Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista
SQL attack continues to infect Web sites
Robert Lemos, 2008-01-10
Comments Mode:
SQL attack continues to infect Web sites 2008-01-10
Anonymous (1 replies)
Re: SQL attack continues to infect Web sites 2008-01-17
Anonymous
Use MSSQL/PL-SQL Stored Procedures, limit what and who has access to the stored procedures and associated tables. Perform code reviews, check that string, interger, etc. types are declared in the code and perform error checking. Patch and set IDS/IPS SQL-Injection signatures to High and send alerts , set IPS drop malicious packets and alert.

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/newsbriefs/660/2323#2323







 

Privacy Statement
Copyright 2008, SecurityFocus