Загрузка видео...

Не удалось загрузить видео

На главную

We’ve known about SQL injection attacks for a long time. Catch vulnerable code before it’s committed to your codebase. 🔍🔒

72,022 просмотров • 3 лет назад •via X (Twitter)

Комментарии: 9

Фото профиля psycopg
psycopg3 лет назад

What is a SQL injection?

Фото профиля mRr3b00t
mRr3b00t3 лет назад

Irl footage of me catching SQLi ! 🤙😏

Фото профиля Barney Laurance
Barney Laurance3 лет назад

What happens if the vulnerability is created by the merge commit from the PR to main? Maybe unlikely, but it would be nice to have the scan run on the main branch as part of the deployment pipeline, not only on PR branches.

Фото профиля Thomas Edwin
Thomas Edwin3 лет назад

When will it available for pro subscribers?

Фото профиля Christoffer Noring
Christoffer Noring3 лет назад

@davidpine7 Love a great video from @GeekTrainer :)

Фото профиля 🇺🇦 Maarten Ballintijn 🌍🇪🇺🇳🇱🇺🇸
🇺🇦 Maarten Ballintijn 🌍🇪🇺🇳🇱🇺🇸3 лет назад

Bobby Tables lives!

Фото профиля None
None3 лет назад

Why not do this check for other types of exploits or viruses? PHP exploits are a good example to catch. And why do you need to press a button to do this? Just mark it on commit.

Фото профиля Information Shrekurity
Information Shrekurity3 лет назад

I'd argue people stashing secrets and other important bits of information into public repositories is a bigger issue.

Фото профиля Craig Francis
Craig Francis3 лет назад

To prevent Injection Vulnerabilities completely (taint checking or basic scanners aren’t good enough), you must use parameterised queries, and enforce their correct use by requiring a “developer defined string” for the SQL, HTML template, etc …

Похожие видео