Rise in SQL Injection Attacks Exploiting Unverified User Data Input PDF Print E-mail
Written by Zeeshan Ali Shah   
Wednesday, 25 June 2008 08:40

"Microsoft is aware of a recent escalation in a class of attacks targeting Web sites that use Microsoft ASP and ASP.NET technologies but do not follow best practices for secure Web application development. These SQL injection attacks do not exploit a specific software vulnerability, but instead target Web sites that do not follow secure coding practices for accessing and manipulating data stored in a relational database." 

Microsoft has identified several tools to assist administrators. These tools cover detection, defense, and identifying possible coding which may be exploited by an attacker. Read here

 

Zeeshan Ali Shah

Current Location: Stockholm, Sweden.

Lat 59,3333 Long 18,05

Email: zeeshan at infoshield dot info

Mobile: 0046 76 2776193 (Sweden)

Language: Urdu, English, Swedish, Italian (very basic)

 

View Zeeshan's page on House of Hackers