Skip to main content

A Developer’s Perspective OF Why SQL Injection Vulnerabilities Still Exist

Prevent SQL Innjection Using Parametrized queries

 Knowing how to prevent a SQL injection vulnerability is only half the web application security battle. A multitude of factors come into play when it comes to writing secure code, many of which are out of the developers’ direct control. That’s why common vulnerabilities like SQL injection continue to plague today’s applications, and why application security testing software is so important. These problems can be overcome – with a little insight, organizations can begin to address these challenges directly and better enable developers to remediate SQL injection. Here are the top eight reasons SQL injection vulnerabilities are still rampant:
  • SQL itself is vulnerable. SQL is designed to allow people access to information and is therefore inherently vulnerable, so every developer must know how to prevent SQL injection – not just one or two individuals on your development team.
  • The price of agnosticism. SQL is agnostic, meaning it works across database platforms. The upside to this is that it allows code to be database-server agnostic. But it is also the source of the problem. To prevent most vulnerabilities, developers should use parameterized SQL or stored procedures specific to the database server.
  • One mistake is all it takes. If just one vulnerability is left unsecured, a hacker can have his way. Every single input must be protected. Unfortunately, this is a tall order for any development team, as there can be tens of thousands of potential vulnerabilities on a single website.
  • Inexperienced developers lack training on old vulnerabilities. New generations of developers do not always receive the training and mentoring necessary to understand how to prevent common application vulnerabilities. They must be taught how to prevent exposing SQL injection vulnerabilities by creating comprehensive validation logic on every parameter or input.
  • Seasoned developers lack training on new technologies. Many veteran developers are using new formats and technologies to develop new types of applications. They must understand that SQL injection should still be considered for every input. For example, the application inputs from a mobile interface written in JSON that access the backend database can be as vulnerable to SQL injection as any input on an end-user page.
  • It’s not a priority. Many organizations do not consider fixing web application security vulnerabilities to be as important as they should. As a result, developers are generally more concerned with building new features and fixing bugs that impact user functionality.
  • It requires team effort. In order to eradicate SQL injection vulnerabilities, development and web application security teams must collaborate. Developers need security specialists to keep them informed of new hacking techniques, and security teams need developers to eliminate vulnerabilities.
  • Abandoned legacy applications. With the original application developers retired and the source code difficult to locate, vulnerabilities in legacy applications can be difficult or impossible to patch.
As you can see, educating developers on how to prevent SQL injection vulnerabilities won’t completely solve the problem. Organizations must enable developers to build secure code and make web application security testing a priority. Security teams have their perspective as well.

Reblogged from : http://www.manvswebapp.com/reasons-sql-injection-vulnerabilities-exist-developers-perspective


Comments

Popular posts from this blog

Foxeprenuer at UCSC | Introduction to Firefox Student Ambassadors

Had privilege to attend another awesome event as Regional Ambassador Lead . "Foxepernuer 2016" organized by University of Colombo , School of Computing , UCSC Firefox Club - Sri Lanka . Introduction FSA Program - Sri Lanka  while I had chance to talk about Mozilla project , Firefox Student Ambassador program , contributions and benefits , had opportunity to meet great enthusiast people after the event.  And Future of developments & technologies , being a professional & maintain it Encouraging students bring innovative ideas happen , becoming entrepreneurs and really interesting topics we discussed by resource persons.   Shafraz Rahim and Malinda Prasad from Dialog Axiata IdeaMart , and Rashmika Nawaratne from 99X Techno logy has done those sessions in really interesting way !.  Rashmika Navaratne talk about maintain professionalism Shafraz Rahim on "Intern Entrepreneur" Malinda Prasad talk about "...

පොත් කියවීමයි මමයි

පොතක් කියවන්න. වැඩි වයසක් නැති උනාට ඒ දවස් වල ආසම වැඩේ තමයි පොතක් කියවන එක. ගෙදර පරිසරය කොහොමෙන් හැදුනද දන්නේ නැති උනත් පුංචිම කාලේ ඉදල පොත් වලට තිබ්බේ පුදුම ආසාවක් . මම හිතන්නේ මට ඒ පුරුද්ද හැදෙන්න ඇත්තේ අක්ක නිසා වෙන්න ඕනි .  අම්මගේ තාත්තගේ පඩි දවසට අක්කටයි මටයි පොත් දෙකක් අනිවාර්යයි පොඩිම දවස් වල ඉදල. ඒ නැතත් පොතක් කියවල ඉවර වෙද්දී තව පොතක් අරන් දෙනවා කොහොම හරි කියවන්න.  ඒ නිසාම අපේ අම්ම මාවත් එකක්ගෙන ගිහින් පුස්තකාලෙට සම්බන්ද කළා . අනේ මන්ද මොකක් උනත් මට පුස්තකාලයට නම් පුරුදු වෙන්නම අමාරු උනා. අවුරුද්දක් විතර පුස්තකාලයට ගියත් ආයේ ගෙනාපු පොතක් ගෙනියන්න තියෙන කම්මැලි කමටම දෙතුන් පාරක් දඩ වැදුනම තවත් හිතට අමාරුයි . ඇයි ඉතින් එක පැත්තකින් මන් වැරද්දක් කළා කියන හැගීමයි අනිත් පැත්තෙන් අතේ තියෙන රුපියල් දහයක් විතර නැති වෙනවනේ .. හත් වලාමේ...  කොහොමෙන් හරි ඔය පොත් කියවිල්ලේ රුදාව නිසාම කොහොමෙන් හරි 5 , 6 වසර වගේ ඉද්දි අම්ම ගෙනාව හෙන පතාර පොතක් කැමති නම් කියවන්න කියල. හෙන අසාවෙන් ගත්තට මොකද අතට මෙලෝ සංසාරයක් තේරෙන්නේ නැ එකේ තියෙන. බාසාව නිකම් පාලි වගේ . වගේ න...