September 2009
Intermediate to advanced
464 pages
9h 58m
English
SQL injection is a very serious code defect that can lead to machine compromises, the disclosure of sensitive data, and more recently, spreading malicious software. What’s really worrying is the systems affected by such vulnerabilities are often e-commerce applications or applications handling sensitive data or personally identifiable information (PII); and from the authors’ experience, many in-house or line-of-business database-driven applications have SQL injection bugs.
Allow us to be, hopefully, abundantly clear about the potential for havoc. If you build applications that communicate with databases and your code has one or more SQL injection vulnerabilities (whether you know it or not!), you are putting ...
Read now
Unlock full access