We were alerted to the potential compromise of database information via the web when we started working with Secerno, a company whose business is database security. Basically, if there is the potential for user interaction through your site, then there is also a high risk that a hacker might ‘inject’ his own SQL code and download information that you would wish to keep safe – like passwords, clients, products.
If you are password-protecting databased information, (making it available via a closed user area perhaps) you may have locked the doors, but you will need to check that the windows are closed too. Damage from SQL injection is just one of the issues that Secerno helps protect against.
Wild West clients too, (including our various banking, investment and private equity clients) are safeguarded against this very prevalent form of attack. Read more here: http://www.secerno.com/?pg=SQL-Injection
0 Responses to “SQL Injections – Is Your Site Safe?”