Live data from Hacker News

Massive SQL injection attack making the rounds—694K URLs so far

arstechnica.com

21–22 of 22 posts

Re: Massive SQL injection attack making the rounds—694K URLs so far

#22
post #11
post #8

Earlier quoted context omitted.

Exactly. I'd like to know how to check my personal site and some of our sites at work to see if they are vulnerable or not.

Do they use prepared statements? If not, they are almost certainly vulnerable.

Look I am not trying to start a flamewar here, but if his code is developed without knowledge of sql injections then they are almost certainly vulnerable.

It is almost impossible to fuck up prepared statements, so although they take longer to write it is a good way to secure a website.

Post reply on HN