SQL Injection Probing Methodology for Analysts

Lab Flask+SQLite app: concatenated vs parameterized queries, SQL logs, WAF noise, ASAN-irrelevant crash on the concat path — no production DB dump.

February 18, 2020 · 6 min · 1215 words · Jose Adalberto Gutierrez Ochoa