Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: ISA Server and SQL Injection |
|---|---|
| Date: | Thu, 17 Feb 2005 21:56:49 +0000 |
Bogdan Tomchuk wrote:
Sure, if the patch is available. (A webapp firewall is a protection against way to exploit a web app vulnerability, not against some identified vulnerable application only). So patching is not the only solution. if it was, explain me why so many system are vulnerable to worm that exploit old vuln, and today, some worm are still doing so much disaster.Protection against this kind of injection is just other way of patching the code, so useless, because this assume knowing difference between "good" and "bad" URL, so for OWA, for example, you define list of templates for all known "good" URL and anything else will be consider as SQL injection. I do not understand why to spend money on expensive firewall staff if you can patch or upgrade software.
In a perfect world, maybe... You should say this to big companies with security team, they are all dumb and do not understand security. they should not use firewall but only windows update program or apt-get dist upgrade ;)Keep your software current is always better then "imaginable" security given by software level firewall especially against SQL injection.
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | RE: ISA Server and SQL Injection, Jeff Robertson |
|---|---|
| Next by Date: | RE: ISA Server and SQL Injection, Sebastien Deleersnyder |
| Previous by Thread: | Re: ISA Server and SQL Injection, Bogdan Tomchuk |
| Next by Thread: | RE: ISA Server and SQL Injection, Marty Block |
| Indexes: | [Date] [Thread] [Top] [All Lists] |