Title:
Suspicious SQL Error Messages
Status:
test
Description:Detects SQL error messages that indicate probing for an injection attack
References:
-http://www.sqlinjection.net/errors
Author: Bjoern Kimminich
Date: 2017-11-27
modified:2023-02-12
Tags:
- -'attack.initial-access'
- -'attack.t1190'
Logsource:
- category: application
- product: sql
- definition: Requirements: application error logs must be collected (with LOG_LEVEL ERROR and above)
Detection:
keywords:
- 'quoted string not properly terminated'
- 'You have an error in your SQL syntax'
- 'Unclosed quotation mark'
- 'near "*": syntax error'
- 'SELECTs to the left and right of UNION do not have the same number of result columns'
condition:
keywords
Falsepositives:
-A syntax error in MySQL also occurs in non-dynamic (safe) queries if there is an empty in() clause, that may often be the case.
Level:
high