Jakub Pruzinec

9 posts

Jakub Pruzinec

Jakub Pruzinec

@offbyfour

A cybersecurity researcher at Nanyang Technological University, Singapore.

Se unió Ağustos 2022
19 Siguiendo25 Seguidores
Jakub Pruzinec
Jakub Pruzinec@offbyfour·
Hakuin, a blazing fast Blind SQL Injection framework, made it to BlackHat Middle East & Africa this year! Come check out my two sessions (14 Nov 3pm, 15 Nov 5pm) at the arsenal track. Hakuin: github.com/pruzko/hakuin #BHMEA #BHMEA23
Jakub Pruzinec tweet media
English
1
0
1
238
Jakub Pruzinec
Jakub Pruzinec@offbyfour·
@clintgibler Thanks for the shout-out. BTW the framework is actively developed and new features are added!
English
0
0
0
10
Jakub Pruzinec
Jakub Pruzinec@offbyfour·
@ron190jsql My point here is that if you deduplicate the "users_sex" column then you'll get "male" & "female" but there is no way you can tell which users are male/female (without additional requests). Same goes for "product_category". I like the feature tho, will probably do it as well.
English
1
0
0
32
ron190 💉
ron190 💉@ron190jsql·
- jSQL deduplicates values which leads to "values detached from their indices" and "loss of information" Hmm, it just avoids wasting time, no loss, I don't get the point here. Though I'm glad it has been noticed, sure we see that removing duplicates is efficient on the chart.
ron190 💉 tweet media
English
1
0
0
221
ron190 💉
ron190 💉@ron190jsql·
It's paper time again, jSQL quoted among three "state-of-the-art" tools by the team of researcher @offbyfour and doctor aquynh. I heard feedbacks sounding worse than that.
ron190 💉 tweet media
English
2
0
0
280
Jakub Pruzinec
Jakub Pruzinec@offbyfour·
@ron190jsql You can have parallelism on bit/character/column level and achieve the same performance. One advantage I see with bit-extraction is that it can be easily combined with single-request-multiple-bits extraction (see "Blind sql injection attacks optimization" by Ruben Ventura).
English
0
0
0
17
ron190 💉
ron190 💉@ron190jsql·
Also some pertinent remarks about jSQL I can discuss: - bitwise operation allows 7 queries in parallel - 3 Python tools, 1 Java tool: I feel attacked
English
2
0
0
200
Jakub Pruzinec
Jakub Pruzinec@offbyfour·
@ron190jsql Hey, thx for finding time to read our paper, I'll try to address your comments.
English
0
0
1
8
Jakub Pruzinec retuiteado
USENIX WOOT Conference on Offensive Technologies
Session 4: Web & Network Security! "Scripted Henchmen: Leveraging XS-Leaks for Cross-Site Vulnerability Detection" "Hakuin: Optimizing Blind SQL Injection with Probabilistic Language Models" "Towards Simultaneous Attacks on Multiple Cellular Networks"
USENIX WOOT Conference on Offensive Technologies tweet mediaUSENIX WOOT Conference on Offensive Technologies tweet mediaUSENIX WOOT Conference on Offensive Technologies tweet media
English
0
3
3
816