New SQL Injection Whitepaper

From: Chris Anley (chrisat_private)
Date: Thu Jan 31 2002 - 07:37:42 PST

  • Next message: HarryM: "Fairly serious vulnerability in vBulletin 2.2.0"

    Hi folks,
    
    I've just completed a Microsoft SQL Server 'injection' whitepaper, that can
    be downloaded from
    
    http://www.ngssoftware.com/papers/advanced_sql_injection.pdf
    
    At least half of the sites I've audited have been vulnerable to some form of
    SQL injection; I think it's important that people fully understand the
    issues.
    
    The paper contains information on a variety of attacks, including
    second-order SQL injection, automation scripts and audit evasion. It also
    discusses input validation and (briefly) secure builds. The intention is to
    raise awareness of the rich variety of SQL injection attacks, in order to
    encourage people to fix these issues in their applications.
    
    Cheers,
    
         -chris.
    



    This archive was generated by hypermail 2b30 : Thu Jan 31 2002 - 13:04:19 PST