Injection attacks are a prevalent and dangerous category of security vulnerabilities that pose significant threats to data integrity, confidentiality, and availability in modern applications. These attacks occur when untrusted data is sent to an interpreter as part of a command or query, allowing attackers to inject malicious code or commands that can manipulate the application's behavior.
Various types of injection attacks exist, each exploiting different systems and technologies, but they all share the same underlying principle: the failure to validate and sanitize user input properly.
The consequences of successful injection attacks can be severe, ranging from unauthorized access to sensitive information and data corruption to complete system compromise. This paper explores the various types of injection attacks, their mechanisms, real-world examples, and effective mitigation strategies to protect applications from these pervasive threats.
Table of Contents:
00:00 - Introduction
00:34 - Injection Attack Definition
01:47 - SQL Injection
03:50 - NoSQL Injection
05:03 - Object Serialization
07:13 - OS Command Injection
08:05 - LDAP Injection
09:14 - XML Injection
12:19 - Attack Examples
12:23 - SQL Injection Example
12:38 - NoSQL Injection Example
13:02 - OS Command Injection Example
14:10 - LDAP Injection Example
15:01 - XML Injection Example
=====
Video Script/Study Guide
https://adventuresinsecurity.com/_Sec...
=====
Selected Bibliography
Bothra, H. (2023, February 23). Introduction to LDAP Injection Attack. Www.cobalt.io. https://www.cobalt.io/blog/introducti...
Dizdar, A. (2022, May 29). Command Injection: How it Works and 5 Ways to Protect Yourself. Bright Security. https://brightsec.com/blog/os-command...
Erickson, J. (2022). What is JSON? Oracle.com. https://www.oracle.com/database/what-...
Hazelcast. (n.d.). What is serialization and how does it work? Hazelcast. Retrieved September 16, 2024, from https://hazelcast.com/glossary/serial...
Hofesh, B. (2022, March 8). SQL Injection Attack: Real Life Attacks and Code Examples. Bright Security. https://brightsec.com/blog/sql-inject...
Kime, C. (2023, May 16). How to Prevent SQL Injection Attacks | eSecurity Planet. ESecurityPlanet. https://www.esecurityplanet.com/threa...
Maurya, V. (2023, August 2). XML Attack or XXE, Impact, Techniques to Attack, Mitigation. BIN-FIN TECH; BIN-FIN TECH. https://binfintech.com/xml-attack-ext...
OWASP. (n.d.-a). OS Command Injection Defense - OWASP Cheat Sheet Series. Cheatsheetseries.owasp.org. Retrieved September 17, 2024, from https://cheatsheetseries.owasp.org/ch...
OWASP. (n.d.-b). SQL Injection Prevention · OWASP Cheat Sheet Series. Owasp.org; Owasp. Retrieved September 16, 2024, from https://cheatsheetseries.owasp.org/ch...
OWASP. (n.d.-c). XML External Entity Prevention. Cheatsheetseries.owasp.org. Retrieved September 17, 2024, from https://cheatsheetseries.owasp.org/ch...
OWASP. (2019). LDAP Injection Prevention · OWASP Cheat Sheet Series. Owasp.org. https://cheatsheetseries.owasp.org/ch...
StackHawk. (2022, March 12). Secure .NET: Mitigating XML External Entities (XXE) Threats. StackHawk. https://www.stackhawk.com/blog/net-xm...
W3Schools. (2019). SQL Stored Procedures. W3schools.com. https://www.w3schools.com/sql/sql_sto...