Deploying a WAF can help detect and block common SQL injection payloads found in URL strings before they reach the application server.
Replace the numbers with data extraction queries: http://example.com/page.php?id=-1 UNION SELECT 1, database(), user(), 4-- - .