Sign In
The What, Why and How of Software Security
Translate This Page
Translate this page
Powered by
Microsoft® Translator
Options
About
Email Blog Author
RSS for posts
Atom
RSS for comments
OK
Search
Advanced search options...
Search In:
Everything
Blogs
Forums
People
Groups
Places
Pages
Date range:
All Time
Last Year
Last 6 Months
Last 3 Months
Last Month
Last Week
Last Two Days
Tags
Authorization
Catch the security flaw
Cryptography
Least Priv
Security Conference/ Workshop
Security Tool
Archive
Archives
June 2009
(1)
April 2009
(1)
February 2009
(1)
December 2008
(3)
November 2008
(1)
August 2008
(1)
July 2008
(2)
June 2008
(1)
March 2008
(1)
February 2008
(1)
January 2008
(2)
December 2007
(1)
November 2007
(3)
October 2007
(2)
September 2007
(2)
August 2007
(1)
December, 2008
MSDN Blogs
>
The What, Why and How of Software Security
>
December, 2008
Posts
Subscribe via RSS
Sort by:
Most Recent
|
Most Views
|
Most Comments
Excerpt View
|
Full Post View
The What, Why and How of Software Security
catch the security flaw #5 (flaw and its countermeasure)
Posted
over 4 years ago
by
Varun Sharma
1
Comments
In my last post , I showed input validation code that uses RegularExpressionValidators improperly. Thanks to Mathew Grabau and Marius Cristian CONSTANTIN for pointing out that the Page’s IsValid property has not been checked before using the input. As...
The What, Why and How of Software Security
Catch the security flaw #5
Posted
over 4 years ago
by
Varun Sharma
5
Comments
A lot of web applications use RegularExpressionValidators for performing input validation [1]. Sometimes these validators are not implemented properly, which can lead to potential flaws. See if you can catch the flaw here:- Code for Default.aspx:- 1:...
The What, Why and How of Software Security
Catch the Security Flaw(s) #4
Posted
over 4 years ago
by
Varun Sharma
4
Comments
Identify as many security issues as you can with this piece of code:- 1: [WebMethod] 2: public string GetEmpName( string empid) 3: { 4: SqlConnection con = new SqlConnection( "server=.;database=test;uid=sa;pwd=PassW2rd12" ); 5: SqlCommand cmd =...
Page 1 of 1 (3 items)