Digital Fingerprints

SQL Injection Attacks

Please sign in to save this to your favorites.
Date: July 1, 2009
read time: 4 mins

Organized cybercriminals are taking advantage of vulnerabilities that exist in the way dynamic Web sites operate by injecting malicious code that sites' database servers process. This, in turn, is infecting the computers of visitors to the affected sites.

These SQL injection attacks are nothing new. But, in the past, each attack was directed at "valuable" targets. Hackers most often selected these targets because their databases contained sensitive information that could be resold or used for identity theft. Today these attacks have become more widespread, and they're acting as vehicles for mass infection of Web sites, which leads to thousands of infected computers.

Cybercriminals target organizations because they store valuable information in their online applications. At the most basic level, improperly validated user input in a Web-based application causes these attacks. This user input is comprised of character "strings" that an attacker carefully crafts and injects into instructions sent to the database by the Web application to take aim at the database layer. Applications should validate all user input passed to the database, but some don't perform this function adequately. Instead they allow malicious code to be passed to the database for processing.

Begin Your Free 30-Day Trial

Unlock full access to Fraud Magazine and explore in-depth articles on the latest trends in fraud prevention and detection.