28.10.2014 Views

SQL Injection Attacks and Defense - 2009

SQL Injection Attacks and Defense - 2009

SQL Injection Attacks and Defense - 2009

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Code-Level <strong>Defense</strong>s • Chapter 8 351<br />

Tools & Traps…<br />

Designing an Input Validation <strong>and</strong> H<strong>and</strong>ling Strategy<br />

Input validation is a valuable tool for securing an application. However, it should be<br />

only part of a defense-in-depth strategy, with multiple layers of defense contributing<br />

to the application’s overall security. Here is an example of an input validation <strong>and</strong><br />

h<strong>and</strong>ling strategy utilizing some of the solutions presented in this chapter:<br />

■■<br />

■■<br />

■■<br />

■■<br />

■■<br />

■■<br />

Whitelist input validation used at the application input layer to validate all<br />

user input as it is accepted by the application. The application allows only<br />

input that is in the expected form.<br />

Whitelist input validation also performed at the client’s browser. This is<br />

done to avoid a round trip to the server in case the user enters data that is<br />

unacceptable. You cannot rely on this as a security control, as all data from<br />

the user’s browser can be altered by an attacker.<br />

Blacklist <strong>and</strong> whitelist input validation present at a Web application<br />

firewall (WAF) layer (in the form of vulnerability “signatures” <strong>and</strong><br />

“learned” behavior) to provide intrusion detection/prevention capabilities<br />

<strong>and</strong> monitoring of application attacks.<br />

Parameterized statements used throughout the application to ensure that<br />

safe <strong>SQL</strong> execution is performed.<br />

Encoding used within the database to safely encode input when used in<br />

dynamic <strong>SQL</strong>.<br />

Data extracted from the database appropriately encoded before it is used.<br />

For example, data being displayed in the browser is encoded for cross-site<br />

scripting (XSS).<br />

Blacklisting<br />

Blacklisting is the practice of only rejecting input that is known to be bad. This commonly<br />

involves rejecting input that contains content that is specifically known to be malicious by<br />

looking through the content for a number of “known bad” characters, strings, or patterns.<br />

This approach is generally weaker than whitelist validation because the list of potentially bad<br />

characters is extremely large, <strong>and</strong> as such any list of bad content is likely to be large, slow to<br />

run through, incomplete, <strong>and</strong> difficult to keep up to date.<br />

A common method of implementing a blacklist is also to use regular expressions, with a<br />

list of characters or strings to disallow, such as the following example:<br />

'|%|--|;|/\*|\\\*|_|\[|@|xp_

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!