A Day, In the Life, of an Intern

Posted on June 3, 2005 03:13 by LeviRosol

How exactly, does someone go about explaining what SQL injection is to a first time developer? I think I did 'Okay' explaining it today by showing examples of what could be done, and how, however, I struggled with giving a good definition.

Tonight I did a google search[^], and came up with this definition from the E-government in New Zealand[^] website:

“SQL injection is the name for a general class of attacks that can allow nefarious users to retrieve data, alter server settings, or even take over your server if you're not careful. SQL injection is not a SQL Server problem, but a problem with improperly written applications.“

That pretty much sums it up. Here is an article[^] that goes in to more depth on how these attacks are carried out, and what developers should do to prevent them. I think I'll revisit this discussion tomorrow.

Be the first to rate this post

  • Currently 0/5 Stars.
  • 1
  • 2
  • 3
  • 4
  • 5

Related posts

Add comment


(Will show your Gravatar icon)  

  Country flag

[b][/b] - [i][/i] - [u][/u]- [quote][/quote]



Live preview

September 6. 2008 17:42