<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://msmvps.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>How to Detect, Identify and Defend against SQL Injection?</title><link>http://msmvps.com/blogs/bernard/archive/2008/06/25/how-to-detect-identify-and-defend-against-sql-injection.aspx</link><description>SQL Injection has been around for many years :) and you probably get over 3 million results when you googled the term. so why is it so HOT now? Well, not so long ago some folks (don&amp;#39;t ask me who!!, go read) were claiming that it was an IIS exploit</description><dc:language>en</dc:language><generator>CommunityServer 2008.5 SP2 (Build: 40407.4157)</generator><item><title>re: How to Detect, Identify and Defend against SQL Injection?</title><link>http://msmvps.com/blogs/bernard/archive/2008/06/25/how-to-detect-identify-and-defend-against-sql-injection.aspx#1639058</link><pubDate>Wed, 02 Jul 2008 02:00:41 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1639058</guid><dc:creator>qbernard</dc:creator><description>&lt;p&gt;For the urlscan the the hp scrawlr, both are done via http request and no source code is needed. Again, scarwlr is use to detect, while urlscan is defend, both didn&amp;#39;t fix the issue at root.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1639058" width="1" height="1"&gt;</description></item><item><title>re: How to Detect, Identify and Defend against SQL Injection?</title><link>http://msmvps.com/blogs/bernard/archive/2008/06/25/how-to-detect-identify-and-defend-against-sql-injection.aspx#1638835</link><pubDate>Mon, 30 Jun 2008 03:21:02 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1638835</guid><dc:creator>walter</dc:creator><description>&lt;p&gt;Unfortunately the URLSCan and Scrawlr only able to detect through SQL Injection that is through querystring. &lt;/p&gt;
&lt;p&gt;correct?&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1638835" width="1" height="1"&gt;</description></item></channel></rss>