QuestionQ644

Web Application Injection Attacks

Which of the following HTTP requests constitutes a SQL injection attack?

  • A http://www.xsecurity.com/cgiin/bad.cgi?foo=..%fc%80%80%80%80%af../bin/ls%20-al
  • B http://www.victim.com/example?accountnumber=67891&creditamount=999999999
  • C http://www.myserver.com/search.asp?lname=adam%27%3bupdate%20usertable%20set% 20pass wd%3d %27hCx0r%27%3b--%00
  • D http://www.myserver.com/script.php?mydata=%3cscript%20src=%22http%3a%2f% 2fwww.yourser ver.c0m %2fbadscript.js%22%3e%3c%2fscript%3e
Explanation

SQL injection inserts SQL syntax into untrusted request input so that it can alter a database query. The lname value in choice C contains an encoded quote, statement separator, UPDATE command, and comment marker, attempting to modify a database password value. OWASP SQL Injection

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!