Mitigating SQL Injection Attack Threats

Since SQL injection attacks are very hard to detect, prevention is the best approach. Use these recommendations and best practices provided by US-CERT.


Partner logo

US-CERT is charged with providing response support and defense against cyber attacks for the Federal Civil Executive Branch (.gov) and information sharing and collaboration with state and local government, industry and international partners. US-CERT interacts with federal agencies, industry, the research community, state and local governments, and others to disseminate reasoned and actionable cyber security information to the public.

All IT Downloads from US-CERT » | Visit US-CERT »

From US-CERT | Jan 30, 2012

Structured Query Language (SQL) injection is an attack technique that attempts to subvert the relationship between a Web page and its supporting database, typically in order to trick the database into executing malicious code. SQL injection usually involves a combination of over-elevated permissions, unsanitized/untyped user input, and/or true software (database) vulnerabilities. Since SQL injection is possible even when no traditional software vulnerabilities exist, mitigation is often much more complicated than simply applying a security patch.

The following mitigation strategies and best practices can be used to minimize the risks associated with this attack vector: As with any system or architecture changes, local administrators are best positioned to know which strategies are appropriate for their specific networks and systems.

Included in this ZIP file are:

  • Intro Page.doc
  • Terms and Conditions.pdf
  • Mitigating SQL Injection Attack Threats.pdf
IT Downloads help you save time and money while executing essential IT management tasks. Download this useful resource now and put it to work for your business.

Inside the Latest Web Threats: From Myths to Mechanics

Join this live eSeminar to bust some common Web security myths and learn how the latest Web threats are created and spread.

10 Ways the IT Department Enables Cybercrime

This white paper discusses 10 ways that IT departments are enabling cybercriminals today, and offers ways to stop them.