Microsoft is pushing freeware to help combat SQL injection attacks. Microsoft is promoting newly released freeware to help IT pros put up a fight against SQL injection attacks.The release of the products comes at a time when news of legitimate Web sites being compromised by SQL injections has become familiar in the headlines. Microsoft announced these products' availability June 24 in a security advisory. Two of the tools, UrlScan Version 3.0 Beta and Microsoft Source Code Analyzer for SQL Injection Community Technology Preview, are the sole fruits of Microsoft. The third, a Web site scanner called HP Scrawlr, was developed by Hewlett-Packard's Web Security Research Group in conjunction with Microsoft.
















It is such an easy problem to alleviate that any developer caught writing bad code should just be canned/sacked right then and there.
It is good that Microsoft is looking at helping users deal with this (though if I were a boss, I would take the more draconian approach and fire anyone who wrote crap code)
Commenting has either been disabled on this article or you are not logged in. Click here to login or register, its free!
Note: Anonymous commenting is disabled in order to keep the quality of responses to a high standard.