<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Musings on Database Security &#187; SQL injection</title>
	<atom:link href="http://www.slaviks-blog.com/category/sql-injection/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.slaviks-blog.com</link>
	<description>Slavik&#039;s Blog</description>
	<lastBuildDate>Wed, 07 Dec 2011 17:07:31 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>UKOUG 2011</title>
		<link>http://www.slaviks-blog.com/2011/12/07/ukoug-2011/</link>
		<comments>http://www.slaviks-blog.com/2011/12/07/ukoug-2011/#comments</comments>
		<pubDate>Wed, 07 Dec 2011 17:07:31 +0000</pubDate>
		<dc:creator>Slavik</dc:creator>
				<category><![CDATA[OUG]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[SQL injection]]></category>

		<guid isPermaLink="false">http://www.slaviks-blog.com/?p=327</guid>
		<description><![CDATA[Well, that was fun. I had a great time at UKOUG at Birmingham. Met friends, enjoyed the parties and gave a SQL Injection security presentation. All in all, I think it went well &#8211; no demos crashing, etc. It&#8217;s pretty much the same presentation I gave at in the hacking exposed series so you can download [...]]]></description>
		<wfw:commentRss>http://www.slaviks-blog.com/2011/12/07/ukoug-2011/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Hacking exposed presentation and source code</title>
		<link>http://www.slaviks-blog.com/2011/05/04/hacking-exposed-presentation-and-source-code/</link>
		<comments>http://www.slaviks-blog.com/2011/05/04/hacking-exposed-presentation-and-source-code/#comments</comments>
		<pubDate>Wed, 04 May 2011 22:17:28 +0000</pubDate>
		<dc:creator>Slavik</dc:creator>
				<category><![CDATA[Oracle]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[SQL injection]]></category>

		<guid isPermaLink="false">http://www.slaviks-blog.com/?p=313</guid>
		<description><![CDATA[Here is the presentation and demo application I&#8217;ve used for the hacking exposed webinar I did on April 14th. The download file includes an eclipse project and instructions under the &#8220;etc&#8221; folder. It also includes a few scripts I used for blind SQL injection and worm infection. Tell me what you think&#8230; HackingExposed]]></description>
		<wfw:commentRss>http://www.slaviks-blog.com/2011/05/04/hacking-exposed-presentation-and-source-code/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>LizaMoon Threat Brief</title>
		<link>http://www.slaviks-blog.com/2011/04/13/lizamoon-threat-brief/</link>
		<comments>http://www.slaviks-blog.com/2011/04/13/lizamoon-threat-brief/#comments</comments>
		<pubDate>Thu, 14 Apr 2011 03:01:09 +0000</pubDate>
		<dc:creator>Slavik</dc:creator>
				<category><![CDATA[breach]]></category>
		<category><![CDATA[SQL injection]]></category>

		<guid isPermaLink="false">http://www.slaviks-blog.com/?p=310</guid>
		<description><![CDATA[McAfee just posted a threat brief we created regarding the LizaMoon attack spreading through vulnerable web sites. Thanks to Vadim and our red team for providing the material and Andy for doing the proofing and adding his words of wisdom. As always, the simple way to solve SQL injection is to use bind variables. On another [...]]]></description>
		<wfw:commentRss>http://www.slaviks-blog.com/2011/04/13/lizamoon-threat-brief/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>MySQL.com Database Compromised By Blind SQL Injection</title>
		<link>http://www.slaviks-blog.com/2011/03/27/mysql-com-database-compromised-by-blind-sql-injection/</link>
		<comments>http://www.slaviks-blog.com/2011/03/27/mysql-com-database-compromised-by-blind-sql-injection/#comments</comments>
		<pubDate>Sun, 27 Mar 2011 22:53:19 +0000</pubDate>
		<dc:creator>Slavik</dc:creator>
				<category><![CDATA[breach]]></category>
		<category><![CDATA[SQL injection]]></category>

		<guid isPermaLink="false">http://www.slaviks-blog.com/?p=308</guid>
		<description><![CDATA[I guess this is somewhat ironical. At least it was nothing simple as in-band SQL Injection via errors or directly. It just goes to show you that any site can be vulnerable to attacks, even guys that write DB engines for a living. On the other hand, I&#8217;m sure that the sites were not created [...]]]></description>
		<wfw:commentRss>http://www.slaviks-blog.com/2011/03/27/mysql-com-database-compromised-by-blind-sql-injection/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>A nice blog post about SQL Injection</title>
		<link>http://www.slaviks-blog.com/2010/02/15/a-nice-blog-post-about-sql-injection/</link>
		<comments>http://www.slaviks-blog.com/2010/02/15/a-nice-blog-post-about-sql-injection/#comments</comments>
		<pubDate>Mon, 15 Feb 2010 21:30:49 +0000</pubDate>
		<dc:creator>Slavik</dc:creator>
				<category><![CDATA[Oracle]]></category>
		<category><![CDATA[SQL injection]]></category>

		<guid isPermaLink="false">http://www.slaviks-blog.com/?p=229</guid>
		<description><![CDATA[A really well written blog post from Mike Smithers about the need to validate data from all sources &#8211; also coming from the database. Good one&#8230;]]></description>
		<wfw:commentRss>http://www.slaviks-blog.com/2010/02/15/a-nice-blog-post-about-sql-injection/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Tapulous MySQL Error and SQL Injection vulnerability</title>
		<link>http://www.slaviks-blog.com/2010/01/06/tapulous-mysql-error-and-sql-injection-vulnerability/</link>
		<comments>http://www.slaviks-blog.com/2010/01/06/tapulous-mysql-error-and-sql-injection-vulnerability/#comments</comments>
		<pubDate>Thu, 07 Jan 2010 06:36:08 +0000</pubDate>
		<dc:creator>Slavik</dc:creator>
				<category><![CDATA[MySQL]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[SQL injection]]></category>

		<guid isPermaLink="false">http://www.slaviks-blog.com/?p=205</guid>
		<description><![CDATA[I&#8217;ve talked about displaying errors from the database on the user screen a while ago. In my opinion, this is definitely a big no-no and a security problem just waiting to happen. As some of you know, I have an iPhone (and I like it a lot, but that&#8217;s another story). I&#8217;ve installed a nice [...]]]></description>
		<wfw:commentRss>http://www.slaviks-blog.com/2010/01/06/tapulous-mysql-error-and-sql-injection-vulnerability/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

<!-- Dynamic Page Served (once) in 0.504 seconds -->

