How to test for SQL Injections
Not only does this snippet effective in finding simple SQL Injection attacks:
The side effects are highly reduced ratio of second offences, and a sudden improvement in backup practices.
Now if I could fix the weeping issue...
Comments
A better test would drop master or msdb, that way the test could be re-used for other projects. WAITFOR DELAY '00:00:30' works too.
Joe '; DROP DATABASE *; --
Hehe. Fair enough.
This would be a good place for one of us SP lovers to make a comment, but I will hold back :)
Comment preview