Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



WebApp Sec: Re: Strange beaviour in sql injection

Re: Strange beaviour in sql injection

From: Kevin Spett <kspett_at_spidynamics.com>
Date: Tue, 29 Oct 2002 10:34:47 -0500

I think Dennis's explanation of the situation is probably accurate as far as
what's happening.

> So, can we desume that the previous dogmas for securing a web application
> replacing quotes and checking if a value is numeric are not enough?

Yes, the best way to protect against SQL injection is to program using
stored procedures, commands objects (in the case of ADO) and prepared
statements (for JDBC). More info coming, stay tuned.

Kevin Spett
SPI Labs
http://www.spidynamics.com/
Received on Oct 29 2002

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
edgeos