title: Suspicious SQL Error Messages status: experimental description: Detects SQL error messages that indicate probing for an injection attack author: Bjoern Kimminich references: - http://www.sqlinjection.net/errors logsource: category: application product: sql detection: keywords: # Oracle - quoted string not properly terminated # MySQL - You have an error in your SQL syntax # SQL Server - Unclosed quotation mark # SQLite - 'near "*": syntax error' - SELECTs to the left and right of UNION do not have the same number of result columns condition: keywords falsepositives: - Application bugs level: high