<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://msmvps.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Microsoft Best Practices for preventing SQL Injection Attacks</title><link>http://msmvps.com/blogs/harrywaldron/archive/2008/05/31/microsoft-best-practices-for-preventing-sql-injection-attacks.aspx</link><description>Microsoft has recently published a series of best practices to help developers build SQL code that is not susceptible to SQL injection attacks . SQL injection attacks occur in applications that are poorly programmed . They are not a result of failures</description><dc:language>en</dc:language><generator>CommunityServer 2008.5 SP2 (Build: 40407.4157)</generator><item><title>re: Microsoft Best Practices for preventing SQL Injection Attacks</title><link>http://msmvps.com/blogs/harrywaldron/archive/2008/05/31/microsoft-best-practices-for-preventing-sql-injection-attacks.aspx#1642959</link><pubDate>Fri, 01 Aug 2008 11:34:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1642959</guid><dc:creator>turkey</dc:creator><description>&lt;p&gt;thanks you .. perfect docs &lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1642959" width="1" height="1"&gt;</description></item><item><title>URL Scan 3.0 Beta - New version helps detect SQL Injection Attacks</title><link>http://msmvps.com/blogs/harrywaldron/archive/2008/05/31/microsoft-best-practices-for-preventing-sql-injection-attacks.aspx#1638368</link><pubDate>Fri, 27 Jun 2008 12:36:52 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1638368</guid><dc:creator>Harry Waldron - My IT Forums Blog </dc:creator><description>&lt;p&gt;Microsoft has just enhanced a key IIS based security tool in response to the new wave of automated SQL&lt;/p&gt;
&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1638368" width="1" height="1"&gt;</description></item><item><title>URL Scan 3.0 Beta - New version helps detect SQL Injection Attacks</title><link>http://msmvps.com/blogs/harrywaldron/archive/2008/05/31/microsoft-best-practices-for-preventing-sql-injection-attacks.aspx#1638364</link><pubDate>Fri, 27 Jun 2008 12:35:51 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1638364</guid><dc:creator>Harry Waldron - Microsoft MVP Blog</dc:creator><description>&lt;p&gt;Microsoft has just enhanced a key IIS based security tool in response to the new wave of automated SQL&lt;/p&gt;
&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1638364" width="1" height="1"&gt;</description></item><item><title>URL Scan 3.0 Beta - New version helps detect SQL Injection Attacks</title><link>http://msmvps.com/blogs/harrywaldron/archive/2008/05/31/microsoft-best-practices-for-preventing-sql-injection-attacks.aspx#1638360</link><pubDate>Fri, 27 Jun 2008 12:35:31 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1638360</guid><dc:creator>Harry Waldron - My IT Forums Blog </dc:creator><description>&lt;p&gt;URL Scan 3.0 Beta - New version helps detect SQL Injection Attacks Microsoft has just enhanced a key&lt;/p&gt;
&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1638360" width="1" height="1"&gt;</description></item><item><title>re: Microsoft Best Practices for preventing SQL Injection Attacks</title><link>http://msmvps.com/blogs/harrywaldron/archive/2008/05/31/microsoft-best-practices-for-preventing-sql-injection-attacks.aspx#1637486</link><pubDate>Wed, 25 Jun 2008 09:34:58 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1637486</guid><dc:creator>Rovastar</dc:creator><description>&lt;p&gt;A great selection of links but also check out.&lt;/p&gt;
&lt;p&gt;which gives you more of a hackers prospective:&lt;/p&gt;
&lt;p&gt;&lt;a rel="nofollow" target="_new" href="http://ferruh.mavituna.com/sql-injection-cheatsheet-oku/"&gt;ferruh.mavituna.com/sql-injection-cheatsheet-oku&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a rel="nofollow" target="_new" href="http://ha.ckers.org/sqlinjection/"&gt;ha.ckers.org/sqlinjection&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;so you understanding about the sort of things they do. &lt;/p&gt;
&lt;p&gt;You will also get a greater understanding of the differences in styles that hackers user for different databases (mysql, oracle, etc). although some commands are generic others can be tailored to attack the database platform.&lt;/p&gt;
&lt;p&gt;(search for &amp;#39;SQL injection cheat sheet&amp;#39; for more example of these)&lt;/p&gt;
&lt;p&gt;Although SQL injection problems are foremost developers issues hosting admin need to be aware for IIS check out the different filters like urlscan 3:&lt;/p&gt;
&lt;p&gt;&lt;a rel="nofollow" target="_new" href="http://blogs.technet.com/swi/archive/2008/06/24/new-tools-to-block-and-eradicate-sql-injection.aspx"&gt;blogs.technet.com/.../new-tools-to-block-and-eradicate-sql-injection.aspx&lt;/a&gt;&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1637486" width="1" height="1"&gt;</description></item><item><title>UrlScan v3.0 Beta Release</title><link>http://msmvps.com/blogs/harrywaldron/archive/2008/05/31/microsoft-best-practices-for-preventing-sql-injection-attacks.aspx#1637471</link><pubDate>Wed, 25 Jun 2008 08:31:38 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1637471</guid><dc:creator>iis</dc:creator><description>&lt;p&gt;The IIS team has some street smarts when it comes to security. We learned quite a few lessons the hard&lt;/p&gt;
&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1637471" width="1" height="1"&gt;</description></item><item><title>UrlScan v3.0 Beta Release</title><link>http://msmvps.com/blogs/harrywaldron/archive/2008/05/31/microsoft-best-practices-for-preventing-sql-injection-attacks.aspx#1637313</link><pubDate>Tue, 24 Jun 2008 20:29:21 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1637313</guid><dc:creator>iis</dc:creator><description>&lt;p&gt;The IIS team has some street smarts when it comes to security. We learned quite a few lessons the hard&lt;/p&gt;
&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1637313" width="1" height="1"&gt;</description></item><item><title>UrlScan v3.0 Beta Release</title><link>http://msmvps.com/blogs/harrywaldron/archive/2008/05/31/microsoft-best-practices-for-preventing-sql-injection-attacks.aspx#1637304</link><pubDate>Tue, 24 Jun 2008 19:50:40 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1637304</guid><dc:creator>Wade Hilmo</dc:creator><description>&lt;p&gt;The IIS team has some street smarts when it comes to security. We learned quite a few lessons the hard&lt;/p&gt;
&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1637304" width="1" height="1"&gt;</description></item><item><title>URL Scan 3.0 Beta - New version helps detect SQL Injection Attacks</title><link>http://msmvps.com/blogs/harrywaldron/archive/2008/05/31/microsoft-best-practices-for-preventing-sql-injection-attacks.aspx#1636579</link><pubDate>Sat, 21 Jun 2008 22:37:20 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1636579</guid><dc:creator>Harry Waldron - Microsoft MVP Blog</dc:creator><description>&lt;p&gt;Microsoft has just enhanced a key IIS based security tool in response to the new wave of automated SQL&lt;/p&gt;
&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1636579" width="1" height="1"&gt;</description></item><item><title>URL Scan 3.0 Beta - New version helps detect SQL Injection Attacks</title><link>http://msmvps.com/blogs/harrywaldron/archive/2008/05/31/microsoft-best-practices-for-preventing-sql-injection-attacks.aspx#1636576</link><pubDate>Sat, 21 Jun 2008 22:37:09 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1636576</guid><dc:creator>Harry Waldron - My IT Forums Blog </dc:creator><description>&lt;p&gt;Microsoft has just enhanced a key IIS based security tool in response to the new wave of automated SQL&lt;/p&gt;
&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1636576" width="1" height="1"&gt;</description></item><item><title>URL Scan 3.0 Beta - New version helps detect SQL Injection Attacks</title><link>http://msmvps.com/blogs/harrywaldron/archive/2008/05/31/microsoft-best-practices-for-preventing-sql-injection-attacks.aspx#1636570</link><pubDate>Sat, 21 Jun 2008 22:32:51 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1636570</guid><dc:creator>Harry Waldron - My IT Forums Blog </dc:creator><description>&lt;p&gt;Microsoft has just enhanced a key IIS based security tool in response to the new wave of automated SQL&lt;/p&gt;
&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1636570" width="1" height="1"&gt;</description></item><item><title>re: Microsoft Best Practices for preventing SQL Injection Attacks</title><link>http://msmvps.com/blogs/harrywaldron/archive/2008/05/31/microsoft-best-practices-for-preventing-sql-injection-attacks.aspx#1630382</link><pubDate>Mon, 02 Jun 2008 18:01:27 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1630382</guid><dc:creator>Nico</dc:creator><description>&lt;p&gt;Microsoft has even gone so far as creating video primers on Hello Secure World: www.microsoft.com/hellosecureworld7 &amp;nbsp;Worth noting, especially when you can&amp;#39;t ever be too careful these days.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1630382" width="1" height="1"&gt;</description></item><item><title>SQL injection information from Harry's blog</title><link>http://msmvps.com/blogs/harrywaldron/archive/2008/05/31/microsoft-best-practices-for-preventing-sql-injection-attacks.aspx#1629657</link><pubDate>Sat, 31 May 2008 16:17:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1629657</guid><dc:creator>MVPs</dc:creator><description>&lt;p&gt;While the default apps on a SBS 2003 (and upcoming SBS 2008) go through a SDL process so that I&amp;amp;#39;m&lt;/p&gt;
&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1629657" width="1" height="1"&gt;</description></item><item><title>SQL injection information from Harry's blog</title><link>http://msmvps.com/blogs/harrywaldron/archive/2008/05/31/microsoft-best-practices-for-preventing-sql-injection-attacks.aspx#1629644</link><pubDate>Sat, 31 May 2008 15:31:52 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1629644</guid><dc:creator>THE OFFICIAL BLOG OF THE SBS "DIVA"</dc:creator><description>&lt;p&gt;While the default apps on a SBS 2003 (and upcoming SBS 2008) go through a SDL process so that I&amp;amp;#39;m&lt;/p&gt;
&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1629644" width="1" height="1"&gt;</description></item></channel></rss>