LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 10-17-2014, 07:31 AM   #1
ktandel
LQ Newbie
 
Registered: May 2014
Posts: 8

Rep: Reputation: Disabled
Question Precautions before testing for sql injection of a web application


What are the precautions that needed to be taken before testing for sql injection on a webpage to prevent damaging the integrity of that web application?
 
Old 10-17-2014, 08:23 AM   #2
TenTenths
Senior Member
 
Registered: Aug 2011
Location: Dublin
Distribution: Centos 5 / 6 / 7
Posts: 3,475

Rep: Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553
Take full backups and don't run tests on a live/production server.
 
Old 10-31-2014, 08:07 AM   #3
ktandel
LQ Newbie
 
Registered: May 2014
Posts: 8

Original Poster
Rep: Reputation: Disabled
I heard the test could be run on live server and thats what I wish to know how it can be carried out ?
 
Old 11-01-2014, 10:16 PM   #4
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
It's expected from a Live web application users will alter data. So what TenTenths wrote about making backups partially addresses that in that you have a data set that is (or should be) consistent up to the point that you start your pentest. Note prevention means keeping damage from happening, as in: inline IDS, reverse proxy, application firewall, well vetted code.

I agree you should not run pentests on Live production targets but on your staging area.
Then again some people only learn things the hard way...
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
LXer: Web Password Form - Fending Off SQL Injection LXer Syndicated Linux News 0 08-18-2008 10:00 AM
SQL Injection inaki Linux - Security 6 06-04-2007 06:42 AM
Testing Web Stats Application tracyanne Linux - General 1 11-25-2006 11:00 AM
sql injection inaki Linux - Security 8 12-22-2005 10:41 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 10:17 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration