sql injection



Dear All,

I'd like to know what we can do against sql injection, in sql2003 and iis6.0
environment.

Does exist a sort of tool able to filter inpunt url string in order to stop
this kind of sql injection?


Regards

Alberto Brivio


.



Relevant Pages

  • Re: character(s) that cannot be stored in DB
    ... May I ask what sort of issuemight occur by allowing the use of "? ... >> Thanks for your reply Tibor. ... > My guess is they're trying to trap certain stuff to prevent SQL Injection ... > attacks. ...
    (microsoft.public.sqlserver.server)
  • Re: sprintf for SQL injection testing
    ... On Apr 14, 11:52 am, Erwin Moller ... any sort of malformed data. ... Maybe SQL injection wasn't the concern it was supposed to ...
    (comp.lang.php)
  • Re: sprintf for SQL injection testing
    ... On Apr 14, 11:29 am, Erwin Moller ... Well, IIRC, it wasn't specifically for SQL injection, but rather for ... any sort of malformed data. ...
    (comp.lang.php)
  • Re: sprintf for SQL injection testing
    ... Well, IIRC, it wasn't specifically for SQL injection, but rather for ... any sort of malformed data. ... you still have SQL injection. ...
    (comp.lang.php)
  • [REVS] More Advanced SQL Injection Paper Released
    ... Microsoft SQL Server/IIS/Active Server Pages environment, ... Advanced SQL Injection". ... conversations around the subject of SQL injection in a SQL Server ... In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages. ...
    (Securiteam)