{"id":2664,"date":"2022-04-29T12:28:43","date_gmt":"2022-04-29T17:28:43","guid":{"rendered":"https:\/\/xlinesoft.com\/blog\/?p=2664"},"modified":"2022-10-14T17:00:39","modified_gmt":"2022-10-14T22:00:39","slug":"preventing-sql-injection-in-low-code-web-applications","status":"publish","type":"post","link":"https:\/\/xlinesoft.com\/blog\/2022\/04\/29\/preventing-sql-injection-in-low-code-web-applications\/","title":{"rendered":"Preventing SQL injection in low-code web applications"},"content":{"rendered":"<p>The main difference no-code and low-code applications is that you can easily extend low-code applications by adding your own code. This gives you both power and responsibility and we are going to talk about some typical mistakes people do while adding their own code. <\/p>\n<p>Let me show you an example of the code one our clients were using in BeforeLogin event:<\/p>\n<div class=\"my-syntax-highlighter\">\n<pre><textarea id=\"mshighlighter\" class=\"mshighlighter\" language=\"php\" name=\"mshighlighter\" >\r\n$rs = DB::Query(\"select * from users where username like '\".$username.\"'\");\r\n$data = $rs->fetchAssoc();\r\n...<\/textarea><\/pre>\n<\/div>\n<p>Can you tell what is wrong here? If not, keep reading. <\/p>\n<p><a href=\"https:\/\/xlinesoft.com\/blog\/wp-content\/uploads\/2022\/04\/fly-d-OQptsc4P3NM-unsplash.jpg\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/xlinesoft.com\/blog\/wp-content\/uploads\/2022\/04\/fly-d-OQptsc4P3NM-unsplash-600x400.jpg\" alt=\"\" width=\"600\" height=\"400\" class=\"alignnone size-medium wp-image-2667\" srcset=\"https:\/\/xlinesoft.com\/blog\/wp-content\/uploads\/2022\/04\/fly-d-OQptsc4P3NM-unsplash-600x400.jpg 600w, https:\/\/xlinesoft.com\/blog\/wp-content\/uploads\/2022\/04\/fly-d-OQptsc4P3NM-unsplash-768x512.jpg 768w, https:\/\/xlinesoft.com\/blog\/wp-content\/uploads\/2022\/04\/fly-d-OQptsc4P3NM-unsplash-1024x683.jpg 1024w\" sizes=\"auto, (max-width: 600px) 100vw, 600px\" \/><\/a><br \/>\n<!--more--><\/p>\n<p>The problem is that the $username variable is inserted into a SQL Query as is and it opens the door for SQL injection. Every time you pass something that the user entered directly into a SQL Query you are in trouble. The attackers will be able to access your sensitive data or even make some changes to it. <\/p>\n<p>The correct approach is to use the <a href=\"https:\/\/xlinesoft.com\/phprunner\/docs\/db_preparesql.htm\">PrepareSQL<\/a> function. This way the input will be properly escaped eliminating all potential SQL injection risks. <\/p>\n<div class=\"my-syntax-highlighter\">\n<pre><textarea id=\"mshighlighter\" class=\"mshighlighter\" language=\"php\" name=\"mshighlighter\" >\r\n$sql = DB::PrepareSQL(\"select * from users where username like ':1'\", $username);\r\n$rs = DB::Query($sql);\r\n$data = $rs->fetchAssoc();\r\n...<\/textarea><\/pre>\n<\/div>\n<p>This little change will make your life so much easier. <\/p>\n<p>Additional reading:<br \/>\n<a href=\"https:\/\/xlinesoft.com\/blog\/2021\/06\/17\/secure-low-code-web-applications\/\">Building secure low-code web applications<\/a> (Section 11)<\/p>\n<p>We also added SQL injection as one of the topics of the <a href=\"https:\/\/xlinesoft.com\/blog\/2022\/02\/15\/devquest-contest-with-prizes\/\">DevQuest contest<\/a> (step 8).  <\/p>\n","protected":false},"excerpt":{"rendered":"<p>The main difference no-code and low-code applications is that you can easily extend low-code applications by adding your own code. This gives you both power and responsibility and we are going to talk about some typical mistakes people do while adding their own code. Let me show you an example of the code one our clients were using in BeforeLogin event: $rs = DB::Query(&#8220;select * from users where username like &#8216;&#8221;.$username.&#8221;&#8216;&#8221;); $data = $rs->fetchAssoc(); &#8230; Can you tell what is wrong here? If not, keep&#8230;<span class=\"clearfix clearfix-post\"><\/span><a href=\"https:\/\/xlinesoft.com\/blog\/2022\/04\/29\/preventing-sql-injection-in-low-code-web-applications\/\" class=\"more-link\">Continue Reading <span class=\"screen-reader-text\">&#8220;Preventing SQL injection in low-code web applications&#8221;<\/span> <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[16,10,1,8],"tags":[],"class_list":["post-2664","post","type-post","status-publish","format-standard","hentry","category-asp-net","category-news","category-php-category","category-tutorials"],"_links":{"self":[{"href":"https:\/\/xlinesoft.com\/blog\/wp-json\/wp\/v2\/posts\/2664","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/xlinesoft.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/xlinesoft.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/xlinesoft.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/xlinesoft.com\/blog\/wp-json\/wp\/v2\/comments?post=2664"}],"version-history":[{"count":7,"href":"https:\/\/xlinesoft.com\/blog\/wp-json\/wp\/v2\/posts\/2664\/revisions"}],"predecessor-version":[{"id":2895,"href":"https:\/\/xlinesoft.com\/blog\/wp-json\/wp\/v2\/posts\/2664\/revisions\/2895"}],"wp:attachment":[{"href":"https:\/\/xlinesoft.com\/blog\/wp-json\/wp\/v2\/media?parent=2664"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/xlinesoft.com\/blog\/wp-json\/wp\/v2\/categories?post=2664"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/xlinesoft.com\/blog\/wp-json\/wp\/v2\/tags?post=2664"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}