Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

Advanced MSSQL Injection Tricks

Summary

A collection of advanced MSSQL injection techniques tested on SQL Server 2019/2017/2016SP2: DNS out-of-band exfiltration via fn_xe_file_target_read_file and friends, WAF-bypassing error-based vectors, single-query table dumps with FOR JSON, and local file reads via OpenRowset.
Published
Collected

original ↗

Related coverage

back