The OpenNET Project
 
Search (keywords):  SOFT ARTICLES TIPS & TRICKS SECURITY
LINKS NEWS MAN DOCUMENTATION


New SQL Injection Whitepaper


<< Previous INDEX Search src Set bookmark Go to bookmark Next >>
Date: Thu, 31 Jan 2002 15:37:42 -0000
From: Chris Anley <[email protected]>
To: [email protected]
Subject: New SQL Injection Whitepaper

Hi folks,

I've just completed a Microsoft SQL Server 'injection' whitepaper, that can
be downloaded from

http://www.ngssoftware.com/papers/advanced_sql_injection.pdf

At least half of the sites I've audited have been vulnerable to some form of
SQL injection; I think it's important that people fully understand the
issues.

The paper contains information on a variety of attacks, including
second-order SQL injection, automation scripts and audit evasion. It also
discusses input validation and (briefly) secure builds. The intention is to
raise awareness of the rich variety of SQL injection attacks, in order to
encourage people to fix these issues in their applications.

Cheers,

     -chris.

<< Previous INDEX Search src Set bookmark Go to bookmark Next >>



Партнёры:
PostgresPro
Inferno Solutions
Hosting by Hoster.ru
Хостинг:

Закладки на сайте
Проследить за страницей
Created 1996-2025 by Maxim Chirkov
Добавить, Поддержать, Вебмастеру