many of the folks i interact with always says that sql injection and xss does not matter much these days.i say i m strongly disagree.it takes skills to write a buffer overflow/heap overflow and therefor not many people really preffer doing it that way.if you want to own some site i bet my first guess anyone will do is look for either sql injection or xss.
there are many such bugs discovered in various popular softwares.it is not possible to ignore this attacks.only thing i want to say here is take them seriously otherwise some kid will come an hack your site.
why sql injection and xss are still dangrous today?
By secgeeks - Posted on July 13th, 2008
54
vote
http://www.secgeeks.com/trackback/1975
















