Click here to Skip to main content
15,887,344 members

The Insider News

   

The Insider News is for breaking IT and Software development news. Post your news, your alerts and your inside scoops. This is an IT news-only forum - all off-topic, non-news posts will be removed. If you wish to ask a programming question please post it here.

Get The Daily Insider direct to your mailbox every day. Subscribe now!

 
NewsWindows Update is broken for some Windows 7 users Pin
Kent Sharkey4-Dec-17 13:31
staffKent Sharkey4-Dec-17 13:31 
NewsCan you hear this silent gif bouncing? Here’s why Pin
Kent Sharkey4-Dec-17 9:46
staffKent Sharkey4-Dec-17 9:46 
GeneralRe: Can you hear this silent gif bouncing? Here’s why Pin
Marc Clifton4-Dec-17 11:10
mvaMarc Clifton4-Dec-17 11:10 
GeneralRe: Can you hear this silent gif bouncing? Here’s why Pin
Joe Woodbury4-Dec-17 13:07
professionalJoe Woodbury4-Dec-17 13:07 
GeneralRe: Can you hear this silent gif bouncing? Here’s why Pin
Dan Neely5-Dec-17 3:35
Dan Neely5-Dec-17 3:35 
NewsBobby Tables Pin
Kent Sharkey4-Dec-17 9:31
staffKent Sharkey4-Dec-17 9:31 
GeneralRe: Bobby Tables Pin
raddevus4-Dec-17 9:38
mvaraddevus4-Dec-17 9:38 
GeneralRe: Bobby Tables Pin
Richard Deeming5-Dec-17 2:13
mveRichard Deeming5-Dec-17 2:13 
raddevus wrote:
you could solve most of this by requiring all SQL to be run only via Stored Procs too.

Stored procedures aren't a magical defence against SQLi. If you're not using a properly parameterized query, they're just as vulnerable to SQLi as any other query.

And if you've spent any time in QA, you'll know that it's perfectly possible to write a stored procedure that contains its own SQLi vulnerability. Smile | :)

The only defence is to parameterize everything. And if you find yourself hitting one of the few things that can't be parameterized (table and column names, for example), and you can't find a way to avoid it, then use the system views to validate the crap out of the user input, preferably ditching the user input in favour of the values returns from the views.



"These people looked deep within my soul and assigned me a number based on the order in which I joined."
- Homer


GeneralRe: Bobby Tables Pin
Dominic Burford4-Dec-17 10:40
professionalDominic Burford4-Dec-17 10:40 
GeneralRe: Bobby Tables Pin
Marc Clifton4-Dec-17 11:15
mvaMarc Clifton4-Dec-17 11:15 
GeneralRe: Bobby Tables Pin
Joe Woodbury4-Dec-17 13:14
professionalJoe Woodbury4-Dec-17 13:14 
NewsGartner’s guide to successful DevSecOps Pin
Kent Sharkey4-Dec-17 9:16
staffKent Sharkey4-Dec-17 9:16 
NewsNobel prize-winning economist says Bitcoin “Ought to be outlawed” Pin
Kent Sharkey4-Dec-17 9:16
staffKent Sharkey4-Dec-17 9:16 
GeneralRe: Nobel prize-winning economist says Bitcoin “Ought to be outlawed” Pin
raddevus4-Dec-17 9:41
mvaraddevus4-Dec-17 9:41 
GeneralRe: Nobel prize-winning economist says Bitcoin “Ought to be outlawed” Pin
User 592414-Dec-17 13:02
User 592414-Dec-17 13:02 
GeneralRe: Nobel prize-winning economist says Bitcoin “Ought to be outlawed” Pin
Joe Woodbury4-Dec-17 13:18
professionalJoe Woodbury4-Dec-17 13:18 
GeneralRe: Nobel prize-winning economist says Bitcoin “Ought to be outlawed” Pin
Sander Rossel5-Dec-17 6:17
professionalSander Rossel5-Dec-17 6:17 
NewsGoogle's AI built its wwn AI that outperforms any made by humans Pin
Kent Sharkey4-Dec-17 8:16
staffKent Sharkey4-Dec-17 8:16 
NewsThe first text message was sent 25 years ago Pin
Kent Sharkey4-Dec-17 8:16
staffKent Sharkey4-Dec-17 8:16 
NewsLenovo will pay a $3.5 million fine for preinstalling adware on certain laptops Pin
Eddy Vluggen4-Dec-17 5:59
professionalEddy Vluggen4-Dec-17 5:59 
NewsArtificial intelligence isn’t as clever as we think, but that doesn’t stop it being a threat Pin
Kent Sharkey3-Dec-17 18:01
staffKent Sharkey3-Dec-17 18:01 
NewsNormalization of deviance in software: how broken practices become standard Pin
Kent Sharkey3-Dec-17 18:01
staffKent Sharkey3-Dec-17 18:01 
GeneralRe: Normalization of deviance in software: how broken practices become standard Pin
Marc Clifton4-Dec-17 11:19
mvaMarc Clifton4-Dec-17 11:19 
GeneralRe: Normalization of deviance in software: how broken practices become standard Pin
Nelek4-Dec-17 12:28
protectorNelek4-Dec-17 12:28 
NewsWall St Journal gets pounded after suggesting finance pros drop Excel Pin
Kent Sharkey3-Dec-17 18:01
staffKent Sharkey3-Dec-17 18:01 

General General    News News    Suggestion Suggestion    Question Question    Bug Bug    Answer Answer    Joke Joke    Praise Praise    Rant Rant    Admin Admin   

Use Ctrl+Left/Right to switch messages, Ctrl+Up/Down to switch threads, Ctrl+Shift+Left/Right to switch pages.