Re: RE: Oracle SQL Injection vulnerability




Hello,

There're lots(!) of good resources for SQL injection (and other kinds of injections).

For example:

http://www.spidynamics.com/assets/documents/WhitepaperSQLInjection.pdf

http://www.securiteam.com/securityreviews/5DP0N1P76E.html

http://www.sqlsecurity.com/FAQs/SQLInjectionFAQ/tabid/56/Default.aspx

http://www.webappsec.org/projects/threat/classes/sql_injection.shtml

and MANY MANY more... some of them are really informative.

Kind Regards,

Elad Shapira ("Zest" )

"Security, however, is an art, not a science." - RFC 3631

------------------------------------------------------------------------
This list is sponsored by: Cenzic

Need to secure your web apps NOW?
Cenzic finds more, "real" vulnerabilities fast.
Click to try it, buy it or download a solution FREE today!

http://www.cenzic.com/downloads
------------------------------------------------------------------------



Relevant Pages

  • Re: Oracle SQL Injection vulnerability
    ... This would be indicative of SQL injection. ... Need to secure your web apps NOW? ... Cenzic finds more, "real" vulnerabilities fast. ... buy it or download a solution FREE today! ...
    (Pen-Test)
  • Re: Oracle URL SQL Injection issue
    ... It just looks like your query is invalid. ... While SQL injection is easier to perform than trying to bring some ... Need to secure your web apps NOW? ... Cenzic finds more, "real" vulnerabilities fast. ...
    (Pen-Test)
  • Re: [PHP-DB] $_POST in MySQL query issue...
    ... The only remark which I would make here is to beware of SQL injection. ... Here are a couple of good resources to explain what an SQL injection ...
    (php.general)
  • RE: Oracle SQL injection
    ... mate... ... 2px solid; MARGIN-RIGHT: 0px'><font ... anyone provide links towards SQL injection using Oracle's SQL?.>I've ... knowing>Oracle SQL if anyone has any good links towards resources ...
    (Security-Basics)
  • RE: Oracle SQL Injection vulnerability
    ... and is executing the input as a statement. ... When I give ' on the username field I was received ... Does that mean the site is vulnerable to SQL Injection? ... Cenzic finds more, "real" vulnerabilities fast. ...
    (Pen-Test)