- overlooked by people who don't test all of their critical systems from every possible angle
- overlooked by people who haven't learned how to properly use their Web vulnerability scanners
- overlooked by people who chose to only perform PCI-DSS-type vulnerability scans that don't go deeply enough
- And, perhaps worst of all, overlooked by tools that can't test for - or properly exploit - SQL injection
Certain automated tools for SQL injection testing/exploitation have been around for years but I've never seen a tool that actually finds SQL injection as frequently or is as simple to use as HP's WebInspect. As shown in the following screenshots, with WebInspect it's a simple two-step process from initial scan to data extraction:



Folks, this is something that cannot be taken lightly. I'm not just talking about SQL injection itself but the fact that your tools may not be providing you the right information you need. As I've said before, You cannot secure what you don't acknowledge. In this case, I'll tweak that a bit and say You cannot secure what you cannot find. Just because the tools you're using aren't finding or exploiting SQL injection doesn't mean it's not a problem. Trust but verify.
0 comments:
Post a Comment