1.[Info-ingres] FW: [Users] How to Log errors while executing ingres sql command
2.[Info-ingres] How to Log errors while executing ingres sql command
3.[Info-ingres] RES: [Info-ingres] RES: [Info-ingres] SQL Injection attacks
> -----Mensagem original----- > De: XXXX@XXXXX.COM > [mailto: XXXX@XXXXX.COM ] Em nome de Emiliano > Enviada em: Monday, June 12, 2006 10:06 AM > Para: XXXX@XXXXX.COM > Assunto: Re: [Info-ingres] RES: [Info-ingres] SQL Injection attacks > > On 2006-06-12, Leandro Pinto Fava < XXXX@XXXXX.COM > wrote: > > Three years ago we had a case of SQL Injection against our web portal of > > students's info. This portal was made using ICE and reports in 1999 > > (with very bad security control). Now we have this portal made in PHP > > and the possibility of SQL injection is nearly null (I think :-(). We > > had another web application (ASP) that suffered a successful SQL > > injetcion too. The problems were corrected as well. > > And (to hook into the delightful discussion I'm having with Roy), I'll > bet you dimes to dollars that both were using query assembly. The ASP app was, but the ICE app was not directly. Report Writer internally should work with query assembly when passing parameters to run a report. > > The PHP function addslashes ought to protect you if you use it > consistently. PHP ADODb has parameter binds, which are better. Yes. > > > In our case the problems were in the application layer. > > HTML injection? No, when I said application layer, I wanted to say the problem was not in database server. Leandro.
4.[Info-ingres] RES: [Info-ingres] RES: [Info-ingres] SQL Injection attacks
5.[Info-ingres] RES: [Info-ingres] SQL Injection attacks
6. How to Log errors while executing ingres sql command
7. [Info-Ingres] Ingres SQL question
8. [Info-ingres] Scheduled SQL Job pulling from Ingres Fails
Users browsing this forum: No registered users and 84 guest