Hello. There is a page of type name.html. How to forbid modifying the URL via "?" Through .htaccess and put a 301 redirect from such vulnerable URLs to the name.html page and the like? Now, by any request, by the link http://name.name/name.html ? After the_this_ignation/ you can get a server response - 200 (the page exists).
осуществить слепой подборwhat else is a blind selection, what will the attackers choose? With regards to the main question - so make the redirect in the code, it would be better if you really want htaccess - that’s the answer to the question of stackoverflow.com/questions/3457022/… - Goncharov Alexandersql-injectioninjections should be processed not by destroying parameters, but by processing parameters in the code of the controllers. Injections will be only if your.htmllink is actually not a fig not html - but is processed by the server (php, asp, java), with what is full of holes. That is, the injections are watched differently, otherwise the holes you will not go anywhere. 99% of injections go away when using the query builder, for example framework.zend.com/manual/1.10/ru/zend.db.select.html (for PHP) - Goncharov Alexander