-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 If you really want to stop SQL injection you need to update your application code. Bolting on security will only buy you some wiggle room, it won't solve the problem.
OSSEC is very good at recognizing keyword signatures in URL requests after they are written to the log, but at that point the injection has taken place. OSSEC is not an intrusion prevention system, it is an intrusion detection system. An effective use of OSSEC would be to detect potential SQL injection attacks so they can be investigated and vulnerable code remediated or incident response can ensue. Justin C. Klein Keane Information Security and Unix Systems University of Pennsylvania School of Arts and Sciences 3600 Market St. Room 520 Philadelphia, PA 19104 215.898.0236(p) 215.573.3166(f) The digital signature on this e-mail may be confirmed using the PGP key located at: http://www.sas.upenn.edu/computing/user/3 On 02/03/2011 01:00 PM, satish patel wrote: > How efficient OSSEC is to stop SQL injection ? If not then i have to > move on mod_security > > Is anybody out there who using ossec for sql injection ? > > > Thanks, > S > -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.11 (GNU/Linux) Comment: Using GnuPG with Fedora - http://enigmail.mozdev.org/ iEYEARECAAYFAk1K9w4ACgkQR4a3EW2yjlR57wCePVZP3SHyBtitAy/ntDXlethC dssAmQEKhdItpVgzNttFZlPR1HBcmRC4 =JU8D -----END PGP SIGNATURE-----
