{"id":80,"date":"2006-06-09T13:31:15","date_gmt":"2006-06-09T18:31:15","guid":{"rendered":"https:\/\/www.zubairalexander.com\/stage\/?p=80"},"modified":"2007-05-08T13:56:36","modified_gmt":"2007-05-08T18:56:36","slug":"using-sql-injection-to-bypass-security-controls","status":"publish","type":"post","link":"https:\/\/www.zubairalexander.com\/blog\/using-sql-injection-to-bypass-security-controls\/","title":{"rendered":"Using SQL Injection to Bypass Security Controls"},"content":{"rendered":"<p>To demonstrate some of the security issues, Joel Helgeson of Appiant.net has posted a video that shows how he used SQL injection to bypass security controls on a college Web site. In this video he demonstrates how easy this type of attack can be. If you are a Web developer, this is a good reminder for you to test your Web applications thoroughly for security issues.<\/p>\n<p>The video is available on appiant.net&#8217;s Web site.<\/p>\n<p><a HREF=\"http:\/\/www.appiant.net\/video\/exploit.wmv\" class=\"entrylink\">Exploit Video<\/a> (WMV format &#8211; 7.8MB &#8211; 3:25 min)<br \/>\n<a HREF=\"http:\/\/www.appiant.net\/video\/exploit_fixed.wmv\" class=\"entrylink\">Exploit Fixed<\/a> (WMV format &#8211; 764KB &#8211; 37 secs) <\/p>\n<p>Check out this <a HREF=\"http:\/\/www.microsoft.com\/emea\/itsshowtime\/sessionh.aspx?videoid=31\" class=\"entrylink\">video<\/a> from Microsoft on SQL Security. It looks at the security architecture of SQL server 2000 and introduces the SQL Server 2005 Security model. It also shows you how to lock down SQL server implementations.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>To demonstrate some of the security issues, Joel Helgeson of Appiant.net has posted a video that shows how he used SQL injection to bypass security controls on a college Web site. In this video he demonstrates how easy this type of attack can be. If you are a Web developer, this is a good reminder [&hellip;]<\/p>\n","protected":false},"author":7,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[24],"tags":[],"class_list":["post-80","post","type-post","status-publish","format-standard","hentry","category-security"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 4.9.8 - aioseo.com -->\n\t<meta name=\"description\" content=\"To demonstrate some of the security issues, Joel Helgeson of Appiant.net has posted a video that shows how he used SQL injection to bypass security controls on a college Web site. In this video he demonstrates how easy this type of attack can be. If you are a Web developer, this is a good reminder\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Zubair Alexander\"\/>\n\t<meta name=\"google-site-verification\" content=\"xUGSODobCBguuxTNOCWOCVwAIhfY39LLtYAQOmExYzw\" \/>\n\t<meta name=\"msvalidate.01\" content=\"65829CD0C3C810D64E58EA860413DB21\" \/>\n\t<link rel=\"canonical\" href=\"https:\/\/www.zubairalexander.com\/blog\/using-sql-injection-to-bypass-security-controls\/\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 4.9.8\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"Alexander&#039;s Blog | Sharing knowledge with the global IT community since November 1, 2004\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"Using SQL Injection to Bypass Security Controls | Alexander&#039;s Blog\" \/>\n\t\t<meta property=\"og:description\" content=\"To demonstrate some of the security issues, Joel Helgeson of Appiant.net has posted a video that shows how he used SQL injection to bypass security controls on a college Web site. In this video he demonstrates how easy this type of attack can be. If you are a Web developer, this is a good reminder\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/www.zubairalexander.com\/blog\/using-sql-injection-to-bypass-security-controls\/\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/www.zubairalexander.com\/blog\/wp-content\/uploads\/2004\/11\/AlexandersBlog_logo_590x590.png\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/www.zubairalexander.com\/blog\/wp-content\/uploads\/2004\/11\/AlexandersBlog_logo_590x590.png\" \/>\n\t\t<meta property=\"og:image:width\" content=\"590\" \/>\n\t\t<meta property=\"og:image:height\" content=\"590\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2006-06-09T18:31:15+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2007-05-08T18:56:36+00:00\" \/>\n\t\t<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n\t\t<meta name=\"twitter:site\" content=\"@zubairalexander\" \/>\n\t\t<meta name=\"twitter:title\" content=\"Using SQL Injection to Bypass Security Controls | Alexander&#039;s Blog\" \/>\n\t\t<meta name=\"twitter:description\" content=\"To demonstrate some of the security issues, Joel Helgeson of Appiant.net has posted a video that shows how he used SQL injection to bypass security controls on a college Web site. In this video he demonstrates how easy this type of attack can be. If you are a Web developer, this is a good reminder\" \/>\n\t\t<meta name=\"twitter:creator\" content=\"@zubairalexander\" \/>\n\t\t<meta name=\"twitter:image\" content=\"https:\/\/www.zubairalexander.com\/blog\/wp-content\/uploads\/2004\/11\/AlexandersBlog_logo_590x590.png\" \/>\n\t\t<script type=\"application\/ld+json\" class=\"aioseo-schema\">\n\t\t\t{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.zubairalexander.com\\\/blog\\\/using-sql-injection-to-bypass-security-controls\\\/#article\",\"name\":\"Using SQL Injection to Bypass Security Controls | Alexander's Blog\",\"headline\":\"Using SQL Injection to Bypass Security Controls\",\"author\":{\"@id\":\"https:\\\/\\\/www.zubairalexander.com\\\/blog\\\/author\\\/sp_admin\\\/#author\"},\"publisher\":{\"@id\":\"https:\\\/\\\/www.zubairalexander.com\\\/blog\\\/#organization\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.zubairalexander.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/10\\\/AlexandersBlog_logo_590x590.jpg\",\"@id\":\"https:\\\/\\\/www.zubairalexander.com\\\/blog\\\/#articleImage\"},\"datePublished\":\"2006-06-09T13:31:15-07:00\",\"dateModified\":\"2007-05-08T13:56:36-07:00\",\"inLanguage\":\"en-US\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.zubairalexander.com\\\/blog\\\/using-sql-injection-to-bypass-security-controls\\\/#webpage\"},\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.zubairalexander.com\\\/blog\\\/using-sql-injection-to-bypass-security-controls\\\/#webpage\"},\"articleSection\":\"Security\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.zubairalexander.com\\\/blog\\\/using-sql-injection-to-bypass-security-controls\\\/#breadcrumblist\",\"itemListElement\":[{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.zubairalexander.com\\\/blog#listItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.zubairalexander.com\\\/blog\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.zubairalexander.com\\\/blog\\\/category\\\/security\\\/#listItem\",\"name\":\"Security\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.zubairalexander.com\\\/blog\\\/category\\\/security\\\/#listItem\",\"position\":2,\"name\":\"Security\",\"item\":\"https:\\\/\\\/www.zubairalexander.com\\\/blog\\\/category\\\/security\\\/\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.zubairalexander.com\\\/blog\\\/using-sql-injection-to-bypass-security-controls\\\/#listItem\",\"name\":\"Using SQL Injection to Bypass Security Controls\"},\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.zubairalexander.com\\\/blog#listItem\",\"name\":\"Home\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.zubairalexander.com\\\/blog\\\/using-sql-injection-to-bypass-security-controls\\\/#listItem\",\"position\":3,\"name\":\"Using SQL Injection to Bypass Security Controls\",\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.zubairalexander.com\\\/blog\\\/category\\\/security\\\/#listItem\",\"name\":\"Security\"}}]},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.zubairalexander.com\\\/blog\\\/#organization\",\"name\":\"Alexander's Blog\",\"description\":\"Sharing knowledge with the global IT community since November 1, 2004\",\"url\":\"https:\\\/\\\/www.zubairalexander.com\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.zubairalexander.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/10\\\/AlexandersBlog_logo_590x590.jpg\",\"@id\":\"https:\\\/\\\/www.zubairalexander.com\\\/blog\\\/using-sql-injection-to-bypass-security-controls\\\/#organizationLogo\"},\"image\":{\"@id\":\"https:\\\/\\\/www.zubairalexander.com\\\/blog\\\/using-sql-injection-to-bypass-security-controls\\\/#organizationLogo\"},\"sameAs\":[\"https:\\\/\\\/twitter.com\\\/zubairalexander\",\"https:\\\/\\\/www.linkedin.com\\\/in\\\/zubairalexander\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.zubairalexander.com\\\/blog\\\/author\\\/sp_admin\\\/#author\",\"url\":\"https:\\\/\\\/www.zubairalexander.com\\\/blog\\\/author\\\/sp_admin\\\/\",\"name\":\"Zubair Alexander\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.zubairalexander.com\\\/blog\\\/using-sql-injection-to-bypass-security-controls\\\/#webpage\",\"url\":\"https:\\\/\\\/www.zubairalexander.com\\\/blog\\\/using-sql-injection-to-bypass-security-controls\\\/\",\"name\":\"Using SQL Injection to Bypass Security Controls | Alexander's Blog\",\"description\":\"To demonstrate some of the security issues, Joel Helgeson of Appiant.net has posted a video that shows how he used SQL injection to bypass security controls on a college Web site. In this video he demonstrates how easy this type of attack can be. If you are a Web developer, this is a good reminder\",\"inLanguage\":\"en-US\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.zubairalexander.com\\\/blog\\\/#website\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.zubairalexander.com\\\/blog\\\/using-sql-injection-to-bypass-security-controls\\\/#breadcrumblist\"},\"author\":{\"@id\":\"https:\\\/\\\/www.zubairalexander.com\\\/blog\\\/author\\\/sp_admin\\\/#author\"},\"creator\":{\"@id\":\"https:\\\/\\\/www.zubairalexander.com\\\/blog\\\/author\\\/sp_admin\\\/#author\"},\"datePublished\":\"2006-06-09T13:31:15-07:00\",\"dateModified\":\"2007-05-08T13:56:36-07:00\"},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.zubairalexander.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.zubairalexander.com\\\/blog\\\/\",\"name\":\"Alexander's Blog\",\"description\":\"Sharing knowledge with the global IT community since November 1, 2004\",\"inLanguage\":\"en-US\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.zubairalexander.com\\\/blog\\\/#organization\"}}]}\n\t\t<\/script>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"Using SQL Injection to Bypass Security Controls | Alexander's Blog","description":"To demonstrate some of the security issues, Joel Helgeson of Appiant.net has posted a video that shows how he used SQL injection to bypass security controls on a college Web site. In this video he demonstrates how easy this type of attack can be. If you are a Web developer, this is a good reminder","canonical_url":"https:\/\/www.zubairalexander.com\/blog\/using-sql-injection-to-bypass-security-controls\/","robots":"max-image-preview:large","keywords":"","webmasterTools":{"google-site-verification":"xUGSODobCBguuxTNOCWOCVwAIhfY39LLtYAQOmExYzw","msvalidate.01":"65829CD0C3C810D64E58EA860413DB21","miscellaneous":""},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.zubairalexander.com\/blog\/using-sql-injection-to-bypass-security-controls\/#article","name":"Using SQL Injection to Bypass Security Controls | Alexander's Blog","headline":"Using SQL Injection to Bypass Security Controls","author":{"@id":"https:\/\/www.zubairalexander.com\/blog\/author\/sp_admin\/#author"},"publisher":{"@id":"https:\/\/www.zubairalexander.com\/blog\/#organization"},"image":{"@type":"ImageObject","url":"https:\/\/www.zubairalexander.com\/blog\/wp-content\/uploads\/2020\/10\/AlexandersBlog_logo_590x590.jpg","@id":"https:\/\/www.zubairalexander.com\/blog\/#articleImage"},"datePublished":"2006-06-09T13:31:15-07:00","dateModified":"2007-05-08T13:56:36-07:00","inLanguage":"en-US","mainEntityOfPage":{"@id":"https:\/\/www.zubairalexander.com\/blog\/using-sql-injection-to-bypass-security-controls\/#webpage"},"isPartOf":{"@id":"https:\/\/www.zubairalexander.com\/blog\/using-sql-injection-to-bypass-security-controls\/#webpage"},"articleSection":"Security"},{"@type":"BreadcrumbList","@id":"https:\/\/www.zubairalexander.com\/blog\/using-sql-injection-to-bypass-security-controls\/#breadcrumblist","itemListElement":[{"@type":"ListItem","@id":"https:\/\/www.zubairalexander.com\/blog#listItem","position":1,"name":"Home","item":"https:\/\/www.zubairalexander.com\/blog","nextItem":{"@type":"ListItem","@id":"https:\/\/www.zubairalexander.com\/blog\/category\/security\/#listItem","name":"Security"}},{"@type":"ListItem","@id":"https:\/\/www.zubairalexander.com\/blog\/category\/security\/#listItem","position":2,"name":"Security","item":"https:\/\/www.zubairalexander.com\/blog\/category\/security\/","nextItem":{"@type":"ListItem","@id":"https:\/\/www.zubairalexander.com\/blog\/using-sql-injection-to-bypass-security-controls\/#listItem","name":"Using SQL Injection to Bypass Security Controls"},"previousItem":{"@type":"ListItem","@id":"https:\/\/www.zubairalexander.com\/blog#listItem","name":"Home"}},{"@type":"ListItem","@id":"https:\/\/www.zubairalexander.com\/blog\/using-sql-injection-to-bypass-security-controls\/#listItem","position":3,"name":"Using SQL Injection to Bypass Security Controls","previousItem":{"@type":"ListItem","@id":"https:\/\/www.zubairalexander.com\/blog\/category\/security\/#listItem","name":"Security"}}]},{"@type":"Organization","@id":"https:\/\/www.zubairalexander.com\/blog\/#organization","name":"Alexander's Blog","description":"Sharing knowledge with the global IT community since November 1, 2004","url":"https:\/\/www.zubairalexander.com\/blog\/","logo":{"@type":"ImageObject","url":"https:\/\/www.zubairalexander.com\/blog\/wp-content\/uploads\/2020\/10\/AlexandersBlog_logo_590x590.jpg","@id":"https:\/\/www.zubairalexander.com\/blog\/using-sql-injection-to-bypass-security-controls\/#organizationLogo"},"image":{"@id":"https:\/\/www.zubairalexander.com\/blog\/using-sql-injection-to-bypass-security-controls\/#organizationLogo"},"sameAs":["https:\/\/twitter.com\/zubairalexander","https:\/\/www.linkedin.com\/in\/zubairalexander"]},{"@type":"Person","@id":"https:\/\/www.zubairalexander.com\/blog\/author\/sp_admin\/#author","url":"https:\/\/www.zubairalexander.com\/blog\/author\/sp_admin\/","name":"Zubair Alexander"},{"@type":"WebPage","@id":"https:\/\/www.zubairalexander.com\/blog\/using-sql-injection-to-bypass-security-controls\/#webpage","url":"https:\/\/www.zubairalexander.com\/blog\/using-sql-injection-to-bypass-security-controls\/","name":"Using SQL Injection to Bypass Security Controls | Alexander's Blog","description":"To demonstrate some of the security issues, Joel Helgeson of Appiant.net has posted a video that shows how he used SQL injection to bypass security controls on a college Web site. In this video he demonstrates how easy this type of attack can be. If you are a Web developer, this is a good reminder","inLanguage":"en-US","isPartOf":{"@id":"https:\/\/www.zubairalexander.com\/blog\/#website"},"breadcrumb":{"@id":"https:\/\/www.zubairalexander.com\/blog\/using-sql-injection-to-bypass-security-controls\/#breadcrumblist"},"author":{"@id":"https:\/\/www.zubairalexander.com\/blog\/author\/sp_admin\/#author"},"creator":{"@id":"https:\/\/www.zubairalexander.com\/blog\/author\/sp_admin\/#author"},"datePublished":"2006-06-09T13:31:15-07:00","dateModified":"2007-05-08T13:56:36-07:00"},{"@type":"WebSite","@id":"https:\/\/www.zubairalexander.com\/blog\/#website","url":"https:\/\/www.zubairalexander.com\/blog\/","name":"Alexander's Blog","description":"Sharing knowledge with the global IT community since November 1, 2004","inLanguage":"en-US","publisher":{"@id":"https:\/\/www.zubairalexander.com\/blog\/#organization"}}]},"og:locale":"en_US","og:site_name":"Alexander's Blog | Sharing knowledge with the global IT community since November 1, 2004","og:type":"article","og:title":"Using SQL Injection to Bypass Security Controls | Alexander's Blog","og:description":"To demonstrate some of the security issues, Joel Helgeson of Appiant.net has posted a video that shows how he used SQL injection to bypass security controls on a college Web site. In this video he demonstrates how easy this type of attack can be. If you are a Web developer, this is a good reminder","og:url":"https:\/\/www.zubairalexander.com\/blog\/using-sql-injection-to-bypass-security-controls\/","og:image":"https:\/\/www.zubairalexander.com\/blog\/wp-content\/uploads\/2004\/11\/AlexandersBlog_logo_590x590.png","og:image:secure_url":"https:\/\/www.zubairalexander.com\/blog\/wp-content\/uploads\/2004\/11\/AlexandersBlog_logo_590x590.png","og:image:width":590,"og:image:height":590,"article:published_time":"2006-06-09T18:31:15+00:00","article:modified_time":"2007-05-08T18:56:36+00:00","twitter:card":"summary_large_image","twitter:site":"@zubairalexander","twitter:title":"Using SQL Injection to Bypass Security Controls | Alexander's Blog","twitter:description":"To demonstrate some of the security issues, Joel Helgeson of Appiant.net has posted a video that shows how he used SQL injection to bypass security controls on a college Web site. In this video he demonstrates how easy this type of attack can be. If you are a Web developer, this is a good reminder","twitter:creator":"@zubairalexander","twitter:image":"https:\/\/www.zubairalexander.com\/blog\/wp-content\/uploads\/2004\/11\/AlexandersBlog_logo_590x590.png"},"aioseo_meta_data":{"post_id":"80","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"location":null,"local_seo":null,"breadcrumb_settings":null,"limit_modified_date":false,"ai":null,"created":"2020-12-21 04:03:07","updated":"2025-06-04 00:18:41","seo_analyzer_scan_date":null},"jetpack_featured_media_url":"","_links":{"self":[{"href":"https:\/\/www.zubairalexander.com\/blog\/wp-json\/wp\/v2\/posts\/80","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.zubairalexander.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.zubairalexander.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.zubairalexander.com\/blog\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/www.zubairalexander.com\/blog\/wp-json\/wp\/v2\/comments?post=80"}],"version-history":[{"count":0,"href":"https:\/\/www.zubairalexander.com\/blog\/wp-json\/wp\/v2\/posts\/80\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.zubairalexander.com\/blog\/wp-json\/wp\/v2\/media?parent=80"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.zubairalexander.com\/blog\/wp-json\/wp\/v2\/categories?post=80"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.zubairalexander.com\/blog\/wp-json\/wp\/v2\/tags?post=80"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}