SqlShare.com Logo
 
Skip Navigation Links
Home
Video List
Classes
About Us
Login / Register
Subscribe RSS Feed 

Idera Virtual Database

SQL Injection Explained

SQL injection is a simple and common attack that can easily be prevented - if you understand how it works. In this video Brian covers what SQL Injection is and how to prevent from your code.

Duration:
5 mins 44 secs
Skill Level:
100
Rating:
4.35 out of 5
Publish Date:
December 15, 2008
SQL Injection Explained Watch Video Now  Watch it later!
Bookmark and Share
 
1=Poor, 3=Good, 5=Excellent

About the Author

Image of K. Brian Kelley
Brian is a SQL Server author, columnist, and MVP focusing primarily on SQL Server security. He currently serves as database administrator / architect at AgFirst Farm Credit Bank where he can focus on his passion: SQL Server. He formerly served as a systems and security architect for AgFirst Farm Credit Bank where he worked on Active Directory, Windows security, VMware, and Citrix. In the technical...

References

There are no downloads or recommended reading links for this video

Comments
Jason Martinez on 1/31/2009
Explained beautifully

SAy Soukamneuth on 5/11/2009
Good job

SAy Soukamneuth on 5/11/2009
good job

Veilinginfo on 5/11/2009
Very basic

Harold Snelgrove on 5/11/2009
Great video- I'll recommend it to my junior team members.

Axel Grude on 5/11/2009
I'd like to see an advanced video about methods of code obfuscation

9F655BCB23 on 5/11/2009
Really wanted to see more ways in which injection can take place and how to prevent them. This was way too basic.

Saravanan on 5/11/2009
Short and Clear. Nice Job. Would like to see advanced videos too.

Mark Fyffe on 5/11/2009
A little basic but probably good for beginners

BJ on 5/11/2009
great video! Iwas able to understnad it and I am not a programmer... :)

Rubens on 5/11/2009
Fantastic video, something I don't know a lot about so this video was very useful to me.

Kenneth Wymore on 5/11/2009
Thank you so much for making this easier to understand.

Paul Swanberg on 5/11/2009
Short and to the point

Steve Harris on 5/11/2009
might want to add additional videos of more complex ways sql injection can occur

Carla Wilson on 5/11/2009
Would have been nice to see an example of validating a string input, as this is more complicated than validating for an integer value.

D151BB6B9F on 5/11/2009
You should have given an example of how to validate varChar data. It's easy to check for an integer, but what's the best way to validate TEXT. Showing a check for certain characters (e.g. ";") or whatever way you'd recommend, would have been worth the extra minute or less on the clip.

Marshall Cole on 5/11/2009
Awesome!!!!!!!!!!!!!!!1

DavidB on 5/11/2009
A great basic overview of SQL injection and how to protect against it.

82796FB536 on 5/11/2009
Input validation is not nessesary if you use command object with parameters. PLEASE DO NOT USE DYNAMIC SQL!!!

Michelle Poolet on 5/11/2009
I really like the entire JumpstartTV concept and content -- I can get a bite of good info with my morning coffee. Thanks!

Stephanie Brown on 5/11/2009
Good basic explanation. Would have been nice to show other injection attacks, since validation on text fields is much more difficult.

Andrew on 5/11/2009
Great and simple way to explain SQL injection

Mark Sopczak on 5/11/2009
Very good.

Patrick on 5/11/2009
This was a great video.

luther smith on 5/11/2009
Very clear, no unnecessary words

John William Shroy on 5/11/2009
Basic with great example; good explanation.

melt on 5/12/2009
nice an trivial way to illustrate the problem

Ahmad Elayyan on 5/12/2009
x

Leonard Peoples on 5/12/2009
Great video. All developers should be aware of this.

Dipak Saha on 5/12/2009
Great demo.

Anitha on 5/13/2009
Very insightful and valuable.

Christine Lewis on 5/13/2009
great simple example of the issue

Stuart Ainsworth on 5/18/2009
The question at the end had almost nothing to do with the content material, other than both talked about SQL Injection. The video discussed security and validation; the question referred specifically to EXEC() and sp_executeSQL, neither of which were mentioned in the video.

BillRoger on 5/20/2009
short but very interesting

David Lundell on 5/27/2009
good intro to sql injection but glosses over the vulnerabilities in stored procs. also the question afterwards didn't come from the video

01EFFB45CF on 5/30/2009
Best explanation of SQL Injection yet. Other examples I've seen are much too wordy and clubmsy. This demo was great.

Juan Lorenzoni on 6/8/2009
Great information.

xakep on 9/13/2009
dh

Jody Dodson on 9/21/2009
Short and sweet with applicable information. Thank you!

sunil on 10/22/2009
cool

JohnG on 10/29/2009
Nice one!



Must Be Logged In
 

How Do I Become a Video Author? |  Newsletter History

Copyright © Fourdeuce, Inc., 2005-2009. All Rights Reserved | Privacy Policy | Terms & Conditions