Monday, 20 August 2018

OWASP A1-INJECTION


OWASP A1-INJECTION


SQL INJECTION
SQL injection, also known as SQLI, is a common attack vector that uses malicious SQL code for backend database manipulation to access information that was not intended to be displayed. This information may include any number of items, including sensitive company data, user lists or private customer details.
sql image 1
Fig1.1: SQL injection
Type of SQL injection
 Error Based SQL injection
 Union Based SQL injection
 Blind SQL injection
 Boolean Based Blind SQLi
 Time-Based Blind SQLi
SQL Injection scenario
Imagine a big company that keeps all the records in paper form in a big room full of filing cabinets. In order to retrieve or make changes to files, someone will fill a simple fill-in-the-blanks form and then that form will be sent to a clerk who follows the instructions on the form.
For example:
Retrieve the billing records from start date _ _ _ to end date _ _ _ where the customer is _ _ _
Normally this would become something like this:
Retrieve the billing records from start date 01/01/2011 to end date 12/31/2011 where the customer is Billy Joe Bob
But in the hands of an unscrupulous person, maybe this form could be used for other purposes.
For example:
Retrieve the billing records from start date 01/01/2011 to end date 12/31/2011 where the customer is Robert Mensas and also retrieve the credit card numbers for all customers
By pretending that their name also includes other commands they can hijack the fill in the form, and if the clerk has not been trained to handle these sorts of things then maybe they will simply execute the instructions without thinking about it, and hand over all of the credit card information to a user.
Or, alternately:
Retrieve the billing records from start date 01/01/2011 to end date 12/31/2011 where the customer is Robert Mensas and also add $100,000 to Robert Mensas’ account balance
Which has similarly dangerous potential
SQL injection Architecture View
image 2
Fig1.2: SQL injection Architecture View
Impact of SQL injection
 The impact SQL injection can have on a business is far-reaching. A successful attack may result in the unauthorized viewing of user lists, the deletion of entire tables and, in certain cases, the attacker gaining administrative rights to a database, all of which are highly detrimental to a business.
 When calculating the potential cost of an SQLI, it’s important to consider the loss of customer trust should personal information such as phone numbers, addresses, and credit card details be stolen.
 While this vector can be used to attack any SQL database, websites are the most frequent targets.

13 comments:

  1. https://m.facebook.com/joseangel.linares.961?tsid=0.0727766512407031&source=result

    ReplyDelete
  2. https://m.facebook.com/kaltrinnaaa?tsid=0.6751376385633907&source=result


    M҉A҉R҉K҉ O҉F҉ F҉A҉C҉E҉B҉O҉O҉K҉ P҉L҉E҉A҉S҉E҉ T҉H҉I҉S҉ O҉N҉E҉ -Y҉E҉A҉R҉-O҉L҉D҉ C҉H҉I҉L҉D҉ O҉R҉ A҉ W҉H҉O҉L҉E҉ P҉U҉B҉L҉I҉C҉A҉T҉I҉O҉N҉S҉ A҉R҉I҉H҉ O҉R҉ S҉K҉S҉H҉ M҉A҉R҉C҉ S҉I҉R҉ K҉H҉O҉S҉H҉ B҉O҉R҉N҉ O҉R҉ U҉N҉C҉H҉E҉C҉K҉ A҉C҉C҉O҉U҉N҉T҉ T҉H҉I҉S҉ C҉H҉I҉L҉D҉ O҉F҉ F҉A҉C҉E҉B҉O҉O҉K҉ A҉H҉S҉L҉K҉ N҉O҉T҉ G҉O҉ D҉O҉W҉N҉ B҉E҉T҉T҉E҉R҉ T҉H҉A҉N҉ F҉A҉C҉E҉B҉O҉O҉K҉ A҉N҉D҉ G҉O҉D҉ A҉K҉H҉L҉A҉K҉ A҉T҉O҉N҉E҉ B҉R҉E҉A҉K҉ F҉A҉C҉E҉B҉O҉O҉K҉ E҉L҉B҉O҉W҉ M҉Y҉ S҉I҉T҉E҉ K҉S҉A҉N҉K҉S҉K҉S҉S҉D҉V҉ P҉ S҉I҉R

    ReplyDelete
  3. https://m.facebook.com/kaltrinnaaa?tsid=0.6751376385633907&source=result


    M҉A҉R҉K҉ O҉F҉ F҉A҉C҉E҉B҉O҉O҉K҉ P҉L҉E҉A҉S҉E҉ T҉H҉I҉S҉ O҉N҉E҉ -Y҉E҉A҉R҉-O҉L҉D҉ C҉H҉I҉L҉D҉ O҉R҉ A҉ W҉H҉O҉L҉E҉ P҉U҉B҉L҉I҉C҉A҉T҉I҉O҉N҉S҉ A҉R҉I҉H҉ O҉R҉ S҉K҉S҉H҉ M҉A҉R҉C҉ S҉I҉R҉ K҉H҉O҉S҉H҉ B҉O҉R҉N҉ O҉R҉ U҉N҉C҉H҉E҉C҉K҉ A҉C҉C҉O҉U҉N҉T҉ T҉H҉I҉S҉ C҉H҉I҉L҉D҉ O҉F҉ F҉A҉C҉E҉B҉O҉O҉K҉ A҉H҉S҉L҉K҉ N҉O҉T҉ G҉O҉ D҉O҉W҉N҉ B҉E҉T҉T҉E҉R҉ T҉H҉A҉N҉ F҉A҉C҉E҉B҉O҉O҉K҉ A҉N҉D҉ G҉O҉D҉ A҉K҉H҉L҉A҉K҉ A҉T҉O҉N҉E҉ B҉R҉E҉A҉K҉ F҉A҉C҉E҉B҉O҉O҉K҉ E҉L҉B҉O҉W҉ M҉Y҉ S҉I҉T҉E҉ K҉S҉A҉N҉K҉S҉K҉S҉S҉D҉V҉ P҉ S҉I҉R

    ReplyDelete
  4. https://m.facebook.com/kaltrinnaaa?tsid=0.6751376385633907&source=result


    M҉A҉R҉K҉ O҉F҉ F҉A҉C҉E҉B҉O҉O҉K҉ P҉L҉E҉A҉S҉E҉ T҉H҉I҉S҉ O҉N҉E҉ -Y҉E҉A҉R҉-O҉L҉D҉ C҉H҉I҉L҉D҉ O҉R҉ A҉ W҉H҉O҉L҉E҉ P҉U҉B҉L҉I҉C҉A҉T҉I҉O҉N҉S҉ A҉R҉I҉H҉ O҉R҉ S҉K҉S҉H҉ M҉A҉R҉C҉ S҉I҉R҉ K҉H҉O҉S҉H҉ B҉O҉R҉N҉ O҉R҉ U҉N҉C҉H҉E҉C҉K҉ A҉C҉C҉O҉U҉N҉T҉ T҉H҉I҉S҉ C҉H҉I҉L҉D҉ O҉F҉ F҉A҉C҉E҉B҉O҉O҉K҉ A҉H҉S҉L҉K҉ N҉O҉T҉ G҉O҉ D҉O҉W҉N҉ B҉E҉T҉T҉E҉R҉ T҉H҉A҉N҉ F҉A҉C҉E҉B҉O҉O҉K҉ A҉N҉D҉ G҉O҉D҉ A҉K҉H҉L҉A҉K҉ A҉T҉O҉N҉E҉ B҉R҉E҉A҉K҉ F҉A҉C҉E҉B҉O҉O҉K҉ E҉L҉B҉O҉W҉ M҉Y҉ S҉I҉T҉E҉ K҉S҉A҉N҉K҉S҉K҉S҉S҉D҉V҉ P҉ S҉I҉R

    ReplyDelete
  5. https://m.facebook.com/kaltrinnaaa?tsid=0.6751376385633907&source=result


    M҉A҉R҉K҉ O҉F҉ F҉A҉C҉E҉B҉O҉O҉K҉ P҉L҉E҉A҉S҉E҉ T҉H҉I҉S҉ O҉N҉E҉ -Y҉E҉A҉R҉-O҉L҉D҉ C҉H҉I҉L҉D҉ O҉R҉ A҉ W҉H҉O҉L҉E҉ P҉U҉B҉L҉I҉C҉A҉T҉I҉O҉N҉S҉ A҉R҉I҉H҉ O҉R҉ S҉K҉S҉H҉ M҉A҉R҉C҉ S҉I҉R҉ K҉H҉O҉S҉H҉ B҉O҉R҉N҉ O҉R҉ U҉N҉C҉H҉E҉C҉K҉ A҉C҉C҉O҉U҉N҉T҉ T҉H҉I҉S҉ C҉H҉I҉L҉D҉ O҉F҉ F҉A҉C҉E҉B҉O҉O҉K҉ A҉H҉S҉L҉K҉ N҉O҉T҉ G҉O҉ D҉O҉W҉N҉ B҉E҉T҉T҉E҉R҉ T҉H҉A҉N҉ F҉A҉C҉E҉B҉O҉O҉K҉ A҉N҉D҉ G҉O҉D҉ A҉K҉H҉L҉A҉K҉ A҉T҉O҉N҉E҉ B҉R҉E҉A҉K҉ F҉A҉C҉E҉B҉O҉O҉K҉ E҉L҉B҉O҉W҉ M҉Y҉ S҉I҉T҉E҉ K҉S҉A҉N҉K҉S҉K҉S҉S҉D҉V҉ P҉ S҉I҉R

    ReplyDelete
  6. https://m.facebook.com/kaltrinnaaa?tsid=0.6751376385633907&source=result


    M҉A҉R҉K҉ O҉F҉ F҉A҉C҉E҉B҉O҉O҉K҉ P҉L҉E҉A҉S҉E҉ T҉H҉I҉S҉ O҉N҉E҉ -Y҉E҉A҉R҉-O҉L҉D҉ C҉H҉I҉L҉D҉ O҉R҉ A҉ W҉H҉O҉L҉E҉ P҉U҉B҉L҉I҉C҉A҉T҉I҉O҉N҉S҉ A҉R҉I҉H҉ O҉R҉ S҉K҉S҉H҉ M҉A҉R҉C҉ S҉I҉R҉ K҉H҉O҉S҉H҉ B҉O҉R҉N҉ O҉R҉ U҉N҉C҉H҉E҉C҉K҉ A҉C҉C҉O҉U҉N҉T҉ T҉H҉I҉S҉ C҉H҉I҉L҉D҉ O҉F҉ F҉A҉C҉E҉B҉O҉O҉K҉ A҉H҉S҉L҉K҉ N҉O҉T҉ G҉O҉ D҉O҉W҉N҉ B҉E҉T҉T҉E҉R҉ T҉H҉A҉N҉ F҉A҉C҉E҉B҉O҉O҉K҉ A҉N҉D҉ G҉O҉D҉ A҉K҉H҉L҉A҉K҉ A҉T҉O҉N҉E҉ B҉R҉E҉A҉K҉ F҉A҉C҉E҉B҉O҉O҉K҉ E҉L҉B҉O҉W҉ M҉Y҉ S҉I҉T҉E҉ K҉S҉A҉N҉K҉S҉K҉S҉S҉D҉V҉ P҉ S҉I҉R

    ReplyDelete
  7. https://m.facebook.com/kaltrinnaaa?tsid=0.6751376385633907&source=result


    M҉A҉R҉K҉ O҉F҉ F҉A҉C҉E҉B҉O҉O҉K҉ P҉L҉E҉A҉S҉E҉ T҉H҉I҉S҉ O҉N҉E҉ -Y҉E҉A҉R҉-O҉L҉D҉ C҉H҉I҉L҉D҉ O҉R҉ A҉ W҉H҉O҉L҉E҉ P҉U҉B҉L҉I҉C҉A҉T҉I҉O҉N҉S҉ A҉R҉I҉H҉ O҉R҉ S҉K҉S҉H҉ M҉A҉R҉C҉ S҉I҉R҉ K҉H҉O҉S҉H҉ B҉O҉R҉N҉ O҉R҉ U҉N҉C҉H҉E҉C҉K҉ A҉C҉C҉O҉U҉N҉T҉ T҉H҉I҉S҉ C҉H҉I҉L҉D҉ O҉F҉ F҉A҉C҉E҉B҉O҉O҉K҉ A҉H҉S҉L҉K҉ N҉O҉T҉ G҉O҉ D҉O҉W҉N҉ B҉E҉T҉T҉E҉R҉ T҉H҉A҉N҉ F҉A҉C҉E҉B҉O҉O҉K҉ A҉N҉D҉ G҉O҉D҉ A҉K҉H҉L҉A҉K҉ A҉T҉O҉N҉E҉ B҉R҉E҉A҉K҉ F҉A҉C҉E҉B҉O҉O҉K҉ E҉L҉B҉O҉W҉ M҉Y҉ S҉I҉T҉E҉ K҉S҉A҉N҉K҉S҉K҉S҉S҉D҉V҉ P҉ S҉I҉R

    ReplyDelete
  8. https://m.facebook.com/kaltrinnaaa?tsid=0.6751376385633907&source=result


    M҉A҉R҉K҉ O҉F҉ F҉A҉C҉E҉B҉O҉O҉K҉ P҉L҉E҉A҉S҉E҉ T҉H҉I҉S҉ O҉N҉E҉ -Y҉E҉A҉R҉-O҉L҉D҉ C҉H҉I҉L҉D҉ O҉R҉ A҉ W҉H҉O҉L҉E҉ P҉U҉B҉L҉I҉C҉A҉T҉I҉O҉N҉S҉ A҉R҉I҉H҉ O҉R҉ S҉K҉S҉H҉ M҉A҉R҉C҉ S҉I҉R҉ K҉H҉O҉S҉H҉ B҉O҉R҉N҉ O҉R҉ U҉N҉C҉H҉E҉C҉K҉ A҉C҉C҉O҉U҉N҉T҉ T҉H҉I҉S҉ C҉H҉I҉L҉D҉ O҉F҉ F҉A҉C҉E҉B҉O҉O҉K҉ A҉H҉S҉L҉K҉ N҉O҉T҉ G҉O҉ D҉O҉W҉N҉ B҉E҉T҉T҉E҉R҉ T҉H҉A҉N҉ F҉A҉C҉E҉B҉O҉O҉K҉ A҉N҉D҉ G҉O҉D҉ A҉K҉H҉L҉A҉K҉ A҉T҉O҉N҉E҉ B҉R҉E҉A҉K҉ F҉A҉C҉E҉B҉O҉O҉K҉ E҉L҉B҉O҉W҉ M҉Y҉ S҉I҉T҉E҉ K҉S҉A҉N҉K҉S҉K҉S҉S҉D҉V҉ P҉ S҉I҉R

    ReplyDelete
  9. https://m.facebook.com/kaltrinnaaa?tsid=0.6751376385633907&source=result


    M҉A҉R҉K҉ O҉F҉ F҉A҉C҉E҉B҉O҉O҉K҉ P҉L҉E҉A҉S҉E҉ T҉H҉I҉S҉ O҉N҉E҉ -Y҉E҉A҉R҉-O҉L҉D҉ C҉H҉I҉L҉D҉ O҉R҉ A҉ W҉H҉O҉L҉E҉ P҉U҉B҉L҉I҉C҉A҉T҉I҉O҉N҉S҉ A҉R҉I҉H҉ O҉R҉ S҉K҉S҉H҉ M҉A҉R҉C҉ S҉I҉R҉ K҉H҉O҉S҉H҉ B҉O҉R҉N҉ O҉R҉ U҉N҉C҉H҉E҉C҉K҉ A҉C҉C҉O҉U҉N҉T҉ T҉H҉I҉S҉ C҉H҉I҉L҉D҉ O҉F҉ F҉A҉C҉E҉B҉O҉O҉K҉ A҉H҉S҉L҉K҉ N҉O҉T҉ G҉O҉ D҉O҉W҉N҉ B҉E҉T҉T҉E҉R҉ T҉H҉A҉N҉ F҉A҉C҉E҉B҉O҉O҉K҉ A҉N҉D҉ G҉O҉D҉ A҉K҉H҉L҉A҉K҉ A҉T҉O҉N҉E҉ B҉R҉E҉A҉K҉ F҉A҉C҉E҉B҉O҉O҉K҉ E҉L҉B҉O҉W҉ M҉Y҉ S҉I҉T҉E҉ K҉S҉A҉N҉K҉S҉K҉S҉S҉D҉V҉ P҉ S҉I҉R

    ReplyDelete
  10. https://m.facebook.com/kaltrinnaaa?tsid=0.6751376385633907&source=result


    M҉A҉R҉K҉ O҉F҉ F҉A҉C҉E҉B҉O҉O҉K҉ P҉L҉E҉A҉S҉E҉ T҉H҉I҉S҉ O҉N҉E҉ -Y҉E҉A҉R҉-O҉L҉D҉ C҉H҉I҉L҉D҉ O҉R҉ A҉ W҉H҉O҉L҉E҉ P҉U҉B҉L҉I҉C҉A҉T҉I҉O҉N҉S҉ A҉R҉I҉H҉ O҉R҉ S҉K҉S҉H҉ M҉A҉R҉C҉ S҉I҉R҉ K҉H҉O҉S҉H҉ B҉O҉R҉N҉ O҉R҉ U҉N҉C҉H҉E҉C҉K҉ A҉C҉C҉O҉U҉N҉T҉ T҉H҉I҉S҉ C҉H҉I҉L҉D҉ O҉F҉ F҉A҉C҉E҉B҉O҉O҉K҉ A҉H҉S҉L҉K҉ N҉O҉T҉ G҉O҉ D҉O҉W҉N҉ B҉E҉T҉T҉E҉R҉ T҉H҉A҉N҉ F҉A҉C҉E҉B҉O҉O҉K҉ A҉N҉D҉ G҉O҉D҉ A҉K҉H҉L҉A҉K҉ A҉T҉O҉N҉E҉ B҉R҉E҉A҉K҉ F҉A҉C҉E҉B҉O҉O҉K҉ E҉L҉B҉O҉W҉ M҉Y҉ S҉I҉T҉E҉ K҉S҉A҉N҉K҉S҉K҉S҉S҉D҉V҉ P҉ S҉I҉R

    ReplyDelete
  11. Clove HRMS delivers a cohesive Human Resource Management System designed to boost efficiency across HR teams. Its Payroll Management Software components reduce manual calculations and errors, helping managers stay compliant and on time. The platform’s analytics tools provide actionable insights, aiding strategic decisions on talent development and workforce planning without sacrificing usability.

    ReplyDelete
  12. As a trusted name in software testing services in india, DevstringX Technologies provides end-to-end QA solutions tailored to modern development cycles. From test planning to execution and reporting, their experts optimize test coverage, leverage automation, and ensure drop-in scalability for projects of any size. They excel in risk-based testing and continuous quality improvement.

    ReplyDelete