{"id":936,"date":"2015-05-12T21:30:43","date_gmt":"2015-05-13T02:30:43","guid":{"rendered":"http:\/\/www.serverpronto.com\/spu\/?p=936"},"modified":"2018-07-19T10:46:12","modified_gmt":"2018-07-19T15:46:12","slug":"preventing-sql-injection-attacks","status":"publish","type":"post","link":"https:\/\/www.serverpronto.com\/spu\/2015\/05\/preventing-sql-injection-attacks\/","title":{"rendered":"Preventing SQL Injection Attacks"},"content":{"rendered":"<p>Most people have a general understanding that cybercrime is a very real problem. Also, a threat to just about anyone who has an Internet connection and data they\u00e2\u20ac\u2122d like to protect. If your company has a relational database, you should know that you\u00e2\u20ac\u2122re a potential target of hackers who would love to take a look at the information you have to offer. Companies like PBS, Sony Pictures, LinkedIn, and Yahoo! have all suffered from these types of attacks. In fact, the same can even be said for the CIA. While you may have heard that in the news, what you might not know is that the same type of attack was used each time: a SQL injection.<!--more--><\/p>\n<h2>What Is a SQL Injection Attack?<\/h2>\n<p>Given how valuable databases are and how common SQL is as a programming language, SQL injection attacks have become progressively more common amongst hackers.<\/p>\n<p>Thanks to improper coding, a savvy hacker can identify a weakness where they can \u00e2\u20ac\u0153inject\u00e2\u20ac\u009d SQL commands of their own. If they do this correctly, the database is now wide open and so is something like your website. Far from taking valuable information, many mischievous hackers simply want to use your site to make your company look foolish in front of the whole world.<\/p>\n<p>While that\u00e2\u20ac\u2122s pretty scary, it\u00e2\u20ac\u2122s not all bad news. There are actually some very easy provisions you can take to keep the worst from occurring.\u00c2\u00a0 Keep in mind that no defense is going to be guaranteed in the ever-evolving world of cybercrime, but the below are definitely going to challenge a hacker.<\/p>\n<h2>Sanitize All Data Provided<\/h2>\n<p>If your website has data forms, you may not look at them as a serious threat to your relational database\u00e2\u20ac\u2122s security. After all, they\u00e2\u20ac\u2122re just forms for collecting things like email address and phone numbers, right?<\/p>\n<p>To you and me, you\u00e2\u20ac\u2122re correct. To someone who wants to gain access to your database, they\u00e2\u20ac\u2122re potential locks to pick. This is why you have to be sure that these forms only accept specific characters. No phone number is going to have a letter in it, for example, so simply don\u00e2\u20ac\u2122t allow people to type one in. It\u00e2\u20ac\u2122s not enough to just instruct users to put in their number, don\u00e2\u20ac\u2122t let letters or other characters even appear.<\/p>\n<p>This is one method a hacker could use for SQL injections. They could enter a code that your website then goes on to process thereby inserting it and allowing the hacker to wreak havoc.<\/p>\n<p>Take this a step further by supplying prepared statements or some other type of stored procedure to greatly limit a would-be hacker\u00e2\u20ac\u2122s ability to slip any code in a data form.<\/p>\n<h2>Use a Firewall<\/h2>\n<p>Everyone should be using a web application firewall for their website. Not doing so opens you up to all kinds of threats, for one thing, plus there is a number that you can get for free these days no matter what kind of web server you use.<\/p>\n<p>You want to pick a version that is constantly being updated though. As we mentioned earlier, cybercrime is always evolving; you want a firewall that can keep up.<\/p>\n<h2>Limit Exposure to Possible Breaches<\/h2>\n<p>No matter what you do, it\u00e2\u20ac\u2122s possible someone is going to figure out a way to pull off their SQL injection and breach your website. That being said, you can still limit your exposure to a problem by limiting database privileges.<\/p>\n<p>For example, your login page\u00e2\u20ac\u2122s code should query your company\u00e2\u20ac\u2122s database using an account that is only able to access the relevant table of credentials. This way, even if someone breaks through, they\u00e2\u20ac\u2122ll only get so far.<\/p>\n<p><a href=\"https:\/\/www.serverpronto.com\">ServerPronto<\/a> offers the best affordable and secure hosting service in all dedicated server packages.<\/p>\n<p>&nbsp;<\/p>\n<p>Source:<\/p>\n<p><a href=\"https:\/\/www.esecurityplanet.com\/hackers\/how-to-prevent-sql-injection-attacks.html\">How to Prevent SQL Injection Attacks<\/a><\/p>\n<p><a href=\"https:\/\/www.acunetix.com\/websitesecurity\/sql-injection\/\">Is Your Website Hackable?<\/a><\/p>\n<p>Photo cred: Flickr \/\u00c2\u00a0<a href=\"https:\/\/www.flickr.com\/photos\/cyberhades\/\">cyberhades<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Most people have a general understanding that cybercrime is a very real problem. Also, a threat to just about anyone who has an Internet connection and data they\u00e2\u20ac\u2122d like to protect. If your company has a relational database, you should know that you\u00e2\u20ac\u2122re a potential target of hackers who would love to take a look<\/p>\n","protected":false},"author":9,"featured_media":937,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"image","meta":{"footnotes":""},"categories":[64],"tags":[123,17,112,22,81,18],"class_list":["post-936","post","type-post","status-publish","format-image","has-post-thumbnail","category-support-of-the-day","tag-cloud","tag-dedicated-server","tag-hosting","tag-server","tag-sql","tag-web-hosting","post_format-post-format-image"],"_links":{"self":[{"href":"https:\/\/www.serverpronto.com\/spu\/wp-json\/wp\/v2\/posts\/936","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.serverpronto.com\/spu\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.serverpronto.com\/spu\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.serverpronto.com\/spu\/wp-json\/wp\/v2\/users\/9"}],"replies":[{"embeddable":true,"href":"https:\/\/www.serverpronto.com\/spu\/wp-json\/wp\/v2\/comments?post=936"}],"version-history":[{"count":3,"href":"https:\/\/www.serverpronto.com\/spu\/wp-json\/wp\/v2\/posts\/936\/revisions"}],"predecessor-version":[{"id":2421,"href":"https:\/\/www.serverpronto.com\/spu\/wp-json\/wp\/v2\/posts\/936\/revisions\/2421"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.serverpronto.com\/spu\/wp-json\/wp\/v2\/media\/937"}],"wp:attachment":[{"href":"https:\/\/www.serverpronto.com\/spu\/wp-json\/wp\/v2\/media?parent=936"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.serverpronto.com\/spu\/wp-json\/wp\/v2\/categories?post=936"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.serverpronto.com\/spu\/wp-json\/wp\/v2\/tags?post=936"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}