<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://msmvps.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"><channel><title>SQL injection information from Harry's blog</title><link>http://msmvps.com/blogs/bradley/archive/2008/05/31/sql-injection-information-from-harry-s-blog.aspx</link><description>While the default apps on a SBS 2003 (and upcoming SBS 2008) go through a SDL process so that I&amp;#39;m not concerned about SQL injection possibilities on my SBS box (nor do I have SharePoint exposed anyway) when you have third party and home grown apps</description><dc:language>en</dc:language><generator>CommunityServer 2008.5 SP2 (Build: 40407.4157)</generator><item><title>re: SQL injection information from Harry's blog</title><link>http://msmvps.com/blogs/bradley/archive/2008/05/31/sql-injection-information-from-harry-s-blog.aspx#1630377</link><pubDate>Mon, 02 Jun 2008 17:41:05 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1630377</guid><dc:creator>Nico</dc:creator><description>&lt;p&gt;A lot of the Microsoft best practices really are sound. &amp;nbsp;But if you want to go ahead and use a brute force tool to see if your system is easily hack-able, I hear good things about sqlninja. &amp;nbsp;In the end, though, it usually boils down to not concatenating SQL statements and also proper escaping of input fields.&lt;/p&gt;
&lt;p&gt;**************&lt;/p&gt;
&lt;p&gt;Nico del Castillo&lt;/p&gt;
&lt;p&gt;Microsoft Security Outreach Team&lt;/p&gt;
&lt;p&gt;www.microsoft.com/hellosecureworld7&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1630377" width="1" height="1"&gt;</description></item><item><title>Interesting Finds: June 1, 2008</title><link>http://msmvps.com/blogs/bradley/archive/2008/05/31/sql-injection-information-from-harry-s-blog.aspx#1630059</link><pubDate>Mon, 02 Jun 2008 00:59:42 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1630059</guid><dc:creator>Jason Haley</dc:creator><description>&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1630059" width="1" height="1"&gt;</description></item><item><title>re: SQL injection information from Harry's blog</title><link>http://msmvps.com/blogs/bradley/archive/2008/05/31/sql-injection-information-from-harry-s-blog.aspx#1629761</link><pubDate>Sat, 31 May 2008 23:30:09 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1629761</guid><dc:creator>harry  brelsford</dc:creator><description>&lt;p&gt;what...whats this....another harry?&lt;/p&gt;
&lt;p&gt;:)&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1629761" width="1" height="1"&gt;</description></item></channel></rss>