Showing posts with label ASP.NET. Show all posts
Showing posts with label ASP.NET. Show all posts

Avoiding SQL Injection by sanka dilmadu

Wednesday, January 14, 2009 Posted by Sanka Senevirathna 1 comments

Avoiding SQL Injection


If you are a web developer this article is very important regarding Data security of your application. Actually to avoid hacking your database you have to learn how to hacking database. So sanka will teach you how to hacking database by SQL injection.


following is very interresting...check it..I think it is not more a hacking method,bcz all are know about htis by my articles.

’, ‘’); drop table MyTable;--


most of fu..ing web developers are doing following incorrect idiot type of coding..







string cmdStr =
"insert into Shippers (CompanyName, Phone) values ('" +
txtCompanyName.Text + "', '" + txtPhone.Text + "')";




So my friends do the following type of thing here



insert into Shippers (CompanyName, Phone) values ('', ''); drop table MyTable;--', '')


user name :


The first part of this statement adds a new row with blank values to the Shippers table. The second part, after the first semicolon (;), removes the MyTable table from the database. The rest of the statement, after the second semicolon, is commented out to prevent errors.

As you can see, attackers can do a lot of damage to your system or view information they aren’t supposed to see. Even worse, although it may not be totally obvious by this example, through SQL injection an attacker could potentially take over your entire system.



So this is the solution for that



string surname = this.surnameTb.Text.Replace("'", "''");
string cmdStr =
"insert into Shippers (CompanyName, Phone) values (" +
"@CompanyName, @Phone)";
using (SqlConnection conn = new SqlConnection(connStr))
using (SqlCommand cmd = new SqlCommand(cmdStr, conn))
{
// add parameters
cmd.Parameters.AddWithValue
("@CompanyName", txtCompanyName.Text);
cmd.Parameters.AddWithValue("@Phone", txtPhone.Text);
conn.Open();
cmd.ExecuteNonQuery();
}