SQLi part 6: Out-of-band SQLi

Out-of-band SQL injection is not very common, mostly because it depends on features being enabled on the database server being used by the web application. Out-of-band SQL injection occurs when an attacker is unable to use the same channel to launch the attack and gather results.

Out-of-band techniques, offer an attacker an alternative to inferential time-based techniques, especially if the server responses are not very stable (making an inferential time-based attack unreliable).

Out-of-band SQLi techniques would rely on the database server’s ability to make DNS or HTTP requests to deliver data to an attacker. Such is the case with Microsoft SQL Server’s xp_dirtree command, which can be used to make DNS requests to a server an attacker controls; as well as Oracle Database’s UTL_HTTP package, which can be used to send HTTP requests from SQL and PL/SQL to a server an attacker controls.

Read Part 1 in the Series: SQLi: How it works

Read Part 2 in the Series: What’s the worst an attacker can do with SQL?

Read Part 3 in the Series: The anatomy of an SQL Injection attack

Read Part 4 in the Series: In-band SQLi (Classic SQLi)

Read Part 5 in the Series: SQLi part 5: Inferential SQLi (Blind SQLi)

Share this post

Leave a Reply

Your email address will not be published.