Penetration Testing mailing list archives

Re: SQL injection


From: Richard Barrell <rbarrell () sentryware com>
Date: Thu, 9 Jun 2005 18:35:52 +0200

Hi Faisal,

There are dedicated devices that are designed to prevent attacks of
this sort - web application firewalls. Here are a list of
manufacturers that you should look into:

(in alphabetical order)

Imperva          - www.imperva.com/
Kavado           - www.imperva.com/
Netcontinuum     - www.netcontinuum.com/
Teros            - www.teros.com/
Watchfire (Sanctum) - www.watchfire.com

AND, if you'll forgive the plug,

Sentryware:       www.sentryware.com

Good luck in your search,

Rich

-----------------
FK> Pardon the ignorance, but is there any hardware/software based device that
FK> can outright prevent/mitigate (detect?) SQL injections? Would an IDS be
FK> able to prevent this?

---------------------
Richard Barrell, CCNP, CCDP
International Pre-Sales Manager

www.sentryware.com
Parque Empresarial Zuatzu
Edificio Urgull, 2ª local 10
20018 Donostia-San Sebastián
Spain

Tel: +34 943 31 73 30
Mvl: +34 646 97 10 18
Skype: mr_barrell


Current thread: