You don't need to bother with old-school stuff like grsec, iptables, IDS, chrooted applications or any stack-protection technologies.
Get a WAF, audit your web-app source-code and use a pen-test tool regularly instead.
SQL-injections walk right in, through the front door. They stuff their pockets full of data and then leave the same way they came, unnoticed most of the time.
Comments
Agree!
You don't need to bother with old-school stuff like grsec, iptables, IDS, chrooted applications or any stack-protection technologies.
Get a WAF, audit your web-app source-code and use a pen-test tool regularly instead.
SQL-injections walk right in, through the front door. They stuff their pockets full of data and then leave the same way they came, unnoticed most of the time.