CAPEC-66
SQL Injection
This attack exploits target software that constructs SQL statements based on user input. An attacker crafts input strings so that when the target software constructs SQL statements based on the input, the resulting SQL statement performs actions other than those the application intended. SQL Injection results from failure of the application to appropriately validate input.
Abstraction
Standard
Typical severity
High
Likelihood of attack
High
Understand the attack
What is this attack pattern?
Extended description
Execution flow
How does the attack proceed, step by step?
Explore
Survey application
Techniques used
- Spider web sites for all available links
- Sniff network communications with application using a utility such as WireShark.
Experiment
Determine user-controllable input susceptible to injection
Techniques used
- Use web browser to inject input through text fields or through HTTP GET parameters.
- Use a web application debugging tool such as Tamper Data, TamperIE, WebScarab,etc. to modify HTTP POST parameters, hidden fields, non-freeform fields, etc.
- Use network-level packet injection tools such as netcat to inject input
- Use modified client (modified by reverse engineering) to inject input.
Experiment with SQL Injection vulnerabilities
Techniques used
- Use public resources such as "SQL Injection Cheat Sheet" at http://ferruh.mavituna.com/makale/sql-injection-cheatsheet/, and try different approaches for adding logic to SQL queries.
- Add logic to query, and use detailed error messages from the server to debug the query. For example, if adding a single quote to a query causes an error message, try : "' OR 1=1; --", or something else that would syntactically complete a hypothesized query. Iteratively refine the query.
- Use "Blind SQL Injection" techniques to extract information about the database schema.
- If a denial of service attack is the goal, try stacking queries. This does not work on all platforms (most notably, it does not work on Oracle or MySQL). Examples of inputs to try include: "'; DROP TABLE SYSOBJECTS; --" and "'); DROP TABLE SYSOBJECTS; --". These particular queries will likely not work because the SYSOBJECTS table is generally protected.
Exploit
Exploit SQL Injection vulnerability
Techniques used
- Craft and Execute underlying SQL query
Requirements
What does the attack require?
Prerequisites
- SQL queries used by the application to store, retrieve or modify data.
- User-controllable input that is not properly validated by the application as part of SQL queries.
Skills required
- Low: It is fairly simple for someone with basic SQL knowledge to perform SQL injection, in general. In certain instances, however, specific knowledge of the database employed may be required.
Resources required
- None: No specialized resources are required to execute this type of attack.
Detection
What are the indicators of the attack?
Impact
What does a successful attack lead to?
Affected scopes: Integrity
Affected scopes: Confidentiality
Affected scopes: Confidentiality, Integrity, Availability
Affected scopes: Confidentiality, Access Control, Authorization
Defence
How is it prevented and mitigated?
Real world