11 October 2011

SQL Injection For Beginners

SQL injection is one of those attacks which most developers have heard of, but may not be familiar with.

Photograph of a workstation in a retail shop showing a web browser and a message printed across the top of the display screen 'PUBLIC NOTICE: This computer is for staff use only.'

I stumbled upon some really good guidance on doing some of your own homework on learning about SQL injection. Best Damn Quick Tips for a Total SQL Injection Newbie (Period) quickly describes three steps (reading, setting up a vulnerable web environment and mimicking attackers) to go from little to lots of knowledge. Yes, really do this on your own test vulnerable applications — never start trying things out on applications or systems you are not authorised to examine.

Then for the last step which is to research defensive measures, the best resource is the OWASP SQL Injection Prevention Cheat Sheet. Happy reading!

Posted on: 11 October 2011 at 06:59 hrs

Comments Comments (0) | Permalink | Send Send | Post to Twitter

Comments

Comments are filtered automatically and should appear shortly after they been checked.

Post a comment
Confirm acceptance and understanding of the terms of use
New posts to this thread will be sent to your email address
SQL Injection For Beginners
http://www.clerkendweller.com/2011/10/11/SQL-Injection-For-Beginners
ISO/IEC 18004:2006 QR code for http://clerkendweller.com

Page http://www.clerkendweller.com/2011/10/11/SQL-Injection-For-Beginners
Requested by 50.16.132.180 on Wednesday, 19 June 2013 at 11:35 hrs (London date/time)

Please read our terms of use and obtain professional advice before undertaking any actions based on the opinions, suggestions and generic guidance presented here. Your organisation's situation will be unique and all practices and controls need to be assessed with consideration of your own business context.

Terms of use http://www.clerkendweller.com/page/terms
Privacy statement http://www.clerkendweller.com/page/privacy
© 2011-2013 clerkendweller.com