Australian Websites - Promote Your URL
It is currently 19-05-2012 06:05 AM

All times are UTC + 10 hours [ DST ]




Post new topic Reply to topic  [ 4 posts ] 
Author Message
 Post subject: What is SQL Injecting?
PostPosted: 21-02-2010 05:02 PM 
Offline
Ghost Writer

Joined: 21-02-2010 04:02 PM
Posts: 30
Hello my fellow programmers,

can anybody make some lights on the topic SQL injecting? I got this word while reading a book of vulnerable forums. But don't know much about this. Its about the forum security or something related I guess. I'm not sure though. Let me know please,

thanks.

_________________
Free Press Release


Top
 Profile  
 
 Post subject: Re: What is SQL Injecting?
PostPosted: 21-02-2010 05:02 PM 
Offline
Site Admin
User avatar

Joined: 06-02-2010 10:02 PM
Posts: 153
I think what happens is that via inputs on the page, by placing special characters in the fields and submiting the webpage form, you can affect SQL queries, and for example delete all the data in your website's database...

Could be very painful, so I guess to overcome this type of attacks, you need to validate the form submission.

_________________
Bulk Submissions for SEO services :: Dirstats - Dir of Dirs
----------------------------
Find Service Web Directory


Top
 Profile  
 
 Post subject: Re: What is SQL Injecting?
PostPosted: 21-02-2010 06:02 PM 
Offline
Ghost Writer

Joined: 21-02-2010 04:02 PM
Posts: 30
Thanks admin,

yeah you are right. This is mostly used in forums and bulletin board hackings. I read on the article that these guys use exploits to pass such queries to databases of vulnerable forum boards to get personal information like user passwords(mostly that of admins). But thank god phpbb and vbulletin are strong enough to defend this.

_________________
Free Press Release


Top
 Profile  
 
 Post subject: Re: What is SQL Injecting?
PostPosted: 14-04-2011 09:04 PM 
Offline
Noob Writer

Joined: 05-01-2011 05:01 PM
Posts: 22
SQL injection is a code injection technique that exploits a security weakness occurring in the database layer of an application. The weakness is present when user input is either incorrectly filtered for string literal escape characters embedded in SQL statements or user input is not strongly typed and thereby unexpectedly executed. It is an instance of a more general class of vulnerabilities that can occur whenever one programming or scripting language is implanted inside another. SQL injection attacks are also known as SQL insertion

_________________
Invoicera is an online invoicing and time tracking software which is specifically designed keeping simplicity and online invoicing convenience in mind.


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 4 posts ] 

All times are UTC + 10 hours [ DST ]


Who is online

Users browsing this forum: No registered users and 1 guest


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
cron
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group

phpBB SEO