etutorialspoint
  • Home
  • PHP
  • MySQL
  • MongoDB
  • HTML
  • Javascript
  • Node.js
  • Express.js
  • Python
  • Jquery
  • R
  • Kotlin
  • DS
  • Blogs
  • Theory of Computation

SQL Injection Prevention Techniques

In this article, we will learn how SQL injection is dangerous for our system and how we can prevent it. So let's first know what SQL injection is.

The SQL Injection is one of the oldest code-injection techniques which the attackers generally used to exploit the web applications. Like, if an attacker has inserted some vulnerable query as input, then that input may fetch some important data from your database or delete some information or may be the vulnerable query can delete the entire database. Today, SQL Injection is a common problem for exploited web applications. By using this, the attacker can violate transactions, they can become an administrator of database, or they can also effect our bank balance. So before prevention techniques, first let's know how the attacker attempts on SQL data.


SQL Injection Prevention Techniques



These are some examples that are vulnerable to SQL injection attack


SQL Injection 1=1

Suppose there is a table in the database name 'employee' and 'emp_name' is one of its fields. In front end, there is some search module that selects the employee data on the basis of the employee name. So in the controller, generally we write the query to fetch the searched employee name as -

$query = "SELECT * FROM employee WHERE emp_name = '$emname ' ";

Suppose the attacker goes to this search module in front end and in place of employee name, he has provided the given code in place of employee name variable as

 OR '1' = '1'

Then the select query becomes -

 $query = "SELECT * FROM employee WHERE emp_name = ' ' OR '1' = '1' ";

AS '1' = '1' condition always evaluates to true and executed and fetch all the data from the employee table. By this way, the attacker can fetch all the employee data.


SQL Injection Additional Query

In addition to provide the desired field value, the attacker can append the additional query that can delete or destroy all records. As the following input can delete all employee records if the attacker has provided the input as -

a%';DROP TABLE employee;

then the select query becomes

$query = "SELECT * FROM employee WHERE emp_name = ' a%';DROP TABLE employee;' ";

And when this query will be executed, it will delete all the employee data.


Blind SQL Injection

In this, the attacker can pass the query in URL parameters if the webpage url allows it, like -

http://www.example.com/employeedetail.php?empid=10

This URL gets an employee id 10, and can execute the given query and populate that employee data that having employee id 10.

$query = "SELECT * FROM employee WHERE empid = '10'; "

A hacker can also append the condition in the requested url and which may result.

http://www.example.com/employeedetail.php?empid=101 OR 1=1

This may fetch all employee information. Similarly hacker can affect any data in the database.




Methods to prevent SQL injection

These are the methods that protect from SQL vulnerabilities-

By using MySQLi

MySQLi is an improved version of MySQL. This improved version is built to use with PHP programming language. If you are using MySQL version 4.3 or newer, then it is recommended to use MySQLi Extension.

MySQLi binds the parameter after the select statement. This process results more security by preventing SQL injection attack and increased performance.

$stmt = $dbConnection->prepare('SELECT * FROM employee WHERE emp_name = ?');
$stmt->bind_param('s', $name);
$stmt->execute();
$result = $stmt->get_result();
while ($row = $result->fetch_assoc()) {
    // do something with $row
}    


By using PDO

PDO extends for PHP Data Object. It is lightweight, more portable interface for accessing database in PHP. It is a database access layer which makes the developer to write portable code much easier.

In PDO, you can bind the parameter after select statement. The bindparam() method binds a parameter to the specified variable name to fetch the desired value, i.e. it sets the where clause condition and fetch() method fetches a row from the result set. This process protects from SQL injection attack.

$emp_select = $database->prepare("SELECT * FROM employee WHERE emp_name = :empname ");
$emp_select->bindparam(':empname', '$empname');
$emp_select->execute();
$emprows = $emp_select->fetch(PDO::FETCH_ASSOC);
return $emprows;    




Related Articles

Upload multiple files and store in MySQL database using PHP
multiple choice quiz in PHP and MySQL
Import Data Into MySQL From Excel File
CRUD operations in Python using MYSQL Connector
Windows commands to Create and Run first Django app
Preventing Cross Site Request Forgeries(CSRF) in PHP
PHP code to send email using SMTP
Simple pagination in PHP
Simple PHP File Cache
PHP Connection and File Handling on FTP Server
Sending form data to an email using PHP
Recover forgot password using PHP and MySQL
How to display PDF file in PHP from database
How to read CSV file in PHP and store in MySQL
Create And Download Word Document in PHP




Most Popular Development Resources
Retrieve Data From Database Without Page refresh Using AJAX, PHP and Javascript
-----------------
PHP Create Word Document from HTML
-----------------
How to get data from XML file in PHP
-----------------
Hypertext Transfer Protocol Overview
-----------------
PHP code to send email using SMTP
-----------------
Characteristics of a Good Computer Program
-----------------
How to encrypt password in PHP
-----------------
Create Dynamic Pie Chart using Google API, PHP and MySQL
-----------------
PHP MySQL PDO Database Connection and CRUD Operations
-----------------
Splitting MySQL Results Into Two Columns Using PHP
-----------------
Dynamically Add/Delete HTML Table Rows Using Javascript
-----------------
How to add multiple custom markers on google map
-----------------
How to get current directory, filename and code line number in PHP
-----------------
Fibonacci Series Program in PHP
-----------------
Get current visitor\'s location using HTML5 Geolocation API and PHP
-----------------
How to Sort Table Data in PHP and MySQL
-----------------
Simple star rating system using PHP, jQuery and Ajax
-----------------
Submit a form data using PHP, AJAX and Javascript
-----------------
jQuery loop over JSON result after AJAX Success
-----------------
How to generate QR Code in PHP
-----------------
Simple pagination in PHP
-----------------
Recover forgot password using PHP7 and MySQLi
-----------------
PHP MYSQL Advanced Search Feature
-----------------
PHP Server Side Form Validation
-----------------
PHP user registration and login/ logout with secure password encryption
-----------------
jQuery File upload progress bar with file size validation
-----------------
Simple PHP File Cache
-----------------
Simple File Upload Script in PHP
-----------------
Php file based authentication
-----------------
To check whether a year is a leap year or not in php
-----------------
Calculate distance between two locations using PHP
-----------------
PHP User Authentication by IP Address
-----------------
PHP Secure User Registration with Login/logout
-----------------
Simple way to send SMTP mail using Node.js
-----------------
How to print specific part of a web page in javascript
-----------------
Simple Show Hide Menu Navigation
-----------------
Detect Mobile Devices in PHP
-----------------
Polling system using PHP, Ajax and MySql
-----------------
PHP Sending HTML form data to an Email
-----------------
Google Street View API Example
-----------------
Get Visitor\'s location and TimeZone
-----------------
SQL Injection Prevention Techniques
-----------------
Preventing Cross Site Request Forgeries(CSRF) in PHP
-----------------
Driving route directions from source to destination using HTML5 and Javascript
-----------------
Convert MySQL to JSON using PHP
-----------------
Set and Get Cookies in PHP
-----------------
CSS Simple Menu Navigation Bar
-----------------
PHP Programming Error Types
-----------------
Date Timestamp Formats in PHP
-----------------
How to select/deselect all checkboxes using Javascript
-----------------
How to add google map on your website and display address on click marker
-----------------
Write a python program to print all even numbers between 1 to 100
-----------------
How to display PDF file in web page from Database in PHP
-----------------
PHP Getting Document of Remote Address
-----------------
File Upload Validation in PHP
-----------------


Most Popular Blogs
Most in demand programming languages
Best mvc PHP frameworks in 2019
MariaDB vs MySQL
Most in demand NoSQL databases for 2019
Best AI Startups In India
Kotlin : Android App Development Choice
Kotlin vs Java which one is better
Top Android App Development Languages in 2019
Web Robots
Data Science Recruitment of Freshers - 2019


Interview Questions Answers
Basic PHP Interview
Advanced PHP Interview
MySQL Interview
Javascript Interview
HTML Interview
CSS Interview
Programming C Interview
Programming C++ Interview
Java Interview
Computer Networking Interview
NodeJS Interview
ExpressJS Interview
R Interview







Learn Popular Language

listen
listen
listen
listen
listen

Blogs

  • Jan 3

    Stateful vs Stateless

    A Stateful application recalls explicit subtleties of a client like profile, inclinations, and client activities...

  • Dec 29

    Best programming language to learn in 2021

    In this article, we have mentioned the analyzed results of the best programming language for 2021...

  • Dec 20

    How is Python best for mobile app development?

    Python has a set of useful Libraries and Packages that minimize the use of code...

  • July 18

    Learn all about Emoji

    In this article, we have mentioned all about emojis. It's invention, world emoji day, emojicode programming language and much more...

  • Jan 10

    Data Science Recruitment of Freshers

    In this article, we have mentioned about the recruitment of data science. Data Science is a buzz for every technician...

Follow us

  • etutorialspoint facebook
  • etutorialspoint twitter
  • etutorialspoint linkedin
etutorialspoint youtube
About Us      Contact Us


  • eTutorialsPoint©Copyright 2016-2023. All Rights Reserved.