<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Blind SQL Injection in Oracle</title>
	<atom:link href="http://www.slaviks-blog.com/2009/10/13/blind-sql-injection-in-oracle/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.slaviks-blog.com/2009/10/13/blind-sql-injection-in-oracle/</link>
	<description>Slavik&#039;s Blog</description>
	<lastBuildDate>Thu, 22 Jul 2010 15:04:28 -0700</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
	<item>
		<title>By: Week 42 in Review &#8211; 2009 &#124; Infosec Events</title>
		<link>http://www.slaviks-blog.com/2009/10/13/blind-sql-injection-in-oracle/comment-page-1/#comment-4180</link>
		<dc:creator>Week 42 in Review &#8211; 2009 &#124; Infosec Events</dc:creator>
		<pubDate>Wed, 03 Feb 2010 06:37:24 +0000</pubDate>
		<guid isPermaLink="false">http://www.slaviks-blog.com/?p=187#comment-4180</guid>
		<description>[...] Blind SQL Injection in Oracle &#8211; slaviks-blog.com This post describes SQL injection types, examples for web apps and blind SQL injection into Oracle databases. [...]</description>
		<content:encoded><![CDATA[<p>[...] Blind SQL Injection in Oracle &#8211; slaviks-blog.com This post describes SQL injection types, examples for web apps and blind SQL injection into Oracle databases. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Pete Finnigan</title>
		<link>http://www.slaviks-blog.com/2009/10/13/blind-sql-injection-in-oracle/comment-page-1/#comment-3984</link>
		<dc:creator>Pete Finnigan</dc:creator>
		<pubDate>Thu, 15 Oct 2009 09:56:36 +0000</pubDate>
		<guid isPermaLink="false">http://www.slaviks-blog.com/?p=187#comment-3984</guid>
		<description>Hi Slavik,

Thanks for your reply. Yes i understood the paper and also what you were saying. i was just pointing at anything I could remember in the same &quot;space&quot; and also say &quot;yes&quot; I think you have a valid technique.

cheers

Pete</description>
		<content:encoded><![CDATA[<p>Hi Slavik,</p>
<p>Thanks for your reply. Yes i understood the paper and also what you were saying. i was just pointing at anything I could remember in the same &#8220;space&#8221; and also say &#8220;yes&#8221; I think you have a valid technique.</p>
<p>cheers</p>
<p>Pete</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Slavik</title>
		<link>http://www.slaviks-blog.com/2009/10/13/blind-sql-injection-in-oracle/comment-page-1/#comment-3983</link>
		<dc:creator>Slavik</dc:creator>
		<pubDate>Thu, 15 Oct 2009 02:32:02 +0000</pubDate>
		<guid isPermaLink="false">http://www.slaviks-blog.com/?p=187#comment-3983</guid>
		<description>@Pete

Hi Pete,

Of course I&#039;m familiar with the same techniques for SQL Server (it&#039;s even in the blog entry). What I was not familiar with is the technique for Oracle. To me, it sounds a very valid attack technique because DBMS_PIPE and such are usually open in the databases I&#039;ve seen.</description>
		<content:encoded><![CDATA[<p>@Pete</p>
<p>Hi Pete,</p>
<p>Of course I&#8217;m familiar with the same techniques for SQL Server (it&#8217;s even in the blog entry). What I was not familiar with is the technique for Oracle. To me, it sounds a very valid attack technique because DBMS_PIPE and such are usually open in the databases I&#8217;ve seen.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Pete Finnigan</title>
		<link>http://www.slaviks-blog.com/2009/10/13/blind-sql-injection-in-oracle/comment-page-1/#comment-3981</link>
		<dc:creator>Pete Finnigan</dc:creator>
		<pubDate>Wed, 14 Oct 2009 13:00:38 +0000</pubDate>
		<guid isPermaLink="false">http://www.slaviks-blog.com/?p=187#comment-3981</guid>
		<description>Hi Slavik,

yes this is a valid technique. Chema Alonso wrote a paper including this technique two years ago. I linked to it in my SQL Server security blog at the time - http://database-security.petefinnigan.com/sqlserver/weblog/archives/00000009.htm - he also references a number of other sources such as Chris Anley and David Litchfield who also talk about this technique.

cheers

Pete</description>
		<content:encoded><![CDATA[<p>Hi Slavik,</p>
<p>yes this is a valid technique. Chema Alonso wrote a paper including this technique two years ago. I linked to it in my SQL Server security blog at the time &#8211; <a href="http://database-security.petefinnigan.com/sqlserver/weblog/archives/00000009.htm" rel="nofollow">http://database-security.petefinnigan.com/sqlserver/weblog/archives/00000009.htm</a> &#8211; he also references a number of other sources such as Chris Anley and David Litchfield who also talk about this technique.</p>
<p>cheers</p>
<p>Pete</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Dynamic Page Served (once) in 0.990 seconds -->
