This session is about Parameter Pollution in Connection Strings Attacks. Today, a lot of tools and web applications allow users to configure dynamically a connection against a Database server. This session will demonstrate the high risk in doing this insecurely. This session will show how to steal, in Microsoft Internet Information Services, the user account credentials, how to get access to this web applications impersonating the connection and taking advantage of the web server credentials and how to connect against internal database servers in the DMZ without credentials. The impact of these techniques are specialy dangerous in hosting companies which allow customers to connect against control panels to configure databases.