Wednesday 20 November 2013

SQL injection

SQL injection is a code insertion technique, In which attacker insert the code or query in the input field of form and then submit the form. When the form is submitted in the data with attacker inserted code/query, the inserted code effects the web programmers query and there are more possiblities of attacker entry in the database. +Universal Music Group  +University of Pennsylvania  +UK Photography Community  +COMPUTER BILD  +Software Testing Help  +Sony Xperia  +Software Development Company  +UK Photography Community  +CaringBridge  +James O'Brien   +CaringBridge

This code insertion, sql query insertion or injection is called the SQL INJECTION .


Reason Of attacks

Programmers,developers do not format their code properly while they get the info from the users through submittion of forms.
if the code is properly filter for escape characters then this kind of sql injection can be handled.
if the escape characters are not filtered then sql injection can be expected.  +Bloomberg News 

No comments:

Post a Comment