Garayed.com  

Go Back   Garayed.com > PHP
FAQ Members List Calendar Search Today's Posts Mark Forums Read


Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 04-13-2006, 06:28 AM
lawrence k
 
Posts: n/a
Default if I allow anyone on the web to run SQL queries against my database, what are the obvious attacks hackers will try?

Okay, I just backed up my database, just in case.

The whole schema for the database is here:

http://www.accumulist.com/index.php?whatPage=db.php

You can run any SELECT query against this database that you want, and
send it as a GET request. This would be an example:

http://www.accumulist.com/output.php...rom%20tagCloud


The function that returns this checks to query to see if it contains
the words ALTER, DROP, EMPTY, GRANT, UPDATE, INSERT, and a bunch of
others. It calls die() if it sees any of those words.

For obvious reasons, I'm trepidatious about exposing the database to
this degree. What are some of the obvious, and not so obvious, attacks
that I shoudl expect and defend against?

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT. The time now is 06:32 AM.




LinkBacks Enabled by vBSEO 3.0.0 © 2007, Crawlability, Inc.