<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>SecDocs Feed for author Muhaimin Dzulfakar</title>
    <link>http://secdocs.lonerunners.net</link>
    <atom:link type="application/rss+xml" href="http://secdocs.lonerunners.net/rss/author/463-muhaimin-dzulfakar" rel="self"/>
    <description>Latest security documents RSS feed for author Muhaimin Dzulfakar</description>
    <language>en-us</language>
    <item>
      <title>[Video] Advanced MySQL Exploitation</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/463-muhaimin-dzulfakar"&gt;Muhaimin Dzulfakar&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/10-mysql"&gt;MySQL&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/tags/details/70-sql-injection"&gt;SQL injection&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/39-defcon-17"&gt;DEFCON 17&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Sun, 07 Mar 2010 17:22:29 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/2171-advanced-mysql-exploitation</link>
      <guid>http://secdocs.lonerunners.net/documents/details/2171-advanced-mysql-exploitation</guid>
    </item>
    <item>
      <title>[Paper] Advanced MySQL Exploitation</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/463-muhaimin-dzulfakar"&gt;Muhaimin Dzulfakar&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/10-mysql"&gt;MySQL&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/tags/details/70-sql-injection"&gt;SQL injection&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/39-defcon-17"&gt;DEFCON 17&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Sun, 07 Mar 2010 17:22:27 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/2170-advanced-mysql-exploitation</link>
      <guid>http://secdocs.lonerunners.net/documents/details/2170-advanced-mysql-exploitation</guid>
    </item>
    <item>
      <title>[Slides] Advanced MySQL Exploitation</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/463-muhaimin-dzulfakar"&gt;Muhaimin Dzulfakar&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/10-mysql"&gt;MySQL&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/tags/details/70-sql-injection"&gt;SQL injection&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/39-defcon-17"&gt;DEFCON 17&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Sun, 07 Mar 2010 17:22:26 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/2169-advanced-mysql-exploitation</link>
      <guid>http://secdocs.lonerunners.net/documents/details/2169-advanced-mysql-exploitation</guid>
    </item>
    <item>
      <title>[Audio] Advanced MySQL Exploitation</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/463-muhaimin-dzulfakar"&gt;Muhaimin Dzulfakar&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/10-mysql"&gt;MySQL&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/tags/details/70-sql-injection"&gt;SQL injection&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/39-defcon-17"&gt;DEFCON 17&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Sun, 07 Mar 2010 17:22:24 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/2168-advanced-mysql-exploitation</link>
      <guid>http://secdocs.lonerunners.net/documents/details/2168-advanced-mysql-exploitation</guid>
    </item>
    <item>
      <title>[Video] Advanced MySQL Exploitation</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/463-muhaimin-dzulfakar"&gt;Muhaimin Dzulfakar&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/10-mysql"&gt;MySQL&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/tags/details/70-sql-injection"&gt;SQL injection&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/tags/details/83-exploiting"&gt;exploiting&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/31-har-2009"&gt;HAR 2009&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Abstract&lt;/b&gt;: Attackers performing SQL injection on a MySQL platform must deal with several limitations and constraints. For example, the lack of multiple statements in one query makes MySQL an unpopular platform for remote code execution compared to other platforms. This talk will show that arbitrary code execution is possible on the MySQL platform and explain the techniques. In this presentation, the author will demonstrate the tool he wrote, titled MySqloit. This tool can be integrated with metasploit and is able to upload and execute shellcodes using a SQL Injection vulnerability in LAMP or WAMP environments.</description>
      <pubDate>Tue, 06 Oct 2009 20:27:00 +0200</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/1356-advanced-mysql-exploitation</link>
      <guid>http://secdocs.lonerunners.net/documents/details/1356-advanced-mysql-exploitation</guid>
    </item>
    <item>
      <title>[Slides] Advanced MySQL Exploitation</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/463-muhaimin-dzulfakar"&gt;Muhaimin Dzulfakar&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/10-mysql"&gt;MySQL&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/tags/details/70-sql-injection"&gt;SQL injection&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/tags/details/83-exploiting"&gt;exploiting&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/31-har-2009"&gt;HAR 2009&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Abstract&lt;/b&gt;: Attackers performing SQL injection on a MySQL platform must deal with several limitations and constraints. For example, the lack of multiple statements in one query makes MySQL an unpopular platform for remote code execution compared to other platforms. This talk will show that arbitrary code execution is possible on the MySQL platform and explain the techniques. In this presentation, the author will demonstrate the tool he wrote, titled MySqloit. This tool can be integrated with metasploit and is able to upload and execute shellcodes using a SQL Injection vulnerability in LAMP or WAMP environments.</description>
      <pubDate>Tue, 06 Oct 2009 20:25:00 +0200</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/1355-advanced-mysql-exploitation</link>
      <guid>http://secdocs.lonerunners.net/documents/details/1355-advanced-mysql-exploitation</guid>
    </item>
    <item>
      <title>[Paper] Advanced MySQL Exploitation</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/463-muhaimin-dzulfakar"&gt;Muhaimin Dzulfakar&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/10-mysql"&gt;MySQL&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/tags/details/70-sql-injection"&gt;SQL injection&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/30-black-hat-usa-2009"&gt;Black Hat USA 2009&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Sat, 05 Sep 2009 19:27:00 +0200</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/1243-advanced-mysql-exploitation</link>
      <guid>http://secdocs.lonerunners.net/documents/details/1243-advanced-mysql-exploitation</guid>
    </item>
    <item>
      <title>[Slides] Advanced MySQL Exploitation</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/463-muhaimin-dzulfakar"&gt;Muhaimin Dzulfakar&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/10-mysql"&gt;MySQL&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/tags/details/70-sql-injection"&gt;SQL injection&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/30-black-hat-usa-2009"&gt;Black Hat USA 2009&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Sat, 05 Sep 2009 19:21:00 +0200</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/1242-advanced-mysql-exploitation</link>
      <guid>http://secdocs.lonerunners.net/documents/details/1242-advanced-mysql-exploitation</guid>
    </item>
  </channel>
</rss>

