Chris Anley
Member for
12 years 7 monthsChris Anley is a director at NGSSoftware, the world's leading security vulnerability research company. When he's not spending time auditing software or websites for security bugs, he writes whitepapers that help folks do it for themselves. You can read more about NGSSoftware here.
Chris Anley is a director at NGSSoftware, the world's leading security vulnerability research company. When he's not spending time auditing software or websites for security bugs, he writes whitepapers that help folks do it for themselves. You can read more about NGSSoftware here.
All Articles by Chris Anley
All Stories by Chris Anley
| More Advanced SQL Injection This paper addresses the subject of SQL Injection in a Microsoft SQL Server/IIS/Active Server Pages environment, but most of the techniques discussed have equivalents in other database environments. |
|
| Advanced SQL Injection in SQL Server Applications This document discusses in detail the common "SQL injection" technique, as it applies to the popular Microsoft Internet Information Server/Active Server Pages/SQL Server platform. It discusses the various ways in which SQL can be "injected" into the application and addresses some of the data validation and database lockdown issues that are related to this class of attack. |