Snitz Forums 2000
Snitz Forums 2000
Home | Profile | Register | Active Topics | Members | Search | FAQ
Username:
Password:
Save Password
Forgot your Password?

 All Forums
 Announcements
 Announcements: Community
 Microsoft ASP Code Analyzer for SQL Injection
 New Topic  Reply to Topic
 Printer Friendly
Previous Page
Author Previous Topic Topic Next Topic
Page: of 2

HuwR
Forum Admin

United Kingdom
20584 Posts

Posted - 02 July 2008 :  15:49:54  Show Profile  Visit HuwR's Homepage  Reply with Quote
quote:
Originally posted by Astralis

This is good. I had a dream last night that I found that "script" injection all over my sites again. It requires NET 3.0, but does anyone know if you have NET 3.5, will it matter?


no it won't matter, I have all versions of .net installed<
Go to Top of Page

Etymon
Advanced Member

United States
2385 Posts

Posted - 07 August 2008 :  17:40:44  Show Profile  Visit Etymon's Homepage  Reply with Quote
Guys,

How accurate is this tool? I mean, if I run it against installed MODs and such and it says they are OK, can I leave it at that or is there something more I need to do?<
Go to Top of Page

ruirib
Snitz Forums Admin

Portugal
26364 Posts

Posted - 07 August 2008 :  18:17:03  Show Profile  Send ruirib a Yahoo! Message  Reply with Quote
You can trust the holes it finds, but if it fails to find any, you cannot conclude the code is bug free. Manual analysis is the only way to be sure the code is safe.<


Snitz 3.4 Readme | Like the support? Support Snitz too
Go to Top of Page

Etymon
Advanced Member

United States
2385 Posts

Posted - 10 August 2008 :  04:29:45  Show Profile  Visit Etymon's Homepage  Reply with Quote
Just an FYI ...

Microsoft upgraded the tool to version 1.3 in mid-July and downgraded the .NET requirement within this version from 3.0 to 2.0.<
Go to Top of Page

Lon2
Junior Member

USA
151 Posts

Posted - 16 January 2009 :  18:01:09  Show Profile  Reply with Quote
Thanks for the info, Rui! I'll shoot one back at ya. I've used Scrawlr to help find a few vulnerabilities in our applications. Appearantly Hewlett Packard was contracted by Microsoft to help come up with some SQL Injection Tools and they offer this one as a freebie now. For whatever it's worth.

Download: https://download.spidynamics.com/products/scrawlr/
Forum: http://www.communities.hp.com/securitysoftware/forums/198.aspx

<
Go to Top of Page

ruirib
Snitz Forums Admin

Portugal
26364 Posts

Posted - 16 January 2009 :  19:08:17  Show Profile  Send ruirib a Yahoo! Message  Reply with Quote
Thanks for the info .<


Snitz 3.4 Readme | Like the support? Support Snitz too
Go to Top of Page
Page: of 2 Previous Topic Topic Next Topic  
Previous Page
 New Topic  Reply to Topic
 Printer Friendly
Jump To:
Snitz Forums 2000 © 2000-2021 Snitz™ Communications Go To Top Of Page
This page was generated in 0.05 seconds. Powered By: Snitz Forums 2000 Version 3.4.07