Question: Eric, a professional hacker, is trying to perform a SQL injection attack on the back - end database system of the InfomationSEC, Inc. During the
Eric, a professional hacker, is trying to perform a SQL injection attack on the backend database system of the InfomationSEC, Inc. During the information gathering process, he identifies that MYSQL server is the backend database engine used. Eric has tried various SQL injection attack attempts based on the information gathered but all of his attempts failed. Later, he discovered that IPS system is blocking all the SQL injection attack attempts. Eric decided to bypass the IPS using string concatenation IPS evasion technique where he needs to break the SQL query into a number of small pieces and concatenates the SQL query endtoend.
Which of the following string concatenation operator Eric need to use in the SQL query to concatenate the SQL query endtoend?
A
operator
B
concat operator
C
operator
D
& operator
Step by Step Solution
There are 3 Steps involved in it
1 Expert Approved Answer
Step: 1 Unlock
Question Has Been Solved by an Expert!
Get step-by-step solutions from verified subject matter experts
Step: 2 Unlock
Step: 3 Unlock
