What is the best way to check to see if your web app or database is vulnerable to a SQL injection attack? Do I try and pass a sql command in the input box of the web app?
Check the following articles...
http://msdn.microsoft.com/en-us/magazine/cc163917.aspx
http://www.wwwcoder.com/main/parentid/258/site/2966/68/default.aspx
http://www.silksoft.co.za/data/sqlinjectionattack.htm