|
|
Choosing A Webhost: |
Re: New builds posted to jdbc.postgresql.org websit for jdbc driver: msg#00389db.postgresql.jdbc
Oliver Jowett <oliver@xxxxxxxxxxxxx> writes: > On Wed, Jul 23, 2003 at 05:30:52PM -0700, Barry Lind wrote: >> New 7.3 and Dev builds for the driver are posted to the website. These >> fix two additional sql injection vulnerabilities reported by Oliver >> Jowett and Dmitry Tkach. > Now that it's patched, the one I reported was that you could insert a > literal \0 via setString() and friends, which the backend treated as "end of > query", so you could use a string like this: > "\0Qrollback;begin;insert into testquerynull(sensitive) values > (42);commit\0" > to inject your own query. FWIW, that won't work anymore in the V3 protocol, whether or not JDBC has been patched to reject nulls ... regards, tom lane ---------------------------(end of broadcast)--------------------------- TIP 2: you can get off all lists at once with the unregister command (send "unregister YourEmailAddressHere" to majordomo@xxxxxxxxxxxxxx)
|
|
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| Previous by Date: | Re: psql and jdbc insert discrepencies, Barry Lind |
|---|---|
| Next by Date: | Re: the IN clause saga, Joe Conway |
| Previous by Thread: | Re: New builds posted to jdbc.postgresql.org websit for jdbc driver, Oliver Jowett |
| Next by Thread: | psql and jdbc insert discrepencies, Clyde Wright |
| Indexes: | [Date] [Thread] [Top] [All Lists] |
Free MagazinesCisco NewsReceive a free quarterly e-newsletter with exclusive articles on how Cisco IT uses its own products and solutions to enable the business. subscribe Systems Management News, the newspaper for IT systems administration and data center managers! Each issue of Systems Management News is chock-full of news and analysis to help you understand what's happening in your field. subscribe The Enterprise Newsweekly eWeek is the essential technology information source for builders of e-business. subscribe Oracle Magazine Oracle Magazine contains technology strategy articles, sample code, tips, Oracle and partner news, how to articles for developers and DBAs, and more. Oracle (NASDAQ: ORCL) is the world's largest enterprise software company. subscribe Total Telecom Total Telecom is "The Economist of the communications industry". subscribe |