Bonjour, j'aurais une petite question à vous poser, est-ce que ce code dans le .htaccess , suffirais à bloquer une possible injection SQL via l'url ?
RewriteEngine on
Options +FollowSymlinks
RewriteCond %{QUERY_STRING} (.*)DECLARE(.*)@(.*) [NC,OR]
RewriteCond %{QUERY_STRING} (.*)SELECT(.*)FROM(.*) [NC,OR]
RewriteCond %{QUERY_STRING} (.*)DELETE(.*)FROM(.*) [NC,OR]
RewriteCond %{QUERY_STRING} (.*)ALTER(%20){1,}TABLE(.*) [NC,OR]
RewriteCond %{QUERY_STRING} (.*)INSERT(%20){1,}INTO(.*) [NC,OR]
RewriteCond %{QUERY_STRING} (.*)UPDATE(.*)SET(.*)(WHERE){0,}(.*) [NC,OR]
RewriteCond %{QUERY_STRING} (.*)DROP(.*) [NC]
RewriteRule (.*) %{QUERY_STRING} [F]