Database Security. Database Auditing. Database Caching. Database Masking. Get it nowBypassed..
Posted January 20th, 2009 by eltan
in
Another easy bypass to share:
user: any
password: foo') or name=concat('ad','min
G
Comments
ummm.. looking at the forum,
ummm.. looking at the forum, it seems it's not a 'new' subject.. this query looks like legitimate query..
So I'd better use whitelist.
Hello Eltan You are right.
Hello Eltan
You are right. You need to use firewall mode to cope with such queries.
Best regards,
Yuli