<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
    <channel>
        <title>Paul Gerste: SQL Injection Isn’t Dead — Protocol-Level Injection Attacks</title>
        <link>https://peertube.eqver.se/videos/watch/10106d61-333b-4b45-a5cc-21272f475025</link>
        <description>A DEF CON 32 talk where security researcher Paul Gerste presents a new approach to exploiting SQL injection. Instead of targeting SQL syntax, he focuses on vulnerabilities in database communication protocols, allowing attackers to inject queries directly into the connection between an application and a database. The talk demonstrates how a technique similar to HTTP request smuggling can be applied to binary database protocols. By manipulating message boundaries, an attacker can desynchronize the application and the database, leading to authentication bypass, data leaks, and even remote code execution.</description>
        <lastBuildDate>Fri, 24 Jul 2026 11:35:37 GMT</lastBuildDate>
        <docs>https://validator.w3.org/feed/docs/rss2.html</docs>
        <generator>PeerTube - https://peertube.eqver.se</generator>
        <image>
            <title>Paul Gerste: SQL Injection Isn’t Dead — Protocol-Level Injection Attacks</title>
            <url>https://peertube.eqver.se/client/assets/images/icons/icon-512x512.png</url>
            <link>https://peertube.eqver.se/videos/watch/10106d61-333b-4b45-a5cc-21272f475025</link>
        </image>
        <copyright>All rights reserved, unless otherwise specified in the terms specified at https://peertube.eqver.se/about and potential licenses granted by each content's rightholder.</copyright>
        <atom:link href="https://peertube.eqver.se/feeds/video-comments.xml?videoId=10106d61-333b-4b45-a5cc-21272f475025" rel="self" type="application/rss+xml"/>
    </channel>
</rss>