Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Susceptibility to SQL Injection like Bobby Tables? #3141

Closed
maphew opened this issue Nov 22, 2022 · 2 comments
Closed

Susceptibility to SQL Injection like Bobby Tables? #3141

maphew opened this issue Nov 22, 2022 · 2 comments

Comments

@maphew
Copy link

maphew commented Nov 22, 2022

Issue description

In the Known docs under installing on common hosting providers the following how-to is linked for DreamHost:
How to Install the Known platform on a Dreamhost shared server (Oct 2017)
https://www.kiaikim.com/2017/how-to-install-the-known-platform-on-a-dreamhost-shared/

Looking at other posts on the same site the author followed up with:
Surviving a Bobby Tables Attack (dated Mar 2021 but seems to describe 2018?)
https://www.kiaikim.com/2021/surviving-a-bobby-tables-attack/

Why is this important?

I didn't find any issues mentioning SQL Injection or Bobby Tables security or mitigation measures that have been taken. This leads to questions of whether Known has any protection measures against sql injection and similar issues.

Who does this affect?

Possibly everyone.

@benwerd
Copy link
Member

benwerd commented Dec 11, 2022

Known uses a database library that automatically filters database queries in order to prevent SQL injection attacks. I wasn't aware of this particular post, nor am I aware of successful SQL injection attacks against Known sites. I'm investigating.

@benwerd
Copy link
Member

benwerd commented Oct 23, 2023

I've established that this was not related to Known's core code or database engine. Closing the issue out.

@benwerd benwerd closed this as completed Oct 23, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants