-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

If you really want to stop SQL injection you need to update your
application code.  Bolting on security will only buy you some wiggle
room, it won't solve the problem.

OSSEC is very good at recognizing keyword signatures in URL requests
after they are written to the log, but at that point the injection has
taken place.  OSSEC is not an intrusion prevention system, it is an
intrusion detection system.  An effective use of OSSEC would be to
detect potential SQL injection attacks so they can be investigated and
vulnerable code remediated or incident response can ensue.

Justin C. Klein Keane

Information Security and Unix Systems
University of Pennsylvania
School of Arts and Sciences
3600 Market St.
Room 520
Philadelphia, PA 19104
215.898.0236(p)
215.573.3166(f)

The digital signature on this e-mail may be confirmed using the
PGP key located at: http://www.sas.upenn.edu/computing/user/3

On 02/03/2011 01:00 PM, satish patel wrote:
> How efficient OSSEC is to stop SQL injection ? If not then i have to
> move on mod_security
> 
> Is anybody out there who using ossec for sql injection ?
> 
> 
> Thanks,
> S
> 
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (GNU/Linux)
Comment: Using GnuPG with Fedora - http://enigmail.mozdev.org/

iEYEARECAAYFAk1K9w4ACgkQR4a3EW2yjlR57wCePVZP3SHyBtitAy/ntDXlethC
dssAmQEKhdItpVgzNttFZlPR1HBcmRC4
=JU8D
-----END PGP SIGNATURE-----

Reply via email to