By Matt Hines
Excerpt:
“The affable researcher's approach -- a proof-of-concept exercise that allows an attacker to extract private data from a database by performing mere record insertion operations -- is a pretty interesting, and fairly low-tech example of how someone can potentially scoop credit card numbers or passwords from a commercially-available database by using not much more than their own smarts and a little technical footwork …
“Carried out successfully thus far in Core's labs against a MySQL database, Waissbein said that the company is currently testing the same technique against popular Oracle and Microsoft databases, among others, to see if it will work, but he said he thinks it should.”
Source: InfoWorld.com











