Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:




dailydave logo Dailydave mailing list archives

Re: From blackbox to grey-box during Web App tests
From: "Thomas Ptacek" <tqbf () matasano com>
Date: Sun, 14 Oct 2007 08:56:18 -0500

        Why don't more people just use Parameterized Stored Proceedures?  Is it
because there are implimentation issues or because people don't know
about them? Whats your opinion?

I wonder that too. Also, why don't people just not write integer overflows?

With the snark bit cleared, I'll point out: lots of projects use
stored procedures, but have some patches of functionality (like query
builders) that are easiest to write with raw SQL.

-- 
---
Thomas H. Ptacek // matasano security
read us on the web: http://www.matasano.com/log
_______________________________________________
Dailydave mailing list
Dailydave () lists immunitysec com
http://lists.immunitysec.com/mailman/listinfo/dailydave


  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]