IBM: SQL Injections Entering 'Third Wave' - Growing Resistant
SQL injection grows more resistant to traditional security measures as it enters a third wave.
SQL injection, recovered only after a series of countermeasures, from blocking the Chinese IP addresses where the attacks originated, to finding a developer capable of fixing a vulnerability in its Web application.
The X-Force team at IBM recently made some changes in how it detects SQL injections, changes that allowed its technology to find the latest attacks, Dewey says. Numerous other vendors are releasing updates every week to combat the problem, he notes. "With our protection, they haven't ever evaded us," he says, "so far as we know."
SQL injection



