SQL Injection - Forms and Validity

Forms and Validity

SQL injection attack (SQLIA) is considered one of the top 10 web application vulnerabilities of 2007 and 2010 by the Open Web Application Security Project. The attacking vector contains five main sub-classes depending on the technical aspects of the attack's deployment:

  • Classic SQLIA
  • Inference SQL injection
  • Interacting with SQL injection
  • Database management system-specific SQLIA
  • Compounded SQLIA


  • SQL injection + insufficient authentication
  • SQL injection + DDoS attacks
  • SQL injection + DNS hijacking
  • SQL injection +XSS

A complete overview of the SQL Injection classification is presented in the next figure. The Storm Worm is one representation of Compounded SQLIA.

This classification represents the state of SQLIA, respecting its evolution until 2010—further refinement is underway.

Read more about this topic:  SQL Injection

Famous quotes containing the words forms and, forms and/or validity:

    I had a glimpse through curtain laces
    Of youthful forms and youthful faces.
    Robert Frost (1874–1963)

    The catalogue of forms is endless: until every shape has found its city, new cities will continue to be born. When the forms exhaust their variety and come apart, the end of cities begins.
    Italo Calvino (1923–1985)

    The hardiest skeptic who has seen a horse broken, a pointer trained, or has visited a menagerie or the exhibition of the Industrious Fleas, will not deny the validity of education. “A boy,” says Plato, “is the most vicious of all beasts;” and in the same spirit the old English poet Gascoigne says, “A boy is better unborn than untaught.”
    Ralph Waldo Emerson (1803–1882)