Skip to contentExploitQuest

Lesson 6 of 6 in SQL Injection

Catch It Next Time

The fix stops today's injection. Detection is what you write so the next one pages you at 3am instead of being found by a customer six months later — an alert on the telemetry you just learned to read, and a test that fails if the hole ever reopens.

3 min read

Not yet reviewed

Wrenlearner

The query is parameterised now. The attack is dead. Are we not done?

Rookmentor

The attack is dead on that one query. But you fixed a hundred queries this year and you are human. Detection is the admission that a fix can be undone — by a teammate, by a refactor, by next year's rush — and it makes the undoing loud.

From reading the log to being paged by it

In the last lesson you read the injection in the query log with your own eyes. Detection is writing down what you noticed so a machine notices it for you, at 3am, when no one is looking. You are turning a thing you can recognise into a thing that recognises itself.

Alert: SQL errors from a single user
  when a client causes > 5 database errors in 1 minute
  → page on-call; likely payload tuning in progress

Alert: tautology / UNION in a query
  when a logged query matches  OR 1=1   or   UNION SELECT
  → raise a ticket; a search box does not write these
  1. Line 1The error burst you saw a defender notice. It fires while the attacker is still tuning, which is the best possible time — before the working payload exists.
  2. Line 5A content signal, not just a volume one. It can be noisy, so it raises a ticket rather than waking someone; the value is a trail, not a siren.

Alerts watch production. A test watches the code, and it is the cheaper, surer half: a single test that sends ' OR 1=1 -- at the endpoint and asserts it does not return every row will fail the build the moment anyone reintroduces string-building — which is exactly how a closed hole quietly reopens.

A fix, and nothing watching it

Parameterise the query.
Trust it stays parameterised forever.

A fix that stays fixed

Parameterise the query.
A test that fails if injection ever works again.
An alert if a payload reaches production.

The right column is the difference between fixing a bug and keeping it fixed. The test catches the regression before it ships; the alert catches the one that slips past the test. A fix with neither is a fix with a shelf life.

Why is a named regression test often more valuable than the production alert, even though the alert is what "catches attackers"?