Sign in
Neil Carpenter's Blog
Forefront products, WSUS, Security Incident Response, and whatever else comes up.
Translate This Page
Translate this page
Powered by
Microsoft® Translator
Options
Email Blog Author
RSS for posts
Atom
RSS for comments
OK
Search Blogs
Tags
Antigen
AntiVirus
Anti-Virus
ASP
asp.net
AV
Forefront
FSSMC
General
humor
Incident Response
iphone
Mobile
Networking
Pages
Security
SQL
Tool
Archive
Archives
November 2009
(1)
October 2008
(2)
August 2008
(2)
July 2008
(3)
June 2008
(1)
May 2008
(4)
April 2008
(2)
March 2008
(3)
August 2007
(2)
July 2007
(2)
June 2007
(2)
October 2004
(4)
June 2004
(7)
May, 2008
TechNet Blogs
>
Neil Carpenter's Blog
>
May, 2008
Posts
Subscribe via RSS
Sort by:
Most Recent
|
Most Views
|
Most Comments
Excerpt View
|
Full Post View
Neil Carpenter's Blog
SQL Injection Mitigation: Using Parameterized Queries
Posted
over 5 years ago
by
neilcar
15
Comments
Michael Howard wrote an excellent article yesterday on how the SDL addresses SQL injection . He walks through three coding requirements/defenses: Use SQL Parameterized Queries Use Stored Procedures Use SQL Execute-only Permissions As Michael...
Neil Carpenter's Blog
SQL Injection Mitigation: Using Parameterized Queries part 2 (types and recordsets)
Posted
over 5 years ago
by
neilcar
10
Comments
(Part 1 is here ) Previously, I provided a simple example of using parameterized queries in classic ASP; however, that sample lacked a few things such as explicit typing for the parameters. It also created a read-only ADODB.RecordSet which, obviously...
Neil Carpenter's Blog
SQLInjectionFinder
Posted
over 5 years ago
by
neilcar
0
Comments
My colleague Greg , who has forgotten more about command line scripting than I will ever know, put together a sample on CodePlex that automates finding SQL injection attacks from the ongoing mass SQL injection attack ("SQL Storm", as I saw it...
Neil Carpenter's Blog
SQL Injection: Trends & Guidance
Posted
over 5 years ago
by
neilcar
0
Comments
I've been working with the SWI team to write a comprehensive overview of the SQL Storm attacks with guidance for IT administrators, developers, and end users. That article is posted at sql-injection-attack.aspx . For developers, specifically, Bala...
Page 1 of 1 (4 items)