View Full Version : safe SQL Injection query
Goomzee
03-05-2012, 07:09 AM
How do i know my site is safe from SQL Injection?
v123shine
03-05-2012, 08:24 PM
Good Question!
Disasterpiece
03-05-2012, 08:40 PM
How can I know that I'm safe from meteroids falling from the sky and hitting my head?
> If they do, you will know :)
v123shine
03-05-2012, 08:51 PM
How can I know that I'm safe from meteroids falling from the sky and hitting my head?
> If they do, you will know :)
Good answer :) :) :)
Goomzee
03-06-2012, 04:04 AM
Please reply someone
You probably can't know for sure. If you didn't write the software or inspect the code yourself then you're trusting the people who developed the software. I guess there have been issues in vbulletin itself, but I think if you have the latest version of vb you're probably pretty safe. But I think the more mods you have installed, the greater your chance that one of them has a flaw that hasn't been found yet.
What you might be able to do to detect it is look over web logs periodically and see if you see anything strange going on. There's also a add-on called zbblock that attempts to detect and block some sql injection, but I used it for a while and found that it also blocked some users who were just doing searches (although it was a year ago so it's possible that the issue has been fixed).
vBulletin® v3.8.12 by vBS, Copyright ©2000-2025, vBulletin Solutions Inc.