Core Security
info@coresecurity.com  | +1.617.399.6980 | Contact Us   Core Blog Core Blog Twitter LinkedIn youtube
News
SHARE
Countdown to database timing attacks

By Matt Hines

Excerpt:

“The affable researcher's approach -- a proof-of-concept exercise that allows an attacker to extract private data from a database by performing mere record insertion operations -- is a pretty interesting, and fairly low-tech example of how someone can potentially scoop credit card numbers or passwords from a commercially-available database by using not much more than their own smarts and a little technical footwork …

“Carried out successfully thus far in Core's labs against a MySQL database, Waissbein said that the company is currently testing the same technique against popular Oracle and Microsoft databases, among others, to see if it will work, but he said he thinks it should.”

Source: InfoWorld.com

View the full article

Related Content