SQL injection capstone notes
What a group capstone with DVWA, SQLMap, OWASP ZAP, and Wireshark taught me about injection.
POST #001
For CSCI 400 my group worked through SQL injection against DVWA in a lab environment.
Seeing it three ways
SQLMap automates the attack, ZAP shows the requests, and Wireshark shows what actually goes over the wire. Using all three made the attack concrete instead of abstract.
The fix is boring
Parameterized queries. Once user input can never become part of the SQL text, the whole class of bug goes away.
Thread locked · this board is currently read-only.