Information Systems Auditing

A collection of links, documents, and thoughts of a State IS auditor.

SQLNINJA: SQL Injection

without comments

On a recent pentest I was able to use SQLNINJA to exploit a SQL Injection vulnerability I had identified.  I documented the steps I took so that future auditors can take advantage of this tool.  Check out the tutorial here.

Written by admin

June 4th, 2009 at 7:54 am

Posted in Uncategorized

Leave a Reply