Login     Register
Select Website 

Recruitment Directory's Blog - Australia's #1 Recruitment Technology Blog!

Back to Menu Back to Menu

How secure is your Recruitment website? Part 4 - SQL Injection

Posted By: Thomas Shaw, 11:17am Wednesday 19 August 2009    Email Article    Print Article

Database security is a huge issue at the moment - imaging having your whole database stolen and distributed to your competitors or being used for identity theft? SQL Injection attacks present a serious threat to the security of a recruitment website and it is essential that adequate countermeasures are taken to prevent such an attack from being successful.

I briefly talked about a form of SQL injection in a previous article HTML Special Character #39 - The Apostrophe showing how easy it is to break a search form and how much the industry is in trouble.

SQL injection is a code injection technique that exploits a security vulnerability occurring in the database layer of an application. The vulnerability is present when user input is either incorrectly filtered for string literal escape characters embedded in SQL statements or user input is not strongly typed and thereby unexpectedly executed.

Your recruitment database contains very sensitive user information including: passwords, bank details, tax file numbers, contact details, email address, date of birth, address etc. Even if you store your confidential data securely, you don’t want anything to be accessible to anyone but yourself.

It’s somewhat shameful that there are so many successful SQL Injection attacks occurring, because it is EXTREMELY simple to avoid vulnerabilities in your code.

One of the most effective methods of preventing SQL injection from being used is to thoroughly validate EVERY SINGLE input from the user, by identifying all possible meta-characters which could be utilised by the database system and filtering them out.

Be proactive in computer security. A combination of security measures such as; validation, neutralizing meta-characters, restricting error messages and limiting access rights to the web server can be used to comprehensively protect your website. 

Don't think it will never happen to you.




Article URL: http://www.recruitmentdirectory.com.au/Blog/how-secure-is-your-recruitment-website-part-4-sql-injection-a250.html

Article Tags: identity theft database security apostrophe hack testing job search form insecure sql injection malicious code recruitment websites job board security hacking

Comments Hide Comments (0)

Feel free to join in on the conversation. All comments are moderated before publishing. Comments posted by subscribers don't necessarily reflect the views of Recruitment Directory.

Your Name: * Required
Your Email Address: * Required
Website URL:
Comments: * Required
 


Back to Menu Back to Menu



Random Blog Articles

LinkedIn Job Referrals BETA
Published: 5:10pm Monday 30 March 2009

Is mobile going to become the recruitment platform of choice?
Published: 3:29pm Wednesday 16 December 2009

Improving your Recruitment Website - jQuery Modal Boxes
Published: 10:55pm Tuesday 29 September 2009

Hippo Jobs appoints Administrators
Published: 8:53pm Tuesday 24 March 2009

Recruitment Directory closes MySpace job search applications
Published: 3:24pm Thursday 29 October 2009


Newsletter Mailing List

Stay informed of current news, upcoming events and promotional offers.

Top 25 Most Influential

Latest Blog Comments

frustrated jobseeker - 1:27pm Tuesday 31 August 2010
Are you a Social Recruitment wanker?

Jason - 11:16am Wednesday 18 August 2010
IT Video Resume - Killa Appz

David Lyons - 5:17pm Friday 13 August 2010
Plan for the worst

DmitryK - 6:06pm Monday 09 August 2010
OWASP Top 10 and your Recruitment Website - Part 1

Jim Manico - 5:28pm Monday 09 August 2010
OWASP Top 10 and your Recruitment Website - Part 1

Steve Ludlow - 12:28pm Friday 06 August 2010
Are you a Social Recruitment wanker?

Brad Stewart - 10:45am Tuesday 03 August 2010
2010 Email Marketing Benchmark Report - HR/Recruitment Sector

Adam Crow - 5:23am Tuesday 03 August 2010
Plan for the worst

BryanB - 8:23am Friday 23 July 2010
Job ad of the month - I'm tired of writing boring adverts for boring Recruitment Consultants

robyn - 11:11pm Thursday 22 July 2010
Social Recruiting is a dirty word

Upcoming Webinars