Tools & Code: Microsoft Blogs Presents – SQL Injection Defense Tools

SQL Injection Defense Tools

Bryan here. A couple of weeks ago, I posted a blog entry with links to SQL injection defense guidelines. The SDL requires guidance and education for end-users, and tools to verify security settings are highly recommended, as defined in “Stage 5: Implementation Phase: Creating Documentation and Tools for Users that Address Security and Privacy“. Today, Microsoft is releasing two new SQL injection defense and detection tools, URLScan 3.0 and Microsoft Source Code Analyzer for SQL Injection (MSCASI). We are also excited to announce the release of HP Scrawlr, a SQL injection detection tool developed by HP Web Security Research Group in conjunction with Microsoft.

Go here to read rest of article… and get tools…



About this entry