Friday | 10 July, 2009
CSO
Microsoft, HP ship tools to protect Web sites from hackers
Three tools help sites ward off growing SQL injection attacks
Gregg Keizer (Computerworld) 25/06/2008 09:55:21

"This [SQL injection attack trend] really started when companies began looking at Web 2.0 and decided that they had to have things like social networking and blogging on their sites," said Pescatore. "A lot of those features were added and didn't go through the normal checks [for secure code]. That kind of tinkering leads to a loss of discipline."

Tools like these, added Pescatore, "rattle the doorknobs" of a site, like a city cop on a beat once did as he passed through his neighborhood. "Better for us to rattle them first," said Pescatore.

Also Tuesday, Hewlett-Packard's Web security team posted "HP Scrawlr" -- short for "SQL Injector and Crawler" -- to its Web site. Like "fuzzers" that researchers use to spot potential security problems in, for instance, file formats, HP Scrawlr analyzes Web pages for vulnerability to SQL injection attack, then reports its findings.

Microsoft unveiled its free tools in an advisory posted by the Microsoft Security Response Center, which included download links for UrlScan and SQL Source Code Analysis Tool.

Comments

Post new comment

Login or register to link comments to your user profile, or you may also post a comment without being logged in.
The content of this field is kept private and will not be shown publicly.
Enter the fully qualified URL, eg. http://www.example.com/
  • Web page addresses and e-mail addresses turn into links automatically.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd>
  • Lines and paragraphs break automatically.

More information about formatting options

Syndicate content
 
Whitepaper

LANPlanner | Ensuring High Performance WLAN Networks

Learn how the Motorola LANPlanner facilitates prompt and precise planning and the design and measurement of robust 802.11a/b/g/n networks. Download this paper now to discover how to take wireless network performance to the next level.

Sponsored Links