What You Need to Know About SQL Injection Methods Used by Hackers

I drag out my web application and now I'm in SQL. I already have sql parameters, apostrophe duplication, javascript stripping and html coding. Are there other things I need to worry about besides what was above?

+3
source share
7 answers

Parameterized queries are only necessary if you dynamically generate queries using data from the user.

There are advantages to using these queries for something like oracle, which is also useful.

- , , , , , .

SQL-: http://www.owasp.org/index.php/SQL_Injection_Prevention_Cheat_Sheet

, , .

, , , .

, , : http://www.wwwcoder.com/Directory/tabid/68/type/art/site/2966/parentid/258/Default.aspx

, , , , .

, ? , , , , - , - .

+4

Parameterized Queries, - , . .

, sql- sql .

+7

Javascript HTML SQL-, .

, , , . -, , , , . URL, LDAP, XML File Path.

"" (, ), , SQL- , . , O'Brian exmaple. , , .

, MS, - :

userInput = userInput.Replace( "-", ").Replace(" ' "," ");

, , , , "MyName -'-SELECT * FROM User" ?

, , , , , . < , , , HTML. , , .

, , , , , . , , , . , , , .

, , . SQL-, HTML, URL javascript. SQL- ( , , ), ( , , SQL).

, System.Web HTML URL . Microsoft, Anti Cross Site, , . , Anti-XSS - . . , .Net 4?

+3

, . - ... = 1 = 30... :... = 1; ....

EDIT: , 1 ", DELETE, .

+1

perl uri . 3 - , gql.

0

baddies, , , sql-, .

Another crazy idea: do not run popular open source packages, especially those written in languages ​​starting with P.

0
source

Source: https://habr.com/ru/post/1716637/


All Articles