Extracting the data from the database

Most of the leaked online passwords are done through this kind of attack. If you encounter this vulnerability during your pentests then it means you just hit the jackpot. The idea here is to be able to execute the famous query:

select * from users

Assuming that the database has a users table, this query will extract all the user's records from the database. It's like Christmas day; you're going to have all the usernames and passwords in a wrapped gift.

..................Content has been hidden....................

You can't read the all page of ebook, please click here login for view all page.
Reset
3.138.138.144