Video wird geladen...

Video konnte nicht geladen werden

Zur Startseite

We’ve known about SQL injection attacks for a long time. Catch vulnerable code before it’s committed to your codebase. 🔍🔒

72,022 Aufrufe • vor 3 Jahren •via X (Twitter)

9 Kommentare

Profilbild von psycopg
psycopgvor 3 Jahren

What is a SQL injection?

Profilbild von mRr3b00t
mRr3b00tvor 3 Jahren

Irl footage of me catching SQLi ! 🤙😏

Profilbild von Barney Laurance
Barney Laurancevor 3 Jahren

What happens if the vulnerability is created by the merge commit from the PR to main? Maybe unlikely, but it would be nice to have the scan run on the main branch as part of the deployment pipeline, not only on PR branches.

Profilbild von Thomas Edwin
Thomas Edwinvor 3 Jahren

When will it available for pro subscribers?

Profilbild von Christoffer Noring
Christoffer Noringvor 3 Jahren

@davidpine7 Love a great video from @GeekTrainer :)

Profilbild von 🇺🇦 Maarten Ballintijn 🌍🇪🇺🇳🇱🇺🇸
🇺🇦 Maarten Ballintijn 🌍🇪🇺🇳🇱🇺🇸vor 3 Jahren

Bobby Tables lives!

Profilbild von None
Nonevor 3 Jahren

Why not do this check for other types of exploits or viruses? PHP exploits are a good example to catch. And why do you need to press a button to do this? Just mark it on commit.

Profilbild von Information Shrekurity
Information Shrekurityvor 3 Jahren

I'd argue people stashing secrets and other important bits of information into public repositories is a bigger issue.

Profilbild von Craig Francis
Craig Francisvor 3 Jahren

To prevent Injection Vulnerabilities completely (taint checking or basic scanners aren’t good enough), you must use parameterised queries, and enforce their correct use by requiring a “developer defined string” for the SQL, HTML template, etc …

Ähnliche Videos