Drupal, one of the top content management systems around, warned its users that if their sites had not been updated with an October 15, 2014 released security patch they should consider them compromised. The public announcement from last year to all Drupal users was warning of an SQL injection attack that had been discovered a couple of weeks prior, which had compromised 12 million Drupal 7 widely used sites. Users were asked to update their sites immediately with Drupal 7.32 not more than seven hours after the release of the vulnerability announcement.
Towards dealing with SQL injections (SQLi) attacks, it is important to detect them first and following it with a thorough investigation. If an attack is confirmed, you might want to ask yourself when the attack happened, where the attack took place, the widespread nature of the attack, whether there were any tables or files overwritten and the identity of the attack and if the attack is extensive.
There are three ways to stay on top of SQLi attacks.
Network IDS to Spot the Attacks
Most network IDs usually have an SQLi attack detection feature built-in, which make it possible to monitor every connection request emanating from a web server. The same intrusion detection comes with ingrained correlation directives for spotting all manner of activities that show there is a SQLi attack. The manner of the injection threat is also changing all the time and network intrusion detection signatures receive weekly updates as per threat studies done to ensure you remain on top of new attacks. This is where keeping SQL performance in mind begins to affect more than just speed.
File Activity Watch to Detect SQLi Through Host Intrusion Detection
Unified security management with intrusion detection host-based system can help you to remain on the lookout of SQLi. The detection system allows the user to monitor activity on servers locally. The intrusion detection system is installed on internet servers and parses logs on the IIS or Apache server. Changes occurring on files are also monitored ensuring tables and files in a database that were attacked are clearly visible.
Threat Intelligence in Real-time
Most security management systems recognize threat intelligence networks in real-time known as OTX (Open Threat Exchange) that finds out connections where bad actors are clearly deciphered. Known as malicious attackers or malicious hosts, their IPs appear on the OTX as a result of attacking other contributors to the OTX as well as having been identified as threats by other services that share intelligence. These malicious attackers can also be identified through independent research.
Remember an SQL server that performs faster is a wonderful idea but it has to be free of SQLi attacks. By identifying performance issues through a database performance analyzer, you can establish baseline and display trends on a number of things such as lazy writes, table scans and page life expectancy among others.
Remember that with any SQLi the hacker is able to compromise a specific website easily without any requirement for authentication where the attack can easily disappear without any trace. The vulnerability is usually within the Drupal Core, essentially made to help prevent SQLi attacks. Exploiting this flow helps hackers to steal massive personal data in websites.