正在加载视频...

视频加载失败

We’ve known about SQL injection attacks for a long time. Catch vulnerable code before it’s committed to your codebase. 🔍🔒

72,022 次观看 • 3 年前 •via X (Twitter)

9 条评论

psycopg 的头像
psycopg3 年前

What is a SQL injection?

mRr3b00t 的头像
mRr3b00t3 年前

Irl footage of me catching SQLi ! 🤙😏

Barney Laurance 的头像
Barney Laurance3 年前

What happens if the vulnerability is created by the merge commit from the PR to main? Maybe unlikely, but it would be nice to have the scan run on the main branch as part of the deployment pipeline, not only on PR branches.

Thomas Edwin 的头像
Thomas Edwin3 年前

When will it available for pro subscribers?

Christoffer Noring 的头像
Christoffer Noring3 年前

@davidpine7 Love a great video from @GeekTrainer :)

🇺🇦 Maarten Ballintijn 🌍🇪🇺🇳🇱🇺🇸 的头像
🇺🇦 Maarten Ballintijn 🌍🇪🇺🇳🇱🇺🇸3 年前

Bobby Tables lives!

None 的头像
None3 年前

Why not do this check for other types of exploits or viruses? PHP exploits are a good example to catch. And why do you need to press a button to do this? Just mark it on commit.

Information Shrekurity 的头像
Information Shrekurity3 年前

I'd argue people stashing secrets and other important bits of information into public repositories is a bigger issue.

Craig Francis 的头像
Craig Francis3 年前

To prevent Injection Vulnerabilities completely (taint checking or basic scanners aren’t good enough), you must use parameterised queries, and enforce their correct use by requiring a “developer defined string” for the SQL, HTML template, etc …

相关视频