Login     Register
Select Website 

Recruitment Directory's Blog - Australia's #1 Recruitment Technology Blog!

Back to Menu Back to Menu


How secure is your Recruitment website? Part 4 - SQL Injection

Author: Thomas Shaw
Date: 11:17am Wednesday 19 August 2009

  Email Article Email Article   SMS Article SMS Article   Print Article Print Article

Database security is a huge issue at the moment - imaging having your whole database stolen and distributed to your competitors or being used for identity theft? SQL Injection attacks present a serious threat to the security of a recruitment website and it is essential that adequate countermeasures are taken to prevent such an attack from being successful.

I briefly talked about a form of SQL injection in a previous article HTML Special Character #39 - The Apostrophe showing how easy it is to break a search form and how much the industry is in trouble.

SQL injection is a code injection technique that exploits a security vulnerability occurring in the database layer of an application. The vulnerability is present when user input is either incorrectly filtered for string literal escape characters embedded in SQL statements or user input is not strongly typed and thereby unexpectedly executed.

Your recruitment database contains very sensitive user information including: passwords, bank details, tax file numbers, contact details, email address, date of birth, address etc. Even if you store your confidential data securely, you don’t want anything to be accessible to anyone but yourself.

It’s somewhat shameful that there are so many successful SQL Injection attacks occurring, because it is EXTREMELY simple to avoid vulnerabilities in your code.

One of the most effective methods of preventing SQL injection from being used is to thoroughly validate EVERY SINGLE input from the user, by identifying all possible meta-characters which could be utilised by the database system and filtering them out.

Be proactive in computer security. A combination of security measures such as; validation, neutralizing meta-characters, restricting error messages and limiting access rights to the web server can be used to comprehensively protect your website. 

Don't think it will never happen to you.




Direct URL: http://www.recruitmentdirectory.com.au/Blog/how-secure-is-your-recruitment-website-part-4-sql-injection-a250.html

Tags: identity theft database security apostrophe hack testing job search form insecure sql injection malicious code recruitment websites job board security hacking

Comments Hide Comments (0)

Feel free to join in on the conversation. All comments are moderated before publishing. Comments posted by subscribers don't necessarily reflect the views of Recruitment Directory.

Your Name: * Required
Your Email Address: * Required
Website URL:
Comments: * Required
 


Back to Menu Back to Menu



Random Blog Articles

Is your Job Application Form redirecting candidate applications to identity thieves?
Published: 1:52pm Wednesday 10 February 2010

Ethical Considerations when Drug Testing in the Workplace
Published: 7:05pm Monday 01 June 2009

Kan je vertalen?
Published: 1:51pm Tuesday 13 October 2009

Review of Oracle Recruiter
Published: 12:02am Thursday 22 January 2009

Recruitment Directory launches live Technology Webinars
Published: 2:56pm Thursday 19 March 2009


Newsletter Mailing List

Stay informed of current news, upcoming events and promotional offers.

To subscribe to our mailing list, enter your email address below.

Latest Blog Comments

Andrea - 5:56pm Thursday 11 March 2010
Bluetooth Marketing for Career Expos/Job Fairs

Amelia - 9:18am Saturday 06 March 2010
10 Things We Hate About Recruitment Companies

Gareth Jenkins - 9:32pm Wednesday 03 March 2010
Mobile Device Statistics & Mobile Application behaviour. AdMob Mobile Metrics report

Brian - 8:34pm Wednesday 03 March 2010
Cut the fat. 1 job per job advert

Ann - 9:56am Tuesday 02 March 2010
Recruiters decrease the use of Niche Job Boards, Social Networking sites and Refer a Friend Incentives to source candidates?

AER Head - 10:56am Friday 26 February 2010
Job Board Statistics - January 2010

Kelly Magowan - 7:09pm Tuesday 23 February 2010
Congratulations Thomas. Top 25 Most Influential Online Recruiters!

Clayton Wehner - 1:26pm Tuesday 23 February 2010
Congratulations Thomas. Top 25 Most Influential Online Recruiters!

Michelle Rea - 10:30pm Monday 22 February 2010
Creating an iphone enabled job site

Jay Weerasekara - 6:55pm Monday 22 February 2010
Congratulations Thomas. Top 25 Most Influential Online Recruiters!

Upcoming Webinars