Web Designing, hosting, ecommerce, content and more!
Candidinfo blog is committed to provide you a deeper insight on web development, designing, e-commerce, web hosting, usability, content as well as SEO.
Candidinfo blog is committed to provide you a deeper insight on web development, designing, e-commerce, web hosting, usability, content as well as SEO.

SQL Injection is a technique that exploits the security vulnerability of a website. It usually happens if a user enters either incorrect filter for string characters embedded in SQL statements or input is unexpectedly executed. These errors can harm your website in the long run. At Candidinfo, we employ the latest in cutting edge technologies and makes your e-business error-free. Everything from giving your site a customized open source solution to an updated look and feel, we make the process simple and effective.
Security Compass has introduced a firefox add-on “SQL Inject Me.” It will submit your form and replace the values in the existing form field with strings that are considered as possible attack. This tool will send all the possible database escape string as well as search for any error messages returned. Finally, it will render as HTML format in page.
Once you have installed the addon, go to Tools-> SQL Inject Me-> Open SQL Inject Me Sidebar. You will find a sample form that will proceed an update action into database while form is being posted. To make sure the form is tested, fill in the fields with good values and mark the checkbox.
Here a sample of the tool, after you test the form for all attacks:

Here's is the final output. The result marked with red color background are error messages, which have been returned by
database.

Although, this tool looks for all the possible input that may harm your system but it doesn't provide protection for password hacking, firewall attacks, etc. However, SQL Injection Me is still quite useful and helpful tool for you, as it tests SQL Injection vulnerabilities.Download SQL Injection Me now - to make testing an easy process.
To know more about testing and other web development services, click here.
E-business is more than just selling online or having a website, it is about creating a hold over the ever evolving web world. We at Candidinfo have been continually attempting to stay a step ahead of the developments taking place. Candidinfo blog is committed to provide you a deeper insight on web development, designing, e-commerce, web hosting, usability, content as well as SEO. We bring forth smart web solutions after trying and testing them ourselves.
August 10th, 2009 at 12:26 pm
[…] Here is the original: » Firefox Testing Add-on: SQL Inject Me Candid Software Weblog … […]
August 10th, 2009 at 1:32 pm
[…] View original post here: » Firefox Testing Add-on: SQL Inject Me Candid Software Weblog … […]
August 25th, 2009 at 8:53 pm
Interesting information. Thanks for sharing.
January 31st, 2010 at 3:08 am
Nice thing though there are 2 bugs that popedup in my eyes after 5mins of install:
1) The homepage of the plugin is "http://www.izi-services.nl/" rather than this page we view now, which is rather weird to say the least.
2) The button you can place on your toolbar to toggle the hackbar only works when hackbar is enabled in "View->Toolbars", it's more intuitive if it duplicated the behaviour of the "View->Toolbars->Hackbar" setting as an alias.
February 27th, 2010 at 1:41 pm
I did a lot of development with the E commerce package about 18 months ago (I probably started just before Ubercart started getting traction) and I thought on the whole it was very good.I haven't actually used Ubercart yet, but from the publicity that it is getting recently I'll have to give it a go.
April 16th, 2010 at 11:15 am
So i got this experimental program which will become an add on" for fire fox. how do i test this program on Firefox as if it was an add on?
May 27th, 2010 at 7:29 pm
wauw, I did not know that this tool was avaiable. I have searched and downloaded special software for this called SQL Map or something. This solution is much more easy because I am working with Firefox all the time.
June 3rd, 2010 at 4:20 pm
the developers' and authors' protection, the GPL clearly explains
that there is no warranty for this free software. For both users' and
authors' sake, the GPL requires that modified versions be marked as
changed, so that their problems will not be attributed erroneously to
authors of previous versions.
June 3rd, 2010 at 8:09 pm
The Exploit-Me series was originally introduced at the SecTor conference in Toronto. The slides for the presentation are available for download. Along with this SecTor is making the audio of the talk availabl……….
June 24th, 2010 at 9:11 pm
The Exploit-Me series was originally introduced at the SecTor conference in Toronto. The slides for the presentation are available for download. Along with this SecTor is making the audio of the talk available.
July 24th, 2010 at 7:19 pm
I have 1 table containing user and ordered_product (beside other columns).Now I want to find out - based on a view on product 1 - which user has ordered only product 1 and not product 2.and as a second view which user had ordered both.User with only product 2 will not be looked at.Has someone a good idea?
August 4th, 2010 at 4:43 pm
Information like the one you mentioned here will be very useful to me!.I love books and used to visit bookshops regularly.I just visit your blog.The articles are quite good and I have already used to visit this site regularly.A nice one…
August 6th, 2010 at 3:18 pm
giving your site a customized open source solution to an updated look and feel, we make the process simple and effective.
August 7th, 2010 at 12:22 pm
It appears to me there is another they could impassive still do - archetypes that retain nevertheless to be implemented by additional developers. Single I would cherish to remark is the power to opaque idle apertures. There is precise petite visible discord amid an nimble furthermore unoccupied opening which assembles it susceptible to embark typing in the inexcusable single.
August 14th, 2010 at 5:24 pm
Many web servers return the incorrect syntax error along with the part of the SQL statement that was sent to database server for execution. This situation provides an opportunity to the hacker’s to generate errors by trying various input combinations and get the SQL statement in the error message. After getting the good idea about the existing SQL statement like this, hacker may try other SQL constructs in the injection.
August 19th, 2010 at 4:33 am
Th4t be an epic da shizzi4 post, th4nkie 4it & in da futures we'll be seeing more of it
August 19th, 2010 at 4:34 am
We7ll I8be dat9 ogr6e speekie da speekie, gratz & than4x
August 19th, 2010 at 4:34 am
heb7e sh8at be th34nkie 4it on da posting left & righ8ty
August 26th, 2010 at 6:29 pm
Great post! It is very useful for me.
August 28th, 2010 at 12:01 pm
Firefox Testing Add-on is a good and useful tool.