5 ms·
Obviously the correct solution for SQL injection is to use prepared statements or "proper" input validation. I however wouldn't call WAF solutions snake oil...
by Edmond 6y ago
Obviously the correct solution for SQL injection is to use prepared statements or "proper" input validation.
I however wouldn't call WAF solutions snake oil...Web security in general follows an approach of layering Swiss cheese with holes in them, you hope that if you layer enough protection you can plug all the holes.
Leading WAF solutions have pretty decent coverage for SQLi and other payload attacks. If you're not sure of security in your code then your next best choices is a WAF.
- deleted 6y ago[deleted]
- nicoburns 6y agoIsn't it a fairly simple, mechanical job convert a non-parameterised query into a parameterised one. No non-local reasoning required. Things must bw pretty bad if you're running code with known SQL injection vulnerabilities!
- deleted 6y ago[deleted]
- nexuist 6y agoThis makes a lot of assumptions, for example: 1) You are the only one working on this project and there are no other people who may have varying experience levels or development schedules 2) You are in charge of all the software running on the machine and have the time to audit all of it 3) You are capable of writing software like this and didn't just contract it out to some firm 4) You are capable of writing software at all WAFs are not perfect but there is clearly a market for them. It's not useful to high end tech companies because they have the in-house expertise (including red team/blue team staff) to avoid these pitfalls, which is expertise most small businesses and town/city-level govt agencies can't afford.
- nucleardog 6y agoUntil you run across code that's doing something like: def search(key, value): query("select * from my_table where `" + key + "` = '" + value + "'") Not that I'm suggesting this is a good thing to do, but it's not something you can simply replace with a single line of context or easily.
- nicoburns 6y agoI believe you could handle that case with an escaping function for the `key` variable. Column names are generally quite restricted in what characters they can contain, so this is fairly easy to do in a water-tight way. Of course this won't restrict which column you're giving access to, but a WAF won't catch that either.
- zamalek 6y ago> "proper" input validation. They are. That doesn't work. There is no good reason to concatenate user input into a query, full stop.