Microsoft Interview Question for Software Engineer / Developers






Comment hidden because of low score. Click to expand.
1
of 1 vote

always use paramiterized querys to avoid sql injection

- jagdish December 16, 2011 | Flag Reply
Comment hidden because of low score. Click to expand.
0
of 0 votes

always use paramiterized statement and not querys to avoid sql injection

- jagdish December 16, 2011 | Flag
Comment hidden because of low score. Click to expand.
1
of 1 vote

Take a step back and perform threat modelling for the web application to find out the threats/attack surface/end points, Then, start by mitigating risks with each input source, eg:-
User Input:
- Bound Checking.
- Output encoding to avoid XSS.
- Never use blacklist to prevent XSS.
- Never trust session identifiers from user, treat them as any other input from the user and perform validation on the session identifiers.
- Update the session identifier on user state change to prevent session fixation.
- Perform query string filteration to avoid XSS.
- Use nonce in all the web pages generated by the web server to avoid CSRF.
- Always check HTTP REFERRER header to make decisions about valid and forged requests.
- Set session cookies in a secure manner [isSecure, httpOnly, isSession]
- Always use no-cache, no-store META information for pages which shouldn't be cached by browser.
- Use ORM or parameterized queries to avoid blind sql injection.
- Use custom exception handling for sql error's to prevent information leakage.

The list is just a start and there are many more considerations to security.

- Vikas Chourasiya December 01, 2013 | Flag Reply
Comment hidden because of low score. Click to expand.
0
of 0 vote

We should prevent sql injection using prepared statement..!!!

- barry lance leo July 24, 2011 | Flag Reply


Add a Comment
Name:

Writing Code? Surround your code with {{{ and }}} to preserve whitespace.

Books

is a comprehensive book on getting a job at a top tech company, while focuses on dev interviews and does this for PMs.

Learn More

Videos

CareerCup's interview videos give you a real-life look at technical interviews. In these unscripted videos, watch how other candidates handle tough questions and how the interviewer thinks about their performance.

Learn More

Resume Review

Most engineers make critical mistakes on their resumes -- we can fix your resume with our custom resume review service. And, we use fellow engineers as our resume reviewers, so you can be sure that we "get" what you're saying.

Learn More

Mock Interviews

Our Mock Interviews will be conducted "in character" just like a real interview, and can focus on whatever topics you want. All our interviewers have worked for Microsoft, Google or Amazon, you know you'll get a true-to-life experience.

Learn More