Bug Bounty Hunting Essentials
上QQ阅读APP看书,第一时间看更新

Out-of-band SQLi

Out-of-band SQLi attacks rely on the DBMS's capability to perform DNS or HTTP requests to deliver the data to the attacker. It is usually used with MS SQL server commands, which are normally used to make DNS requests, and Oracle DB, which sends HTTP requests.