Geeks With Blogs

News FAQ on the correct forum to post at: http://forums.asp.net/p/1337412/2699239.aspx#2699239
Tatworth
At http://www.sqlmag.com/content1/topic/sql-injection-basics-142364/catpath/sql-server/utm_source/feedburner/utm_medium/feed, there is an excellent article on the measures needed to defeat SQL Injection Attack.

Read the article but also remember that the account the application uses to access the database adhere to the following points:
  • NEVER EVER use the sa account even in development.
  • Route access via a role on the database.
  • The account should have the minimum privilege required for the job.
  • The account should have no access whatsoever to any other database not required by the application.
  • If you can avoid mixed mode authentication do so and grant access via to a windows group to which you add users.
Posted on Friday, June 1, 2012 8:55 AM | Back to top


Comments on this post: SQL Injection – Beyond the Basics - A good article

No comments posted yet.
Your comment:
 (will show your gravatar)


Copyright © TATWORTH | Powered by: GeeksWithBlogs.net