July 11, 2008
Microsoft has released an analyzer to check asp code for vulnerabilities that can lead to SQL injection attacks. the tool can be downloaded form Microsoft's site and run against source code.
To view more information on the tool and to view the SQL security forums for the latest information on Microsoft SQL, please visit the following site:
http://blogs.msdn.com/sqlsecurity/archive/2008/07/12/microsoft-source-code-analyzer-for-sql-injection-july-2008-ctp.aspx
To download the analyzer, please click the following hyperlink:
http://www.microsoft.com/downloads/details.aspx?FamilyId=58A7C46E-A599-4FCB-9AB4-A4334146B6BA&displaylang=en