Suspicious SQL Error Messages

 Original Source: [Sigma source]
Title: Suspicious SQL Error Messages
Status: test
Description:Detects SQL error messages that indicate probing for an injection attack
References:
  -http://www.sqlinjection.net/errors
Author: Bjoern Kimminich
Date: 2017-11-27
modified:2023-02-12
Tags:
  • -'attack.initial-access'
  • -'attack.t1190'
Logsource:
  • category: application
  • product: sql
  • definition: Requirements: application error logs must be collected (with LOG_LEVEL ERROR and above)
Detection:
  keywords:
    - 'quoted string not properly terminated'
    - 'You have an error in your SQL syntax'
    - 'Unclosed quotation mark'
    - 'near "*": syntax error'
    - 'SELECTs to the left and right of UNION do not have the same number of result columns'
  condition:keywords
Falsepositives:
  -A syntax error in MySQL also occurs in non-dynamic (safe) queries if there is an empty in() clause, that may often be the case.
Level: high