CAPEC-66
SQL Injection
This attack exploits target software that constructs SQL statements based on user input. An attacker crafts input strings so that when the target software constructs SQL statements based on the input, the resulting SQL statement performs actions other than those the application intended. SQL Injection results from failure of the application to appropriately validate input.
Soyutlama
Standard
Tipik ciddiyet
High
Saldırı ihtimali
High
Saldırıyı anla
Bu saldırı kalıbı nedir?
Genişletilmiş açıklama
Uygulama akışı
Saldırı adım adım nasıl ilerler?
Explore
Survey application
Kullanılan teknikler
- Spider web sites for all available links
- Sniff network communications with application using a utility such as WireShark.
Experiment
Determine user-controllable input susceptible to injection
Kullanılan teknikler
- Use web browser to inject input through text fields or through HTTP GET parameters.
- Use a web application debugging tool such as Tamper Data, TamperIE, WebScarab,etc. to modify HTTP POST parameters, hidden fields, non-freeform fields, etc.
- Use network-level packet injection tools such as netcat to inject input
- Use modified client (modified by reverse engineering) to inject input.
Experiment with SQL Injection vulnerabilities
Kullanılan teknikler
- Use public resources such as "SQL Injection Cheat Sheet" at http://ferruh.mavituna.com/makale/sql-injection-cheatsheet/, and try different approaches for adding logic to SQL queries.
- Add logic to query, and use detailed error messages from the server to debug the query. For example, if adding a single quote to a query causes an error message, try : "' OR 1=1; --", or something else that would syntactically complete a hypothesized query. Iteratively refine the query.
- Use "Blind SQL Injection" techniques to extract information about the database schema.
- If a denial of service attack is the goal, try stacking queries. This does not work on all platforms (most notably, it does not work on Oracle or MySQL). Examples of inputs to try include: "'; DROP TABLE SYSOBJECTS; --" and "'); DROP TABLE SYSOBJECTS; --". These particular queries will likely not work because the SYSOBJECTS table is generally protected.
Exploit
Exploit SQL Injection vulnerability
Kullanılan teknikler
- Craft and Execute underlying SQL query
Gereksinimler
Saldırının gerçekleşmesi için ne gerekir?
Ön koşullar
- SQL queries used by the application to store, retrieve or modify data.
- User-controllable input that is not properly validated by the application as part of SQL queries.
Gerekli beceri
- Low: It is fairly simple for someone with basic SQL knowledge to perform SQL injection, in general. In certain instances, however, specific knowledge of the database employed may be required.
Gerekli kaynak
- None: No specialized resources are required to execute this type of attack.
Tespit
Saldırının göstergeleri nelerdir?
Etki
Başarılı saldırı neye yol açar?
Etkilenen alanlar: Integrity
Etkilenen alanlar: Confidentiality
Etkilenen alanlar: Confidentiality, Integrity, Availability
Etkilenen alanlar: Confidentiality, Access Control, Authorization
Savunma
Nasıl önlenir ve etkisi azaltılır?
Gerçek dünya