Nicole Holden

Principal Application Security Engineer

Nicole Holden is EDB's Principal Application Security Engineer and works on the Information Security Team. She is committed to helping EDB achieve its security goals, especially in areas related to Application and Offensive Security. 

Nicole started her security journey at the Rochester Institute of Technology, where she graduated Magna Cum Laude with a Bachelors in Computer Security and Software Engineering. From there she dove into the trenches of information security, working as a penetration tester while beginning the process of developing a cutting edge Application Security Program. In addition to her role at EDB Nicole is active in the security community, speaking as an Application Security and Offensive Security expert at conferences, writing the occasional security blog post, and mentoring professionals looking to enter the Information Security space and grow their careers.

Read Blogs

Postgres Tutorials
작성자: 니콜 홀든 | 2024년 4월 29일 SQL 인젝션(SQL Injection, SQLi)은 사용자 입력이 SQL 명령과 분리되지 않을 때 발생할 수 있는 대표적인 데이터베이스 보안 위협입니다. 이 글에서는 OWASP와 미국 사이버보안 및 인프라 보안국(CISA)의 권고사항을 바탕으로 입력 검증, 데이터 이스케이핑, 매개변수화된 쿼리, 코드 리뷰, 최소 권한 원칙을 살펴봅니다. PostgreSQL과 EDB Postgres Advanced Server(EPAS)에서 활용할 수 있는 방어 기능도 함께 소개합니다. SQL 인젝션의 위험성과 주요 사례 2024년 3월, CISA는 SQL 인젝션과 관련해 디자인부터 안전: 소프트웨어에서 SQL 인젝션 취약점 제거라는 권고문을 발표했습니다. CISA에 따르면...
Postgres Tutorials
In March of 2024 CISA issued the following advisory related to SQL injection (SQLi): Secure by Design Alert - Eliminating SQL Injection Vulnerabilities in Software. SQL Injection is one of the most pervasive and damaging vulnerability types database administrators and developers are tasked with defending against. According to CISA “SQL injection vulnerabilities involve the insertion of user-supplied input directly into a SQL command, allowing threat actors to execute arbitrary queries. SQLi vulnerabilities are caused by software developers’ inattention to security best practices, resulting in the co-mingling of database queries and user-supplied data.” When exploited, attackers can gain unauthorized access to sensitive data, modify database contents, or even execute arbitrary commands on the underlying server. The consequences of a successful SQL injection attack can be catastrophic, leading to compromised customer information, financial loss, damaged reputation and regulatory penalties.