Network World
Monday, December 1, 2008
DNSstuff.com
Get information about your IP
IP Information
50+ On-demand DNS and network tools

Community

Navigation

SQL Injection attack

0

If this could happen on a Microsoft site with all their resources, what chance does a normal enterprise stand?

Most enterprises have staff who can code just enough to make something work and no more and certainly none with the skills of Microsoft themselves.

The answer is to never deploy Microsoft technologies in any web-facing environment. It's not their key focus, they aren't good at it and they're too expensive. Deploy open source instead, it was designed for the Internet in the first place, Microsoft designs for the desktop.

Having said that, the site was probably secured by perimeter firewalls instead of application firewalls. Application firewalls look at behaviours and would have stopped this. Microsoft nil points.

Reply

The content of this field is kept private and will not be shown publicly.
  • Allowed HTML tags: <a> <em> <strong> <i> <b> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd> <blockquote> <br /> <br> <p>
  • Lines and paragraphs break automatically.
  • You can use BBCode tags in the text.
  • Web page addresses and e-mail addresses turn into links automatically.

More information about formatting options

CAPTCHA
This question is for testing whether you are a human visitor and to prevent automated spam submissions.

Advertisement: