Free Republic
Browse · Search
News/Activism
Topics · Post Article

To: proxy_user
If you use a J2EE data access framework like Hibernate, such attacks are impossible.

Or just writing parameterized statements using JDBC should also be sufficient, or just using Stored Procedures. It's amazing when I have interviewed potential candidates for coding positions how few know about Cross-Site Scripting and SQL Injection attacks, if you don't know those things, you are DOA as far as I'm concerned as for getting a position on my team.

5 posted on 04/01/2011 2:24:25 PM PDT by dfwgator
[ Post Reply | Private Reply | To 4 | View Replies ]


To: dfwgator

In many internal business applications that are behind the firewall, it may not be necessary to protect again such attacks. If only senior management has access to the application, what’s the point?

I would not be surprised if coders coming from such an environment would not know how to create a site that is accessible from the public internet.


9 posted on 04/01/2011 2:34:19 PM PDT by proxy_user
[ Post Reply | Private Reply | To 5 | View Replies ]

Free Republic
Browse · Search
News/Activism
Topics · Post Article


FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson