Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
BugTraq
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
RE: Paper: SQL Injection Attacks by Example Jan 05 2005 07:20PM
David Litchfield (davidl ngssoftware com)
Hi Steve,
Nice paper. However, one small nitpick - under "Mitigations" you list using
stored procedures if the database supports them. I've seen other people
suggest this as a defensive strategy as well.

Using stored procedures will *not* protect you from SQL injection attacks.
Firstly, they can b...

[ more ]  





 

Privacy Statement
Copyright 2009, SecurityFocus