Free Newsletters
Technology & Business Daily

InfoWorld
Log-in | Register

Microsoft releases security tools for ASP, ASP.Net

Tools are designed to protect Web sites that could be hit with SQL injection attacks


Microsoft on Tuesday released SQL injection defense and detection tools designed to help developers fight attacks on Web sites that use ASP and ASP.Net technologies.

The tools include URLScan 3.0, which is in beta release, and Microsoft Source Code Analyzer for SQL Injection (MSCASI), available as a Community Technology Preview. Additionally, HP on Tuesday released Scrawlr, a SQL injection detection tool developed by the HP Web Security Research Group and Microsoft.

Developed to help battle recent SQL injection attacks as per a Microsoft Security Advisory bulletin, the tools are intended to help developers build more secure code and promote a more trusted ecosystem, Microsoft said.

In the bulletin, Microsoft cited a rise in SQL injection attacks exploiting unverified user data input; when these attacks succeed, an attacker can compromise data stored in databases and possibly execute remote code. Clients browsing to a compromised server could be forwarded to malicious sites that may install malware on the client machine.

"Microsoft is aware of a recent escalation in a class of attacks targeting Web sites that use Microsoft ASP and ASP.NET technologies but do not follow best practices for secure Web application development. These SQL injection attacks do not exploit a specific software vulnerability but instead target Web sites that do not follow secure coding practices for accessing and manipulating data stored in a relational database," the bulletin said.

A Microsoft engineer emphasized the complementary nature of the three tools.

"Each of these tools works differently and each attacks the SQL injection problem from a different angle and in combination they complement each other well," said Bryan Sullivan, an engineer with Microsoft's Security Development Lifecycle team. 

MSCASI analyzes ASP source code to find potential vulnerabilities. First- and second-order SQL injection bugs can be detected and the exact line of affected source code will be revealed.

UrlScan 3.0 updates the existing URLScan IIS filter tool, blocking HTTP requests that contain suspicious text such as SQL keywords. Scrawlr is described as a black-box analysis tool that does not access source code but, after being given the URL of a Web application, will analyze the application for SQL injection vulnerabilities.

The tools and security advisory can be accessed here.

Paul Krill is editor at large at InfoWorld.

Talkback:

commentPost a Comment

 

MOST COMMENTS

 
 





Do you have the power to resolve technical issues with one call?
Watch this webcast to get an under-the-hood look at a remote support solution that enables the IT organization to be the engine that keeps your end users productive and your company running.

»  Click here to view this Webcast
  Virtualization Solutions Guide
This comprehensive IT Strategy Guide covers Virtualization and puts you at the forefront of the discussion. You'll learn all you need to know from the cost of virtualization, how to implement it for your business, how to back it up safely and which products are best. Sponsored by Riverbed

»  Click here to download now

- Special Advertising Partners -
WHITE PAPERS
 

» Technology White Papers Library

Technology White Papers by Topic

Technology White Papers E-mail Alert

Find out when the latest white paper is available:
 
 
INFOWORLD MARKETPLACE
 
» BUY A LINK NOW
 
 

Video

 
 
 

Podcasts

 
IFW Daily 08/29/2008

Microsoft will focus on performance issues in Windows 7 and IE8, Qualcomm...

 
 

 

Columnists

 
 
 

Resource Center


Ads by techwords beta  [See your link here]
 




Sponsored Technology Links

 
 
 HOME  NEWS  BLOGS  PODCASTS  VIDEOS  TECHNOLOGIES  TEST CENTER  EVENTS  CAREERS   About | Advertise | Awards | RSS | Contact Us 

Copyright © 2008, Reprints, Permissions, Licensing, IDG Network, Privacy Policy, Terms of Service.
All Rights reserved. InfoWorld is a leading publisher of technology information and product reviews on topics including viruses,
phishing, worms, firewalls, security, servers, storage, networking, wireless, databases, and web services.

CIO :: ComputerWorld :: CSO :: Demo :: GamePro :: Games.net :: IDG Connect :: IDG World Expo
Industry Standard :: IT World :: JavaWorld :: LinuxWorld :: MacUser :: Macworld :: Network World :: PC World :: Playlist