# sql-sniffer

> A watchdog for sensitive Database commands and transactions that (when given a text string) will return an array of recognized sensitive SQL phrases if present

Latest version **0.0.1** (published 2016-12-08) · MIT license · 0 weekly downloads

## Install

```sh
npm install sql-sniffer
pnpm add sql-sniffer
yarn add sql-sniffer
bun add sql-sniffer
```

## Health

**Score 15/100 (F)** — status: abandoned.

Positive: no vulnerabilities.

Warnings: low downloads; no types; no esm support; pre 1.0.

Negative: abandoned; low maintenance score.

## Facts

| | |
|---|---|
| Version | 0.0.1 |
| Published | 2016-12-08 |
| First published | 2016-12-08 |
| Weekly downloads | 0 |
| License | MIT |
| TypeScript types | none |
| Module format | CommonJS |
| Dependencies | 0 |
| Known vulnerabilities | 0 |
| Install scripts | no |
| GitHub stars | 0 |
| Author | David Maciejewski |
| Maintainers | dmaciejewski |
| Keywords | data, database, Db, DB, db, layer, node, warehouse, information, transaction, injection, business, mine, mining, SQL, PLSQL, PL/SQL, select, insert, statements, query, queries, querying, clauses, ETL, add-on, API, tool, library, module, oracledb, oracle, ora, OCI, 10g, 11g, 12c |

## Links

- npm: https://www.npmjs.com/package/sql-sniffer
- Repository: https://github.com/dmaciejewski1/sql-sniffer
- Homepage: https://github.com/dmaciejewski1/sql-sniffer#readme
- Issues: https://github.com/dmaciejewski1/sql-sniffer/issues
- npm.io page: https://npm.io/package/sql-sniffer

## Alternatives

- [gamedig](https://npm.io/package/gamedig.md) — 29.3K weekly downloads
- [join-monster](https://npm.io/package/join-monster.md) — 12.8K weekly downloads
- [masked](https://npm.io/package/masked.md) — 5.5K weekly downloads
- [@comunica/actor-query-process-explain-logical](https://npm.io/package/@comunica/actor-query-process-explain-logical.md) — 4.7K weekly downloads
- [@veracity/vui](https://npm.io/package/@veracity/vui.md) — 4.6K weekly downloads

## Recent versions

- 0.0.1 (latest) — 2016-12-08

## README

# sql-sniffer
 Given a string, will return an array of recognize phrases (if present within
 that string) that pertain to certain System, Data Dictionary, Anonymous Block,
 DML or DDL database function.

## Usage
A simple watchdog for sensitive Database commands and transactions.

## Installation

```
npm install sql-sniffer
```


## Recognized Phrase Patterns:
All patterns are case insensitive


### Key:

|symbol| function                                                                           |
|------|------------------------------------------------------------------------------------|
|  *   | any one of the folowing characters or combos-->   ;   '   \"  --  \   /*   \'      |
| ...  | any white space between                                                            |
| ..W..| any white space and/or words between                                               |
|   C  | any "\w" character                                                                 |



### Patterns:

#### Category: Removal

|pattern|a.k.a.|
|-------|------|
|*...truncate...table|* truncate table|
|*...drop...table|* drop table|
|*...drop...procedure|* drop procedure|
|*...drop...package|* drop package|
|*...drop...function|* drop function|
|*...drop...index|* drop index|
|*...drop...bitmap...index|* drop bitmap index|
|*...drop...unique...index|* drop unique index|
|*...drop...materialized...view|* drop materialized view|
|*...drop...view|* drop view|
|*...drop...trigger|* drop trigger|
|*...drop...type|* drop type|
|*...delete...from|* delete from|
|*...purge...table|* purge table|
|*...purge...recyclebin|* purge recyclebin|


#### Category: DDL

|pattern|a.k.a.|
|-------|------|
|*...create...or...replace|* create or replace|
|*...create...table|* create table|
|*...alter...table|* alter table|
|*...create...procedure|* create table|
|*...create...package|* create package|
|*...create...function|* create function|
|*...create...index|* create index|
|*...alter...index..W..rebuild|* alter index [TEXT HERE] rebuild|
|*...alter...index..W..rename|* alter index [TEXT HERE] rename|
|*...create...bitmap...index|* create bitmap index|
|*...create...unique..index|* create unique index|
|*...create...materialized view|* create materialized view|
|*...create...view|* create view|
|*...alter...view|* alter view|
|*...create...trigger|* create trigger|
|*...create...type...as|* create type as|


#### Category: System

|pattern|a.k.a.|
|-------|------|
|*...alter...system...set|* alter system|
|*...shutdown...normal|* shutdown normal|
|*...shutdown...immediate|* shutdown immediate|
|*...shutdown...transactional|* shutdown transactional|
|*...shutdown...abort|* shutdown abort|


#### Category: DML

|pattern|a.k.a.|
|-------|------|
|*...update...set|* update set|
|*...insert...into|* insert into|
|*...insert...all...into|* insert all into|
|*...merge...into..W..using|* merge into [TEXT HERE] using|


#### Category: Anonymous Block

|pattern|a.k.a.|
|-------|------|
|*...begin..W..;...end|begin [TEXT HERE]; end|
|*...sys.C|sys.[TEXT HERE]|
|*...execute immediate|execute immediate|
|*...&&|&&|


#### Category: Data Dictionary

|pattern|a.k.a.|
|-------|------|
|v$|v$|
|from..W..all_|from [TEXT HERE] all_|
|from..W..dba_|from [TEXT HERE] dba_|
|from..W..user_|from [TEXT HERE] user_|

#### Category: Additional Patterns

|pattern|a.k.a.|
|-------|------|
|1...=...1...--|1=1--|
|1...=...1...#|1=1#|
|1...=...1.../*|1=1/*|
|'...1...'...=...'...1...--|'1'='1--|
|admin...'...--|admin'--|
|admin...'...#|admin'#|
|admin...'.../*|admin'/*|

---
_Source: https://npm.io/package/sql-sniffer · Machine-readable twin of the npm.io package page. Health data is recomputed on every publish._
