Bandwidth and Network Usage
Monitoring Software Free Download

Recent Articles

Oracle Acquisitions are Not About MySQL
I've been thinking about this for the last day or so and have come to the conclusion that Oracle's acquisition of Sleepycat Software (and Berkeley DB)...

Someone AJAXified mytop!

Check this out. Someone has built and AJAX powered version of mytop, the little console based MySQL monitoring tool I wrote years ago.

Protecting Against SQL Injection With PHP And MYSQL
Security is important for all developers, but more so when combining two of the most popular Database...


03.07.06


SQL Injections Abound

By John Stith

Danish security firm Secunia reported on Monday several moderately critical vulnerabilities in various software products that allow SQL injection attacks. Products like Gregarius, Total Ecommerce, Akarrus Social Bookmarking Engine and others.

SQL injections are vulnerabilities occurring in the database layer of an application. It's created with the incorrect escaping of dynamically-generated string literals embedded in SQL statements.

Secunia also reported a problem in WordPress with SQL injection issues. "Input is passed to the ‘User-Agent' HTTP header when commenting on an article isn't properly sanitized before being used in a SQL query."

French Security Incident Response Team (FrSIRT) has also been reporting a number of SQL injection attacks. They've picked up on the vulnerabilities in programs like Pixelpost, NMDeluxe, Php-Stats and several others.

Bandwidth and Network Usage
Monitoring Software Free Download


In most cases, there's an additional vulnerability listed as well. With the SQL injection problems, the biggest problem consistently remains the lack of sanitation. Unfortunately, Lysol can't be used on these problems.

For example, in the Total Ecommerce problem, the "input passed to the ‘id' parameter in index.asp isn't properly sanitized before being used in an SQL query." This leads to possible exploitations to manipulate the SQL queries by injecting arbitrary SQL code.


While there are patches for many of these products, it's still something to watch out for regarding most products one might use. Make sure the good sanitation methods are in place and this shouldn't be a regular problem.

As more and more software is available with SQL, companies must become ever-more vigilant in order to protect their information. Getting patches and other updastes is critical.


About the Author:
John Stith is a staff writer for WebProNews covering technology and business.

About SQLproNews
SQLproNews is a collection of up to date tutorials and insightful articles designed to help SQL users of any skill level implement successful SQL systems and practices. SQL Strategies and Tactics for Business

SQLproNews is brought to you by:

SecurityConfig.com NetworkingFiles.com
NetworkNewz.com WebProASP.com
DatabaseProNews.com SQLProNews.com
ITcertificationNews.com SysAdminNews.com
SQLproNews.com WirelessProNews.com
CProgrammingTrends.com SysAdminNews.com




-- SQLProNews is an iEntry, Inc. publication --
iEntry, Inc. 2549 Richmond Rd. Lexington KY, 40509
2006 iEntry, Inc.  All Rights Reserved  Privacy Policy  Legal

advertising info | news headlines | free newsletters | comments/feedback | submit article



SQL Strategies and Tactics for Business SQLproNews News Archives About Us Feedback SQLproNews Home Page About Article Archive News Downloads WebProWorld Forums Jayde iEntry Advertise Contact