The use static state inquires. If needs the dynamic inquiry, the use prepares the good sentence.
Uses a safe connection, if ADO Command Object, causes the application program execution memory process.
Examines SQL to pour into the crack and the attack
Must examine the application procedure which attacks is not the simple matter easy, because these cracks possibly exist in face the user in any application program interface. Although all SQL pours into the attack technology easy to examine by no means that but the database administrator or the development personnel may handle the following matter:
Reads the Web server's diary. Sometimes, in these diaries may discover easily SQL pours into the attack, because wrote by now toward the diary registers the project to ordinary be much more.
Searches HTTP 404 and the HTTP 500 wrong diary projects, as well as program generation inspection user input other wrong diary project.
Uses the Web application procedure scanning tool. These tools may use in warning the database administrator, informs in the manager application procedure to pour into easily SQL the attack the place.
Before deployment application procedure, inspection SQL infuses the factor to be very important.
In brief, defends SQL to pour into the attack the steady plan to be in the development, the deployment, the management, maintenance many aspects carries on the inspection, and needs the safety managers to pay attention to the newest trend which unceasingly SQL pours into, uses the practical and feasible tool, causes the procedure the crack minimum.
Other pages: : <<Prev * 1 * 2
|