IT Community - Software Programming, Web Development and Technical Support

Prevention Measures to Avoid SQL Injection

This is a discussion on Prevention Measures to Avoid SQL Injection within the Database Support forums, part of the Web Development category; Measures to avoid SQL injection 1 Validate all input coming from the user on the server. 2 Avoid the use ...


Go Back   IT Community - Software Programming, Web Development and Technical Support > Web Development > Database Support

Register FAQ Members List Calendar Mark Forums Read
  #1 (permalink)  
Old 01-31-2008, 10:27 PM
vadivelanshanmugam vadivelanshanmugam is offline
D-Web Trainee
 
Join Date: Jan 2008
Posts: 41
vadivelanshanmugam is on a distinguished road
Default Prevention Measures to Avoid SQL Injection

Measures to avoid SQL injection

1 Validate all input coming from the user on the server.
2 Avoid the use of dynamic SQL queries if there an alternate method is available.
3 Use parameterized stored procedure with embedded parameters.
4 Execute stored procedures using a safe interface such as Callable statements in JDBC or CommandObject in ADO.
5 Use a low privileged account to run the database.
6 Give proper roles and privileges to the stored procedure being used in the applications.
Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Sponsored Links
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Sql Injection vadivelanshanmugam Database Support 0 01-31-2008 09:51 PM
security measures for .NET Remoting Arun ASP and ASP.NET Programming 1 08-18-2007 12:15 AM
Microsoft takes new privacy measures senthilkannan Microsoft 0 07-23-2007 03:03 AM
What is SQl injection ? sundarraja Database Support 1 07-21-2007 12:50 AM
SQL injection technique Jeyaseelansarc PHP Programming 1 05-16-2007 07:34 AM


All times are GMT -7. The time now is 04:38 AM.


Copyright ©2004 - 2007, DiscussWeb. All Rights Reserved.

SEO by vBSEO 3.0.0