We will be presenting a slightly updated version of our presentation titled Expanding the Control Over Operating System From the Database. The new abstract is as follows:
Using a database (MySQL, PostgreSQL and Microsoft SQL Server), either via a SQL injection or via direct connection, as a stepping stone to control the underlying operating system can be achieved. There is much to say on operating system control by owning a database server: Windows registry access, anti-forensics technique to establish an out-of-band stealth connection, buffer overflow exploitation with memory protections bypass and custom user-defined function injection. These topics and more will be highlighted during the presentation.The Conference will take place on November 19 - 20, 2009 at Femina Cinema in Warsaw (Poland), don't miss it if you can!
