SQL Injection is a common attack vector in dynamic web applications. It allows an attacker to gain access to the database or database functions through poor coding methodology. A good SQL injection reference is over at the owasp site.
Recently there have been a number of high profile attacks that have been exploited by SQL Injection, these have resulted in the loss of millions of customer records and hundreds of thousands of login / password combinations.
Wednesday, April 13, 2011
Subscribe to:
Post Comments (Atom)
No comments:
Post a Comment