SQL Injection attack detection tools
July 8, 2008 SQL — Tags: SQL, SQL Injection, SQL Injection check, Sql Server — 52coding
聽1.Scrawlr
https://download.spidynamics.com/Products/scrawlr
Microsoft and HP co-developed聽 tools, will be the site of reptiles, string enquiries all the pages of analysis and SQL INJECTION found that the risk. Scrawlr part of HP WebInspect use the same technology, but only detected SQL INJECTION risk. Scrawlr from a starting URL entrance, climbed over the whole site, and all of the pages in the site for analysis to find loopholes that may exist.
2.Microsoft Source Code Analyzer for SQL Injection
http://www.microsoft.com/downloads/details.aspx?FamilyId=58A7C46E-A599-4FCB-9AB4-A4334146B6BA&displaylang=en
聽聽 MSCASI聽 detect ASP code and found that the SQL INJECTION loopholes. you need to provide source code to MSCASI , lt’s will help you find the code at risk locations.
3.URLScan 3.0
http://www.iis.net/downloads/default.aspx?tabid=34&g=6&i=1697
The tool will let IIS restrictions on certain types of HTTP request, through the HTTP request specific restrictions, can prevent certain harmful at the request of the server-side implementation. UrlScan through a series of keywords found malicious requests and prevent the implementation of malicious requests.
