• Email
  • Like
  • Save
  • Private Content
  • Embed
 

Sql Injection Myths and Fallacies

by

  • 44,017 views

...


The most massive crime of identity theft in history was perpetrated in 2007 by exploiting an SQL Injection vulnerability. This issue is one of the most common and most serious threats to web application security. In this presentation, you'll see some common myths busted and you'll get a better understanding of defending against SQL injection.

Accessibility

Categories

Upload Details

Uploaded via SlideShare as Adobe PDF

Usage Rights

CC Attribution-NonCommercial-NoDerivs LicenseCC Attribution-NonCommercial-NoDerivs LicenseCC Attribution-NonCommercial-NoDerivs License

Flagged as inappropriate Flag as inappropriate
Flag as inappropriate

Select your reason for flagging this presentation as inappropriate. If needed, use the feedback form to let us know more details.

Cancel

47 Embeds 4,041

http://ovm-kassel.net 1692
http://ovm-kassel.eu 847
http://www.websdeveloper.com 325
http://www.slideshare.net 247
http://dll.lv 222
http://nwlinux.com 213
http://my.bergersoft.net 122
http://demlaip.wordpress.com 55
http://kerika.net 42
http://kyaiz.wordpress.com 39
http://www.berejeb.com 37
http://khishigee.miniih.com 36
http://www.khishigee.miniih.com 33
http://www.matsuyuku.com 28
http://a0.twimg.com 13
https://groupereflect.bluekiwi.net 11
http://lernen20.de 7
http://localhost 7
http://sjaswinder.blogspot.com 7
http://lernmix.de 6
http://gsmental.blogspot.in 6
http://www.devetdesign.com 5
http://translate.googleusercontent.com 5
http://chirag.dreamworldsolutions.com 3
http://gsmental.blogspot.com 3
https://twitter.com 3
http://localhost:49234 3
http://hml-monqi.monqi.com.br 2
http://www.techgig.com 2
https://twimg0-a.akamaihd.net 2
http://www.google.com 2
http://webcache.googleusercontent.com 1
http://sjaswinder.blogspot.in 1
http://www.linkedin.com 1
http://lms.ipa.edu.sa 1
http://www.ovsa.fr 1
http://chandresh.dreamworldsolutions.com 1
https://si0.twimg.com 1
http://www.blogger.com 1
https://190.96.167.74 1
http://buckycomputing.net 1
http://www.tumblr.com 1
http://rbucky.com 1
http://www.miniih.com 1
http://bharat.dreamworldsolutions.com:8085 1
http://mayur.dreamworldsolutions.com 1
http://paper.li 1

More...

Statistics

Likes
65
Downloads
1,245
Comments
8
Embed Views
4,041
Views on SlideShare
39,976
Total Views
44,017

18 of 8 previous next Post a comment

  • tomexsans Tomex Evaristo the 20th slide, story of my life 1 week ago
    Are you sure you want to
  • dilip-borad dilip-borad very good 2 months ago
    Are you sure you want to
  • vcs023 Varun Saxena, mira road at MUMBAI Awesome PPT and very knowledgeable 8 months ago
    Are you sure you want to
  • wimdesaegher Wim De Saegher Slide 27 - Why does QueryAnyTable have a table_name IN parameter when we pass the 'SELECT * FROM' to the procedure? Won't that execute 'SELECT * FROM SELECT * FROM ...' ? 1 year ago
    Are you sure you want to
  • wimdesaegher Wim De Saegher Slide 12 - did you forget the escape the second special character, right before the 1 ? 1 year ago
    Are you sure you want to
  • billkarwin Karwin Software Solutions LLC at Karwin Software Solutions LLC Updated presentation with new content, after giving the talk at ZendCon 2010 in Santa Clara. Enjoy! 2 years ago
    Are you sure you want to
  • gacdfm10 gacdfm10 Much to my discomfort I discovered I had believed a couple of those myths. I thought this presentation would be something of a review for me -- always a good thing too for security -- but instead it was something even more valuable.

    There certainly will be changes in how I do things, based on what I learned here.
    2 years ago
    Are you sure you want to
  • dthomson1 dthomson1 Excellent and eye-opening presentation. Made me realize that my own techniques for safe SQL were quite inadequate. It helped to not just know what to avoid but why, as in the in-depth discussion of what actually happens during a prepare statement and why it makes a difference. I came away with a number of things that I'm doing that need to be changed, and a whole other set of things that I'm not doing that I plan to start. Thanks! 3 years ago
    Are you sure you want to
Post Comment
Edit your comment

Sql Injection Myths and Fallacies Sql Injection Myths and Fallacies Presentation Transcript