Hacker News new | ask | show | jobs
by np422 4426 days ago
Agree!

You don't need to bother with old-school stuff like grsec, iptables, IDS, chrooted applications or any stack-protection technologies.

Get a WAF, audit your web-app source-code and use a pen-test tool regularly instead.

SQL-injections walk right in, through the front door. They stuff their pockets full of data and then leave the same way they came, unnoticed most of the time.