Alex Rivera | Logout

Are sql injection attacks only a threat on a page that has a form?

Asked 2009-11-11T17:56:57.240
10

I know it's a simple question, but in everything I've read, I've never seen this spelled out specifically.

If you do a query on a page, do you need to worry about SQL injection attacks? Or is it only a problem when you ask the user for input?

Thanks!

Edit
Report

3 Answers

1

SQL Injections is possible if you use any kind of data that comes from the browser. It could be form data, querystring data, cookie values, or even data from the request header.

The obvious and easy ways in is the form data and querystring data, but anything that comes from the browser could be spoofed.

answered 2009-11-11T18:02:30.220
0

When the user can modify the values of the parameters of a query, then it can become a threat.

answered 2009-11-11T17:59:50.060
0

I agree that parameterisation is the best approach.

As an alternative (which might be easier to retro fit into your code, at least initially) doubling the single quotes in a string will prevent SQL Injection.

To take Neil N's example:

sql = "Select * From Products Where ID = " + Request.Querystring["ID"]; 

wrap the variable in a function that doubles the quotes, and wrap the varible with single quotes too.

sql = "Select * From Products Where ID = " 
    + fnSQLSafeParam(Request.Querystring["ID"]);

The function would be something like (VBscript example):

Function fnSQLSafeParam(ByVal strStr)
  If IsNull(strStr) or IsEmpty(strStr) then strStr = ""
  fnSQLSafeParam = "'" & replace(Trim(CStr(strStr)), "'", "''") & "'"
End Function
answered 2009-11-11T19:18:54.823

Your Answer