<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Musings on Database Security &#187; breach</title>
	<atom:link href="http://www.slaviks-blog.com/category/breach/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.slaviks-blog.com</link>
	<description>Slavik&#039;s Blog</description>
	<lastBuildDate>Wed, 07 Dec 2011 17:07:31 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>LizaMoon Threat Brief</title>
		<link>http://www.slaviks-blog.com/2011/04/13/lizamoon-threat-brief/</link>
		<comments>http://www.slaviks-blog.com/2011/04/13/lizamoon-threat-brief/#comments</comments>
		<pubDate>Thu, 14 Apr 2011 03:01:09 +0000</pubDate>
		<dc:creator>Slavik</dc:creator>
				<category><![CDATA[breach]]></category>
		<category><![CDATA[SQL injection]]></category>

		<guid isPermaLink="false">http://www.slaviks-blog.com/?p=310</guid>
		<description><![CDATA[McAfee just posted a threat brief we created regarding the LizaMoon attack spreading through vulnerable web sites. Thanks to Vadim and our red team for providing the material and Andy for doing the proofing and adding his words of wisdom. As always, the simple way to solve SQL injection is to use bind variables. On another [...]]]></description>
		<wfw:commentRss>http://www.slaviks-blog.com/2011/04/13/lizamoon-threat-brief/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>MySQL.com Database Compromised By Blind SQL Injection</title>
		<link>http://www.slaviks-blog.com/2011/03/27/mysql-com-database-compromised-by-blind-sql-injection/</link>
		<comments>http://www.slaviks-blog.com/2011/03/27/mysql-com-database-compromised-by-blind-sql-injection/#comments</comments>
		<pubDate>Sun, 27 Mar 2011 22:53:19 +0000</pubDate>
		<dc:creator>Slavik</dc:creator>
				<category><![CDATA[breach]]></category>
		<category><![CDATA[SQL injection]]></category>

		<guid isPermaLink="false">http://www.slaviks-blog.com/?p=308</guid>
		<description><![CDATA[I guess this is somewhat ironical. At least it was nothing simple as in-band SQL Injection via errors or directly. It just goes to show you that any site can be vulnerable to attacks, even guys that write DB engines for a living. On the other hand, I&#8217;m sure that the sites were not created [...]]]></description>
		<wfw:commentRss>http://www.slaviks-blog.com/2011/03/27/mysql-com-database-compromised-by-blind-sql-injection/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>PlentyOfFish hacked &#8211; blames messenger</title>
		<link>http://www.slaviks-blog.com/2011/01/31/plentyoffish-hacked-blames-messenger/</link>
		<comments>http://www.slaviks-blog.com/2011/01/31/plentyoffish-hacked-blames-messenger/#comments</comments>
		<pubDate>Tue, 01 Feb 2011 02:50:02 +0000</pubDate>
		<dc:creator>Slavik</dc:creator>
				<category><![CDATA[breach]]></category>
		<category><![CDATA[Passwords]]></category>
		<category><![CDATA[sentrigo]]></category>
		<category><![CDATA[SQL injection]]></category>

		<guid isPermaLink="false">http://www.slaviks-blog.com/?p=301</guid>
		<description><![CDATA[This is just too funny &#8211; the site owner is accusing the guys that reported the vulnerability of extortion. More details can be found here and here. And it all started with a simple SQL Injection that can be exploited through the site error messages. I talked about this multiple times in the past. Of course, the [...]]]></description>
		<wfw:commentRss>http://www.slaviks-blog.com/2011/01/31/plentyoffish-hacked-blames-messenger/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>RBS WorldPay site got hacked</title>
		<link>http://www.slaviks-blog.com/2009/09/23/rbs-worldpay-site-got-hacked/</link>
		<comments>http://www.slaviks-blog.com/2009/09/23/rbs-worldpay-site-got-hacked/#comments</comments>
		<pubDate>Wed, 23 Sep 2009 12:40:22 +0000</pubDate>
		<dc:creator>Slavik</dc:creator>
				<category><![CDATA[breach]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[SQL injection]]></category>
		<category><![CDATA[sql_injection]]></category>

		<guid isPermaLink="false">http://www.slaviks-blog.com/?p=164</guid>
		<description><![CDATA[OK, it looks like this was a test site but nevertheless it makes you wonder. Leaving web application vulnerable to SQL injection and entire databases out there without protection is a sure way to get yourself hacked. It doesn&#8217;t even matter if the site was a test site (I hope it was) but we&#8217;ve seen [...]]]></description>
		<wfw:commentRss>http://www.slaviks-blog.com/2009/09/23/rbs-worldpay-site-got-hacked/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>You Know Breaches Hit the Big Time When&#8230;</title>
		<link>http://www.slaviks-blog.com/2007/09/09/you-know-breaches-hit-the-big-time-when/</link>
		<comments>http://www.slaviks-blog.com/2007/09/09/you-know-breaches-hit-the-big-time-when/#comments</comments>
		<pubDate>Sun, 09 Sep 2007 11:41:02 +0000</pubDate>
		<dc:creator>Slavik</dc:creator>
				<category><![CDATA[breach]]></category>
		<category><![CDATA[compliance]]></category>
		<category><![CDATA[insider threat]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[sb1386]]></category>
		<category><![CDATA[breach-notification]]></category>

		<guid isPermaLink="false">http://www.slaviks-blog.com/2007/09/09/you-know-breaches-hit-the-big-time-when/</guid>
		<description><![CDATA[You know that data breaches have become part of big business reality when the Harvard Business Review publishes a hypothetical case study entitled &#8220;Boss, I Think Someone Stole Our Customer Data&#8221;. The case study does a very good job of illustrating the initial confusion and many gray areas that enterprises face when confronted with a [...]]]></description>
		<wfw:commentRss>http://www.slaviks-blog.com/2007/09/09/you-know-breaches-hit-the-big-time-when/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>DBAs are not the enemy, but they too need watching</title>
		<link>http://www.slaviks-blog.com/2007/07/05/dbas-are-not-the-enemy-but-they-too-need-watching/</link>
		<comments>http://www.slaviks-blog.com/2007/07/05/dbas-are-not-the-enemy-but-they-too-need-watching/#comments</comments>
		<pubDate>Thu, 05 Jul 2007 17:28:26 +0000</pubDate>
		<dc:creator>Slavik</dc:creator>
				<category><![CDATA[breach]]></category>
		<category><![CDATA[DBA]]></category>
		<category><![CDATA[insider threat]]></category>
		<category><![CDATA[monitoring]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[database security]]></category>
		<category><![CDATA[segregation_of_duties]]></category>

		<guid isPermaLink="false">http://www.slaviks-blog.com/2007/07/05/dbas-are-not-the-enemy-but-they-too-need-watching/</guid>
		<description><![CDATA[Back after a short and much needed hiatus, I came across this piece by security analyst Eric Ogren on Computerworld&#8217;s website. He discusses how DBAs have become public enemy number one because of compliance mandates to exercise segregation of duties, and how this has been blown out of proportion to other, greater risks. A few [...]]]></description>
		<wfw:commentRss>http://www.slaviks-blog.com/2007/07/05/dbas-are-not-the-enemy-but-they-too-need-watching/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
	</channel>
</rss>

<!-- Dynamic Page Served (once) in 0.442 seconds -->

