2
kudos
spam Kudos Remove

Looking for security vulnerabilities in database code

published 368 days, 8 hours ago posted by sasa 370 days, 13 hours, 28 minutes ago
Tuesday, July 28, 2009 12:05:09 PM GMT Sunday, July 26, 2009 6:37:29 AM GMT

I've always been concerned with security and I've always stressed the importance of auditing the REAL user context not just the current user (see this post on EXECUTE AS and auditing). So, I generally try to avoid using dynamic string execution and if necessary create well tested/protected parameters (fyi - using QUOTENAME can be a fantasic solution to protectng identifiers as input paramet...

category: Security | clicked: 1 | | source: www.sqlskills.com | show counter code
tags: Security, SQL Server 2005, SQL Server 2008

No comments yet, be the first one to post comment.

To post your comment please login or signup