|
Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com |
From: Chris Anley (chris
ngssoftware.com)Date: Thu Jan 31 2002 - 09:37:42 CST
Hi folks,
I've just completed a Microsoft SQL Server 'injection' whitepaper, that can
be downloaded from
http://www.ngssoftware.com/papers/advanced_sql_injection.pdf
At least half of the sites I've audited have been vulnerable to some form of
SQL injection; I think it's important that people fully understand the
issues.
The paper contains information on a variety of attacks, including
second-order SQL injection, automation scripts and audit evasion. It also
discusses input validation and (briefly) secure builds. The intention is to
raise awareness of the rich variety of SQL injection attacks, in order to
encourage people to fix these issues in their applications.
Cheers,
-chris.
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]