, regarding a sub-class of SQL Injection that has not received attention till now. The crux is that when it comes to SQLi, protection and detection do not typically take the architecture into account; this can allow smuggling attacks which are not