Question

Describe how a SQL injection attack works and ways to mitigate one.

Describe how a SQL injection attack works and ways to mitigate one.

0 0
Add a comment Improve this question Transcribed image text
Answer #1

Let us take an example of query that provide the name and description for item number 10.

SELECT Name,Description FROM Table

WHERE Number = 10 OR 1=1

since the statement 1 = 1 is always true, the query returns all names and descriptions in the database, even those which we don't want

Mitigation strategy:

1. Use prepared statement with parameterized queries.

2. Use stored procedures.

3. white list input validation

Add a comment
Know the answer?
Add Answer to:
Describe how a SQL injection attack works and ways to mitigate one.
Your Answer:

Post as a guest

Your Name:

What's your source?

Earn Coins

Coins can be redeemed for fabulous gifts.

Not the answer you're looking for? Ask your own homework help question. Our experts will answer your question WITHIN MINUTES for Free.
Similar Homework Help Questions
ADVERTISEMENT
Free Homework Help App
Download From Google Play
Scan Your Homework
to Get Instant Free Answers
Need Online Homework Help?
Ask a Question
Get Answers For Free
Most questions answered within 3 hours.
ADVERTISEMENT
ADVERTISEMENT
ADVERTISEMENT