Thursday, March 8, 2012

automated sql injection detectors

anybody ever use any of these...
http://www.security-hacks.com/2007/05/18/top-15-free-sql-injection-scanners ?
thoughts? preferences?I have not used any of them. I think this kind of tool could be a good candidate for preliminary testing for vulnerabilities, but in general I have limited faith in automated testing because it limits itself to the logic implemented by the coder.

No comments:

Post a Comment