Microsoft has released a security advisory detailing three ways to respond to the SQL injection attacks. This advisory doesn't covery a patch, just three tools:
- HP Scrawlr is a light weight version of HP's WebInspect that will look for SQL injection flaws. I love that they used the Bobby Tables XKCD comic.
- A new version of UrlScan (3.0 beta) the IIS version of mod_security.
- A source code analyser which will identify SQL injection vulns, although it currently only works for ASP and not ASP.NET.
Barry Irwin

singe: Awesome breakdown from the reigning Web App Scanner queens NTObjectives on why their scanner kicked the other's asses http://is.gd/9e0GZ
Ian Bicking: a blog: What Does A WebOb App Look Like?
0 Trackbacks