Skip to content

What it blocks

Database injection

Someone tries to slip database commands into your site.

What it is

Database commands typed into a search box, a form or an address, hoping your site passes them straight to its database.

  • ' OR '1'='1 in a login form
  • UNION SELECT in an address
  • A command to delete a table in a search box

Why it matters

When it works, the attacker can read or change everything the site stores: customers, orders, passwords.

When it stops a real visitor

This can catch real text that happens to look like a database command, such as a note about SQL or a name with an apostrophe beside certain words. Mark the request as real and that one field is let through.

What you will see most

The request contained a database command.
The input was recognised as SQL, the language websites use to talk to their databases.
The request contained a database command.
The input included SQL used to pull data out of a database.
All 20 rules in this kind, as the rule set names them

For your web person. OWASP Core Rule Set 4.25.0, paranoia level 1.

  • 942100SQL Injection Attack Detected via libinjection
  • 942140SQL Injection Attack: Common DB Names Detected
  • 942151SQL Injection Attack: SQL function name detected
  • 942160Detects blind sqli tests using sleep() or benchmark()
  • 942170Detects SQL benchmark and sleep injection attempts including conditional queries
  • 942190Detects MSSQL code execution and information gathering attempts
  • 942220Looking for integer overflow attacks, these are taken from skipfish, except 2.2.2250738585072011e-308 is the \"magic number\" crash
  • 942230Detects conditional SQL injection attempts
  • 942240Detects MySQL charset switch and MSSQL DoS attempts
  • 942250Detects MATCH AGAINST, MERGE and EXECUTE IMMEDIATE injections
  • 942270Looking for basic sql injection. Common attack string for mysql, oracle and others
  • 942280Detects Postgres pg_sleep injection, waitfor delay attacks and database shutdown attempts
  • 942290Finds basic MongoDB SQL injection attempts
  • 942320Detects MySQL and PostgreSQL stored procedure/function injections
  • 942350Detects MySQL UDF injection and other data/structure manipulation attempts
  • 942360Detects concatenated basic SQL injection and SQLLFI attempts
  • 942500MySQL in-line comment detected
  • 942540SQL Authentication bypass (split query)
  • 942550JSON-Based SQL Injection
  • 942560MySQL Scientific Notation payload detected