Database injection
Someone tries to slip database commands into your site.
What it is
Database commands typed into a search box, a form or an address, hoping your site passes them straight to its database.
- ' OR '1'='1 in a login form
- UNION SELECT in an address
- A command to delete a table in a search box
Why it matters
When it works, the attacker can read or change everything the site stores: customers, orders, passwords.
When it stops a real visitor
This can catch real text that happens to look like a database command, such as a note about SQL or a name with an apostrophe beside certain words. Mark the request as real and that one field is let through.
What you will see most
- The request contained a database command.
- The input was recognised as SQL, the language websites use to talk to their databases.
- The request contained a database command.
- The input included SQL used to pull data out of a database.
All 20 rules in this kind, as the rule set names them
For your web person. OWASP Core Rule Set 4.25.0, paranoia level 1.
- 942100SQL Injection Attack Detected via libinjection
- 942140SQL Injection Attack: Common DB Names Detected
- 942151SQL Injection Attack: SQL function name detected
- 942160Detects blind sqli tests using sleep() or benchmark()
- 942170Detects SQL benchmark and sleep injection attempts including conditional queries
- 942190Detects MSSQL code execution and information gathering attempts
- 942220Looking for integer overflow attacks, these are taken from skipfish, except 2.2.2250738585072011e-308 is the \"magic number\" crash
- 942230Detects conditional SQL injection attempts
- 942240Detects MySQL charset switch and MSSQL DoS attempts
- 942250Detects MATCH AGAINST, MERGE and EXECUTE IMMEDIATE injections
- 942270Looking for basic sql injection. Common attack string for mysql, oracle and others
- 942280Detects Postgres pg_sleep injection, waitfor delay attacks and database shutdown attempts
- 942290Finds basic MongoDB SQL injection attempts
- 942320Detects MySQL and PostgreSQL stored procedure/function injections
- 942350Detects MySQL UDF injection and other data/structure manipulation attempts
- 942360Detects concatenated basic SQL injection and SQLLFI attempts
- 942500MySQL in-line comment detected
- 942540SQL Authentication bypass (split query)
- 942550JSON-Based SQL Injection
- 942560MySQL Scientific Notation payload detected