Video yükleniyor...

Video Yüklenemedi

Ana Sayfaya Dön

We’ve known about SQL injection attacks for a long time. Catch vulnerable code before it’s committed to your codebase. 🔍🔒

72,022 görüntüleme • 3 yıl önce •via X (Twitter)

9 Yorum

psycopg profil fotoğrafı
psycopg3 yıl önce

What is a SQL injection?

mRr3b00t profil fotoğrafı
mRr3b00t3 yıl önce

Irl footage of me catching SQLi ! 🤙😏

Barney Laurance profil fotoğrafı
Barney Laurance3 yıl önce

What happens if the vulnerability is created by the merge commit from the PR to main? Maybe unlikely, but it would be nice to have the scan run on the main branch as part of the deployment pipeline, not only on PR branches.

Thomas Edwin profil fotoğrafı
Thomas Edwin3 yıl önce

When will it available for pro subscribers?

Christoffer Noring profil fotoğrafı
Christoffer Noring3 yıl önce

@davidpine7 Love a great video from @GeekTrainer :)

🇺🇦 Maarten Ballintijn 🌍🇪🇺🇳🇱🇺🇸 profil fotoğrafı
🇺🇦 Maarten Ballintijn 🌍🇪🇺🇳🇱🇺🇸3 yıl önce

Bobby Tables lives!

None profil fotoğrafı
None3 yıl önce

Why not do this check for other types of exploits or viruses? PHP exploits are a good example to catch. And why do you need to press a button to do this? Just mark it on commit.

Information Shrekurity profil fotoğrafı
Information Shrekurity3 yıl önce

I'd argue people stashing secrets and other important bits of information into public repositories is a bigger issue.

Craig Francis profil fotoğrafı
Craig Francis3 yıl önce

To prevent Injection Vulnerabilities completely (taint checking or basic scanners aren’t good enough), you must use parameterised queries, and enforce their correct use by requiring a “developer defined string” for the SQL, HTML template, etc …

Benzer Videolar