﻿# 介紹幾款好用的 SQL Injection 偵測與防禦工具

微軟最近推出了兩套 SQL Injection 偵測與防禦工具，分別是 [Microsoft Source Code Analyzer for SQL Injection](http://blogs.msdn.com/sqlsecurity/archive/2008/06/24/microsoft-source-code-analyzer-for-sql-injection-june-2008-ctp.aspx) (MSCASI) 與 [URLScan 3.0](https://blogs.iis.net/wadeh/urlscan-v3-0-beta-release/)。

其中 [Microsoft Source Code Analyzer for SQL Injection](http://blogs.msdn.com/sqlsecurity/archive/2008/06/24/microsoft-source-code-analyzer-for-sql-injection-june-2008-ctp.aspx) (MSCASI) 是專門用來分析早期 Active Server Pages (ASP) 程式中的 SQL Injection 漏洞，他會直接分析你的 ASP 原始碼並明確點出你的程式中潛在的 SQL Injection 漏洞在哪裡、潛在的風險、第幾行有問題等（如下圖）。如果你曾經寫過的 ASP 網站年久失修，建議你用這套工具執行看看是否有哪一段程式是有 SQL Injection 漏洞的。另外，微軟在前幾週也發表了一篇關於如何在 ASP 程式中防禦 SQL Injection 的建議（ [Preventing SQL Injections in ASP](http://msdn.microsoft.com/en-us/library/cc676512.aspx)），而這套工具就是依據這篇文章中所寫的幾個規則進行 ASP 原始碼分析的。

[![Microsoft Source Code Analyzer for SQL Injection 執行畫面](https://stwillblogassets.blob.core.windows.net/files/images/external/stwillblogassets.blob.core.windows.net/120cb1811f0cd07f4a1c-image_thumb_3.png)](https://stwillblogassets.blob.core.windows.net/files/images/external/stwillblogassets.blob.core.windows.net/7d74fc9c1b9a9141288d-image_8.png)

由於 [Microsoft Source Code Analyzer for SQL Injection](http://blogs.msdn.com/sqlsecurity/archive/2008/06/24/microsoft-source-code-analyzer-for-sql-injection-june-2008-ctp.aspx) 是指令列程式，你下載後只要解壓縮就能用了，用法很簡單，你只要執行 msscasi\_asp.exe 就會出現使用說明了。

```
G:\asp>msscasi_asp.exeMicrosoft (R) Source Code Analyzer for SQL Injection Version 1.3.30601.30622Copyright (C) Microsoft Corporation.  All rights reserved.Usage: msscasi_asp.exe [/nologo] [/quiet] [/suppress=num;..;num] [/GlobalAsaPath=path] [/IncludePaths=path;..;path] /Input=file.asp ** msscasi_asp failure: no input file specified.
```

一次只能掃瞄一個檔案，底下是一個範例的用法：

```
msscasi_asp.exe /nologo /Input="c:\web1\test.asp"
```

你如果要掃瞄整個網站的 asp 程式你可以寫個批次檔來處理。

另一套軟體 [URLScan 3.0](https://blogs.iis.net/wadeh/urlscan-v3-0-beta-release/) 有別於已經推出五年之久的 [UrlScan 2.5](http://technet.microsoft.com/en-us/security/cc242650.aspx) 版，功能多出了許多，他比較能夠主動偵測 SQL Injection 的攻擊，且目前也完整支援 IIS 7.0，不過未來這些掃瞄功能應該會直接整合進 IIS 7.0 中。

URLScan 3.0 版新增的功能有：

-   Support for query string scanning, including an option to scan an unescaped version of the query string.
-   Change notification for configuration (no more restarts for most settings.)
-   UrlScan can be installed as a site filter.  Different sites can have their own copy, with their own configuration.
-   Escape sequences can be used in the configuration file to express CRLF, a semicolon (normally a comment delimiter) or unprintable characters in rules.
-   Custom rules can be created to scan the URL, query string, a particular header, all headers or combination of these.  The rules can be applied based on the type of file requested.
-   Support for 64 bit IIS worker processes.

另外還有一套由 HP Web Security Research Group 發展出來的一個 SQL injection 偵測工具，叫做 [Scrawlr 1.0](https://web.archive.org/web/20080627144437/http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2008/06/23/finding-sql-injection-with-scrawlr.aspx)，我覺得還挺酷的，用一個比較視覺化的方式偵測你的網站是否包含 SQL Injection 漏洞，只要輸入要檢測的網址，再按下 Start 按鈕就會開始跑了，非常的直覺、好用。如果你的網站被他抓到有漏洞的話，他還可以猜出你的資料庫名稱與相關資訊。

[![Scrawlr 1.0](https://stwillblogassets.blob.core.windows.net/files/images/external/stwillblogassets.blob.core.windows.net/63f7c1dac05ecc74e30e-image_thumb_4.png)](https://stwillblogassets.blob.core.windows.net/files/images/external/stwillblogassets.blob.core.windows.net/25d4d05729ddfa2c8975-image_10.png)

**相關連結**

-   [SQL Injection Defense Tools](https://web.archive.org/web/20080628075407/http://blogs.msdn.com:80/sdl/archive/2008/06/24/sql-injection-defense-tools.aspx)
-   [Microsoft ® Source Code Analyzer for SQL Injection – June 2008 CTP](http://blogs.msdn.com/sqlsecurity/archive/2008/06/24/microsoft-source-code-analyzer-for-sql-injection-june-2008-ctp.aspx)
-   [Giving SQL Injection the Respect it Deserves](https://www.microsoft.com/en-us/security/blog/2008/05/15/giving-sql-injection-the-respect-it-deserves/)
-   [Preventing SQL Injections in ASP](http://msdn.microsoft.com/en-us/library/cc676512.aspx)
-   [Filtering SQL injection from Classic ASP](https://blogs.iis.net/nazim/filtering-sql-injection-from-classic-asp/)
-   [The HP Security Laboratory - Finding SQL Injection with Scrawlr](https://web.archive.org/web/20080627144437/http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2008/06/23/finding-sql-injection-with-scrawlr.aspx)
-   [How To: Protect From Injection Attacks in ASP.NET](http://msdn.microsoft.com/en-us/library/bb355989.aspx)
-   [Coding techniques for protecting against Sql injection](http://forums.asp.net/t/1254125.aspx)
-   [UrlScan v3.0 Beta Release](https://blogs.iis.net/wadeh/urlscan-v3-0-beta-release/)
-   [How To：使用 URLScan](https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2003/cc776918\(v=ws.10\)) ( URLScan 2.5 )
-   [『資料隱碼』SQL Injection的源由與防範之道](http://www.microsoft.com/taiwan/sql/SQL_Injection.htm)
-   [Stop SQL Injection Attacks Before They Stop You](http://msdn.microsoft.com/en-us/magazine/cc163917.aspx)
-   [Microsoft Source Code Analyzer for SQL Injection 工具現已提供下載，可用來尋找 ASP 程式碼中的 SQL 隱碼攻擊弱點](https://web.archive.org/web/20120105211655/http://support.microsoft.com:80/kb/954476)
