3 ms·
This seems like a total non-issue. Just CORRECTLY sanitize everything going into the database! <snark> By the way, just to let everyone know also. You should
by thesis 15y ago
This seems like a total non-issue. Just CORRECTLY sanitize everything going into the database!
<snark>
By the way, just to let everyone know also. You should also sanitize form submissions.
</snark>
- MrFoof 15y agoOr, more succinctly, don't trust anything that comes from outside your application stack.
- dangrossman 15y agoOr use prepared statements regardless of the source so that knowing the source, and tracking changes of the source of variables, becomes a non-issue.
- borski 15y agoHa. It turns out the majority of engineers who are not security-conscious don't do this, because it's easy to forget. And there's always another way to get around it, unfortunately.
- nullflux 15y agoHeh, that's not how most people think. It's more like: Security! It's a total non-issue! Why would anyone want to break my app? Most people seem to feel this way until their apps are dumped, rooted, hacked, or they just end up thinking security is cool and say "Man, I didn't realize how much of a mess I had before." Basic scans need to be part of the CI workflow of startups these days. The same QA tier you use for Selenium and what not you should just throw Nessus/SQLMap at and have injections/vulnerabilities of the web stack fail builds as well.
- borski 15y agoCompletely agreed. And actually, this is a large part of what Tinfoil is currently working on building. If you have suggestions, we're all ears. It's all too common to hear people not caring until its too late. At least with all the skiddies running around nowadays it's harder for anybody rational to ignore.
- dwich 15y agoIn defense of the author, his audience appears to be mostly people doing black-box security scans (and those writing security-scanning software). For those people, understanding additional attack vectors is useful.
- natbat 15y agoThinking about "sanitizing" puts you in the wrong frame of mind in my opinion - you should be thinking about ESCAPING. If you're constructing SQL queries sensibly (using an ORM or a library that replaces placeholders rather than concatenating strings together yourself) you won't even have to think about that.
- wglb 15y agoSanitizing wont take care of problems from concatenating sql queries, for example, rather than using parameterized statements.