Cesar
Cerrudo of Argeniss Information Security has put out a new
whitepaper (.pdf format), Data0: Next generation malware for stealing
databases, describing how malware could be crafted to
steal information out of databases. For the most part, it stays
at a high-level, however, Cesar does give a few example queries
(for SQL Server), the appropriate API calls to perform certain
operations, etc., which delve a bit more into the technical side,
but even these are fairly straight-forward. To demonstrate what
he talks about in the whitepaper, he built a simple proof of
concept (PoC), but based on what's in the whitepaper (and what is
generally accepted as what's possible), nothing seemed outlandish
or hard-to-do. Just for those worried about that PoC being …
[Read more]