Niche Content Articles Directory homepage.
Translate Page To German Tranlate Page To Spanish Translate Page To French Translate Page To Italian Translate Page To Japanese Translate Page To Korean Translate Page To Portuguese Translate Page To Chinese
  Number Times Read : 25    Word Count: 577  
Categories

Accessories (159)
Acne (138)
Aerobics (1)
Aging (290)
Application Development (11)
Arts (1238)
Arts and Crafts (758)
Ask an Expert (97)
Automotive (1872)
Banking (56)
Beverages (201)
Branding (62)
Break-up (228)
Budgeting (7)
Business (13336)
Business Management (1103)
Buying (135)
Cancer (62)
Cancer Survival (224)
Career (1308)
Cars and Trucks (820)
Causes and Organizations (8)
Cell Phones (233)
Cheating (81)
Collecting (94)
College and University (72)
Communications (457)
Computers (2074)
Computers and Technology (2769)
Cooking (614)
Corporate (34)
Crafts & Hobbies (80)
Culture (226)
Culture and Society (2860)
Current Affairs (303)
Database Marketing (2)
Death (60)
Death and Dying (19)
DHTML (1)
Directories (15)
Disease & Illness (1437)
Diseases and Conditions (568)
Domain Names (22)
Drop Shipping (13)
E-Commerce (155)
Electronics (426)
Employee Relations (14)
Entertainment (2115)
Environment (241)
Equipment (50)
Etiquette (48)
Ezines and Newsletters (36)
Family (173)
Family Concerns (1170)
Fashion (2663)
Fiction (4)
Finance (8780)
Finances (4419)
Financial Planning (110)
Financing (112)
Fitness (326)
Food and Drinks (1092)
Free Tools and Resources (26)
Gadgets and Gizmos (117)
Gardening (1066)
Grants (32)
Growth Topics (50)
Health (2589)
Health & Fitness (4867)
Home (1277)
Home & Family (5952)
Home Business (656)
Home Management (3593)
HTML (4)
Human Resources (48)
Import Export (59)
Infants and Toddlers (98)
Internet (9209)
Internet Business (604)
Jobs (390)
K-12 (34)
Medical Business (441)
Medicines and Remedies (2095)
Men Only (21)
Motivational (7)
Motorcyles (10)
Nature (30)
Opinions (295)
Our Pets (156)
Personal Development (3091)
Pets and Animals (827)
Podcasting (6)
Pregnancy and Family Pla (76)
Presentation (20)
Product Reviews (69)
Recreation (2112)
Recreation & Sports (1415)
Recreation and Leisure (237)
Reference & Education (1833)
Relationship (4641)
Religion and Spiritualit (39)
Screenplay (0)
Search Engine Optimizati (243)
Search Engines (13)
Self Help (1235)
Self Improvement (870)
Selling (110)
Shopping (486)
Short Stories (38)
Society (548)
Speaking (29)
Sports (2274)
Start Up (65)
Stock Market Investing (129)
Strategic Planning (54)
Structured Settlements (4)
Supplements and Vitamins (116)
Team Building (23)
Technology (397)
Teenagers (53)
Telecommuting (1)
Telesales (1)
Television (36)
Tools & Resources (31)
Travel (4641)
Travel & Leisure (2292)
Vehicles (274)
Video (11)
Web Development (93)
Weddings (769)
Wellness, Fitness and Di (5135)
Womens Interest (2752)
Work Life Balance (19)
World Affairs (114)
Writing & Speaking (925)
 
Stats
Total Articles: 128746
Total Authors: 11974
Total Downloads: 5408200


Newest Member
Mark Kyhos

 


   

How to Detect SQL Injection Attacks



[Valid RSS feed]  Category Rss Feed - http://www.niche-content-articles.com/rss.php?rss=37
By : Andy Huang    19 or more times read
Submitted 2010-03-07 03:28:45
What is SQL Injection Attacks

With the growing up of B/S model application development, more and more programmer write program with it. Unfortunately, many programmers did not judge the validity of users’ input data during encoding, and then, there will be security risk in the application.

Malicious attackers submit a special section of database query code to the server, the server will disclosure some sensitive information when respond with corresponding result. This is SQL Injection Attacks. The main trend Firewall currently will not alarm when there is SQL attack because of the SQL Injection is via normal point and hidden and difficult to be detected, seemingly normal website visit.
The danger of SQL Injection Attacks

According to the statistics of CVE in 2006, there are more than 70% attacks based on web application. The SQL Injection Attacks increase year by year, it arrives at 1078 in 2006. Even though, these data is only for the vulnerability in universal applications currently.

CVE SQL Injection vulnerability
The danger of SQL Injection Attacks including:

Change the data in database without authorization.
Gain the administration authority of a site without authorization.
Maliciously change content of a site without authorization.
XSS attacks.
Gain the control authority of the server without authorization.
Add, delete and change the accounts in the server without authorization.

The process of detect and revert SQL Injection Attacks with Sax2

Some IDS software will execute effective detection for SQL Injection Attacks, though, firewall can not. Now, we go to the process of detect and revert SQL Injection Attacks with IDS software Sax2.

The steps of SQL Injection Attacks are:

a) Determine environment to find the injection point.
b) Determine the type of database.
c) Guess datasheet.
d) Guess the field.
e) Guess the content.

The steps “Guess datasheet”, “Guess the field” and “Guess the content” are very important fro SQL Injection Attacks during the full process. Let’s analyze these there steps.

Sax2 will detect and alarm the attacks in network real-time. It will show the in the table Event when there is SQL Injection Attacks, see the figure 1.

Sax2 alarm the MS_SQL Injection Attacks real-time

Figure 1 Sax2 alarm the MS_SQL Injection Attacks real-time

The selected event in the Figure 1 shows the attacker’s IP 192.168.21.103, the victim’s IP 125.65.112.10. And the original message is “select * from [dirs]”, means enquire whether there is a datasheet named “dirs” in current database, in the Original Communication view.
The attacker will repeat the operation to gain the expected datasheet. He will try to guess the filed in the datasheet if found the corresponding datasheet in the database.
Sax2 analysis the attacker is guessing the filed in the admin database

Figure 2 Sax2 analysis the attacker is guessing the filed in the admin database

The code in the red circle in the Figure 2 show the attacker is guessing the “paths” filed in the admin database. Also, the attacker will repeat the operation till find the corresponding filed.

The attacker will determine the length of the filed and guess the content after found the corresponding filed. It will be a SQL Injection Attacks after the attacker guess the content in the filed successfully. Sometimes, the attacker has to decryption the content if it in MD5 encryption.

Above is the whole process of SQL Injection Attacks and we detect it with Sax2. As we know, Sax2 can effectively detect and alarm the SQL Injection Attacks when it occurs. IDS software Sax2 is a useful tool for SQL Injection Attacks and make your network security combine with firewall software.
Author Resource:- http://www.ids-sax2.com
Article From Niche Content Articles Directory

HTML Ready Article. Click on the "Copy" button to copy into your clipboard.




Firefox users please select/copy/paste as usual
New Members
select
Sign up
select
learn more
Affiliate Sign in
Affiliate Sign In
 
Nav Menu
Home
Login
Submit Articles
Submission Guidelines
Top Articles
Link Directory
About Us
Contact Us
Privacy Policy
RSS Feeds

Actions
Print This Article
Add To Favorites

 
Sponsors

Purchase this software