What is SQL injection?
A SQL injection flaw allows for an attacker to modify or inject SQL syntax into the request to make the application behave in a manner that was not initially intended. In other words, an attacker can change a database query to:
Read sensitive data
Modify the database
Execute other database functions
Break authentication
Lead to remote code execution
Now with almost all web applications having integrations with databases in some way, this flaw has the potential to arise often. However, many frameworks and libraries are available to make database connections and queries safe. That said, SQL injection still exists and is very common. Injection flaws were the number one flaw category under the OWASP 2017, and, currently, injection flaws hold the number three spot in the OWASP 2021.
SQL injection flaws have impacted every industry as well as enterprises that already have a mature information security program in place. It can happen, and it can be catastrophic!
How…
Intelligence View
⚡ tsecurity.de Intelligence
SQL Injection in Today’s Landscape
What is SQL injection? A SQL injection flaw allows for an attacker to modify or inject SQL syntax into the request to make the application behave in a manner that was not initially intended. In other words, an attacker can change a…
Reagiere als Erste:r — dein Feedback zählt!
2. Cyber Threat Intelligence & Forensik
CTI Threat Relationship Graph4 Knoten / 3 Relationen
MITRE ATT&CK Matrix Navigator 14 Taktiken
1 belegte TechnikenLive-Mapping
Reconnaissance
–
Resource Development
–
Initial Access
Execution
–
Persistence
–
Privilege Escalation
–
Defense Evasion
–
Credential Access
–
Discovery
–
Lateral Movement
–
Collection
–
Command and Control
–
Exfiltration
–
Impact
–