Alex Rivera | Logout

Is there some way to inject SQL even if the ' character is deleted?

Asked 2008-09-16T12:36:16.787
13

If I remove all the ' characters from a SQL query, is there some other way to do a SQL injection attack on the database?

How can it be done? Can anyone give me examples?

Edit
Report

4 Answers

15

Yes, depending on the statement you are using. You are better off protecting yourself either by using Stored Procedures, or at least parameterised queries.

See Wikipedia for prevention samples.

answered 2008-09-16T12:38:59.353
2

. . . uh about 50000000 other ways

maybe somthing like 5; drop table employees; --

resulting sql may be something like: select * from somewhere where number = 5; drop table employees; -- and sadfsf

(-- starts a comment)

answered 2008-09-16T12:40:46.493
0

I can only repeat what others have said. Parametrized SQL is the way to go. Sure, it is a bit of a pain in the butt coding it - but once you have done it once, then it isn't difficult to cut and paste that code, and making the modifications you need. We have a lot of .Net applications that allow web site visitors specify a whole range of search criteria, and the code builds the SQL Select statement on the fly - but everything that could have been entered by a user goes into a parameter.

answered 2008-09-16T13:52:15.963
0

When you are expecting a numeric parameter, you should always be validating the input to make sure it's numeric. Beyond helping to protect against injection, the validation step will make the app more user friendly.

If you ever receive id = "hello" when you expected id = 1044, it's always better to return a useful error to the user instead of letting the database return an error.

answered 2008-09-16T17:39:35.590

Your Answer