Flash Sale:75% Off Hosting + Free DomainEnds in13h47m14sView Plans
Hostvento logoHostvento

How to Block SQL Injection With a WAF

This guide explains SQL injection and shows how a web application firewall can stop it before it reaches your site.

Firewall2 min read5 steps

What is SQL injection?

Your website stores things like users and orders in a database. A database is a digital filing cabinet. SQL is the language used to ask the database for information.

In an SQL injection attack, a bad person types SQL commands into a form or web address. If the site is not careful, the database obeys them. The attacker may read private data or delete things. It is like tricking a librarian by writing a fake order on a request slip.

What is a WAF?

A WAF is a Web Application Firewall. A firewall is a guard that checks traffic. A WAF reads each web request and looks for dangerous patterns, such as ' OR 1=1 -- or UNION SELECT. If it finds one, it stops the request. The attack never reaches your site.

A common WAF engine is ModSecurity. A WAF also comes as a service from other companies. Ask Hostvento support which WAF your plan can use.

Steps with ModSecurity

These steps assume ModSecurity is available. On a shared account it is usually set up by the host. On a VPS or dedicated server you need root access.

  1. Turn on ModSecurity. In cPanel, look under Security for ModSecurity. In Plesk, use Web Application Firewall.
  2. Switch the engine to On. Do not choose "Detection only". That mode logs attacks but does not block them.
  3. Install a rule set. A rule set is a ready-made list of patterns. The OWASP Core Rule Set is a well-known free one. On a server, WHM can install it under Security Center, then ModSecurity Vendors.
  4. Make sure the SQL injection rules are on.
  5. Test your site. Open pages and use forms to confirm normal use still works.

Test the block

Type this into your browser address bar, using your own domain:

https://example.com/?id=1' OR '1'='1

A working WAF shows an error such as "403 Forbidden". Only test on your own site.

Check the logs

The WAF writes each block to a log. Look for lines with words like SQL Injection Attack. If a good visitor gets blocked, you can add an exception for that one rule.

Tip: A WAF is one layer, not the whole wall. Also keep your website software, themes and plugins up to date, and use strong passwords. Take regular backups.

Need help? Open a support ticket.

Quick recap

  • SQL injection tricks a database with fake commands.
  • A WAF reads each request and blocks bad ones.
  • Turn the engine On and load a rule set.
  • Test and watch the logs.
  • Keep your software updated too.