Friday | 10 July, 2009
CSO
Microsoft, HP ship tools to protect Web sites from hackers
Three tools help sites ward off growing SQL injection attacks
Gregg Keizer (Computerworld) 25/06/2008 09:55:21

"This [SQL injection attack trend] really started when companies began looking at Web 2.0 and decided that they had to have things like social networking and blogging on their sites," said Pescatore. "A lot of those features were added and didn't go through the normal checks [for secure code]. That kind of tinkering leads to a loss of discipline."

Tools like these, added Pescatore, "rattle the doorknobs" of a site, like a city cop on a beat once did as he passed through his neighborhood. "Better for us to rattle them first," said Pescatore.

Also Tuesday, Hewlett-Packard's Web security team posted "HP Scrawlr" -- short for "SQL Injector and Crawler" -- to its Web site. Like "fuzzers" that researchers use to spot potential security problems in, for instance, file formats, HP Scrawlr analyzes Web pages for vulnerability to SQL injection attack, then reports its findings.

Microsoft unveiled its free tools in an advisory posted by the Microsoft Security Response Center, which included download links for UrlScan and SQL Source Code Analysis Tool.

Comments

Post new comment

Login or register to link comments to your user profile, or you may also post a comment without being logged in.
The content of this field is kept private and will not be shown publicly.
Enter the fully qualified URL, eg. http://www.example.com/
  • Web page addresses and e-mail addresses turn into links automatically.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd>
  • Lines and paragraphs break automatically.

More information about formatting options

Syndicate content
 
Whitepaper

Reducing the risk of insider abuse

The potential for insider abuse can never be eliminated completely, but the steps outlined in this white paper can reduce the potential for such abuse. Read on to ensure no one person can alter your operations to their personal advantage or to the detriment of your organisation.

Sponsored Links