Posts Tagged ‘sql injection’

The number of SQL Injection attacks across the Internet continue to rise. I’m seeing regular posting on the SANS RSS feed related to SQL Injection and XSS these days and clients are finding that applications they thought were not vulnerable turn out to be vulnerable because of patches and custom mods they’ve had made to them.  For most site owners this meant going back to the developers and getting updates and this is generally costly and time consuming. Fortunately, Microsoft has stepped up to the plate and brought us a little relief in the form of URLScan 3.0 beta/go-live release.

Read the rest of this entry »

My previous blog post attempted to explain SQL injection and why it’s a problem.   It’s started to get media coverage now and the media is looking for a target (scapegoat). So as is often the case, someone gets wrongly blamed and right now it’s of course Microsoft.

It’s NOT Microsoft’s fault.

Read the rest of this entry »

Calendar
March 2010
S M T W T F S
« Jan    
 123456
78910111213
14151617181920
21222324252627
28293031