What is SQL injection?
Your website stores things like users and orders in a database. A database is a digital filing cabinet. SQL is the language used to ask the database for information.
In an SQL injection attack, a bad person types SQL commands into a form or web address. If the site is not careful, the database obeys them. The attacker may read private data or delete things. It is like tricking a librarian by writing a fake order on a request slip.
What is a WAF?
A WAF is a Web Application Firewall. A firewall is a guard that checks traffic. A WAF reads each web request and looks for dangerous patterns, such as ' OR 1=1 -- or UNION SELECT. If it finds one, it stops the request. The attack never reaches your site.
A common WAF engine is ModSecurity. A WAF also comes as a service from other companies. Ask Hostvento support which WAF your plan can use.
Steps with ModSecurity
These steps assume ModSecurity is available. On a shared account it is usually set up by the host. On a VPS or dedicated server you need root access.
- Turn on ModSecurity. In cPanel, look under Security for ModSecurity. In Plesk, use Web Application Firewall.
- Switch the engine to On. Do not choose "Detection only". That mode logs attacks but does not block them.
- Install a rule set. A rule set is a ready-made list of patterns. The OWASP Core Rule Set is a well-known free one. On a server, WHM can install it under Security Center, then ModSecurity Vendors.
- Make sure the SQL injection rules are on.
- Test your site. Open pages and use forms to confirm normal use still works.
Test the block
Type this into your browser address bar, using your own domain:
https://example.com/?id=1' OR '1'='1
A working WAF shows an error such as "403 Forbidden". Only test on your own site.
Check the logs
The WAF writes each block to a log. Look for lines with words like SQL Injection Attack. If a good visitor gets blocked, you can add an exception for that one rule.
Need help? Open a support ticket.
Quick recap
- SQL injection tricks a database with fake commands.
- A WAF reads each request and blocks bad ones.
- Turn the engine On and load a rule set.
- Test and watch the logs.
- Keep your software updated too.