The Greatest Risk to Your Website: 30% of Database-Driven Sites Vulnerable to SQL-Injection
Published by Redspin on Sep 03, 2008
Let’s assume for a moment that you have your firewall configuration dialed in impeccably, that your patch management server never rests, and that your state-of-the-art IDS lets you sleep peacefully at night, as it continuously identifies any irregularities from the network’s accepted traffic patterns. Even your web-server contains no known vulnerabilities, and it is responsibly segmented from the internal network and into a distinct security zone. Yet, there remains a critical risk lurking beneath the surface and your network potentially stands to crumble if unfiltered input fields on your website allow an attacker to exploit the database-layer embedded within so many of today’s most common web applications.
|