Christa Carpentiere

extremely precious tagline here

<November 2008>
SuMoTuWeThFrSa
2627282930311
2345678
9101112131415
16171819202122
23242526272829
30123456


Navigation

Subscriptions



Tuesday, October 19, 2004 - Posts

SQL injection in Web apps whitepaper
This one is from SPI Dynamics. It provides an interesting approach; it basically walks you through the various means of launching a successful SQL injection attack, and describes what they'll enable you to do on the server. It then provides some solutions to these issues. I found the Solutions section to a be a bit sparse and a bit of an afterthought, but I think the Attacks section is worth a read to anyone who does serve up data in a Web application. It should help you look at your app from an attacker's point of view, so you can make sure you've really shored up any potential weak points. If you are interested, you can go to https://download.spidynamics.com/1/ad/sql.asp?cs1_ContSupRef=I-N-msdn8.17.04 and fill out some basic contact info, in return for which they'll email you a link to the whitepaper .pdf file.

posted Tuesday, October 19, 2004 10:37 AM by christac




Powered by Dot Net Junkies, by Telligent Systems