WebApp Sec mailing list archives

Re: ISA Server and SQL Injection


From: "Bogdan Tomchuk" <bogdan.tomchuk () polytechnique fr>
Date: Wed, 16 Feb 2005 18:34:34 +0100

I'm not sure any firewall would stop a SQL Injection attack.
Web application firewall can do this. They filter http content.

No, they cannot do it either. Problem is the same: By seeing URL you have no
reliable way to say which parameter will be used in SQL query and how
(with/without transformation). Only application knew it.




Current thread: