SPI Labs SQL Injection Whitepaper Released

From: spi labs (spilabsat_private)
Date: Tue Jan 29 2002 - 18:40:24 PST

  • Next message: Stephen: "Re: Looking for old Interbase proof-of-concept exploit"

        The SPI Labs whitepaper on SQL injection has been released.  It is
    available in PDF format from:
    http://www.spidynamics.com/papers/SQLInjectionWhitePaper.pdf
    
    Here's the overview:
                SQL injection is a technique for exploiting web applications
    that use client-supplied data in SQL queries without stripping illegal
    characters first.  Despite being remarkably simple to protect against, there
    is an astonishing number of production systems connected to the Internet
    that are vulnerable to this type of attack.  The objective of this paper is
    to educate the professional security community on the techniques that can be
    used to take advantage of a web application that is vulnerable to SQL
    injection as well as make clear the correct mechanisms that should be put in
    place to protect against SQL injection, as well as input validations
    problems in general.
    
    Please send comments and questions to spilabsat_private
    



    This archive was generated by hypermail 2b30 : Tue Jan 29 2002 - 20:46:13 PST