Web Password Form - Fending Off SQL Injection

Posted by Scott_Ruecker on Aug 18, 2008 10:23 AM EDT
bst-softwaredevs.com; By Herschel Cohen
Mail this story
Print this story

This series began with the idea of showing a form that could be used by an external user(s) as a means of adding content to a remote site. The idea of the use of a password form was there from the onset. It made sense to limit access to a select set of users. The password form enhances security, which became an issue with the data input form. Nonetheless, until very recently, I intended to skip any real discussion of password forms. I was going to cite a book's discussion. At most, I might have mentioned a few potential problems. I was certain that would have sufficed. I changed my mind when I saw the ease simple minded SQL injection breached this barrier. Therefore, more than a few words are warranted.

Full Story

  Nav
» Read more about: Story Type: News Story

« Return to the newswire homepage

This topic does not have any threads posted yet!

You cannot post until you login.