|
Defense-in-Depth against SQL Injection |
|
|
|
Source: It-Observer.com - Posted by Efren J. Belizario
|
A few years ago, mentioning the phrase SQL Injection to developers or asking to adopt a defense-in-depth strategy would probably get you a blank stare for a reply. These days, more people have heard of SQL Injection attacks and are aware of the potential danger these attacks present, but most developers’ knowledge of how to prevent SQL Injection is still inadequate.
When asked how to defend their applications against SQL Injection, they usually reply, “That’s easy, just use stored procedures. "As we will see, using stored procedures is a great first step for your defense strategy, but is not sufficient as the only step. You need to adopt a defense-in-depth strategy. The problem with exclusively relying on stored procedures and not implementing a defense-in-depth strategy is that you are really just counting on the developer of the stored procedures to provide your security for you.
Read this full article at It-Observer.com
Powered by AkoComment! |