Sign in
Neil Carpenter's Blog
Forefront products, WSUS, Security Incident Response, and whatever else comes up.
Tags
Antigen
AntiVirus
Anti-Virus
ASP
asp.net
AV
Forefront
FSSMC
General
humor
Incident Response
iphone
Mobile
Networking
Pages
Security
SQL
Tool
Browse by Tags
TechNet Blogs
>
Neil Carpenter's Blog
>
All Tags
>
sql
Tagged Content List
Blog Post:
SQL Injection Hijinks
neilcar
or Why I Keep Harping On Blacklisting Summary: An incident reveals attempts to get around blacklisting by manipulating behavior in ASP, illustrating the weakness of blacklist approaches. A new version of UrlScan is shipping today with a change specifically to address this. Discussion:...
on
31 Oct 2008
Blog Post:
Input Validation Is Not The Answer
neilcar
I just sent a piece of e-mail to my team about input validation and SQL injection and it occurred to me that I've been meaning to get into this here, too: If you're trying to solve a SQL injection problem, input validation is NOT the answer! There, I've said it. I keep seeing blog posts, forum posts...
on
7 Aug 2008
Blog Post:
SQL Storm: Possible ASP.Net
neilcar
I’ve had an unconfirmed report that the SQL Storm attacks are now also affecting ASP.Net pages, specifically with a URL of http://www.chliyi.com/m.js (this appears to be offline currently but I wouldn't suggest browsing there...) being injected into those pages. My team hasn’t...
on
4 Jun 2008
Blog Post:
SQL Injection: Trends & Guidance
neilcar
I've been working with the SWI team to write a comprehensive overview of the SQL Storm attacks with guidance for IT administrators, developers, and end users. That article is posted at sql-injection-attack.aspx . For developers, specifically, Bala Neerumalla has written an excellent overview of...
on
30 May 2008
Blog Post:
SQLInjectionFinder
neilcar
My colleague Greg , who has forgotten more about command line scripting than I will ever know, put together a sample on CodePlex that automates finding SQL injection attacks from the ongoing mass SQL injection attack ("SQL Storm", as I saw it dubbed today). This is a fairly convenient...
on
27 May 2008
Blog Post:
SQL Injection Mitigation: Using Parameterized Queries part 2 (types and recordsets)
neilcar
(Part 1 is here ) Previously, I provided a simple example of using parameterized queries in classic ASP; however, that sample lacked a few things such as explicit typing for the parameters. It also created a read-only ADODB.RecordSet which, obviously, isn't one-size-fits-all. Typing In the last...
on
23 May 2008
Blog Post:
SQL Injection Mitigation: Using Parameterized Queries
neilcar
Michael Howard wrote an excellent article yesterday on how the SDL addresses SQL injection . He walks through three coding requirements/defenses: Use SQL Parameterized Queries Use Stored Procedures Use SQL Execute-only Permissions As Michael points out, only the first, parameterized queries...
on
21 May 2008
Blog Post:
SQL Injection -- A Comment
neilcar
Kumar comments here and I think he has some questions/concerns that are worth addressing. I'm going to add my own comments (and, please note, the comments I make here are my own and do not necessarily reflect Microsoft's corporate opinions). ----------------------------------------------------...
on
7 Apr 2008
Blog Post:
Mass SQL Injection -- Get Used To It
neilcar
It looks like another wave of the mass SQL injection I talked about last month is going on. The inserted link is different and, in the one specific incident I've seen, the source IP address is different; however, other than that, the attack looks to be identical. 2.1K websites so far, this month...
on
4 Apr 2008
Blog Post:
Anatomy of a SQL Injection Incident, Part 2: Meat
neilcar
Intro It would appear that the incident I wrote about yesterday is still ongoing. I've been using a search engine to query for the *.js file that's being injected and it looks something like this: Wednesday: 10K hits (This is Avert's number. I didn't look until Thu.) Thursday: 12.1K hits Friday: 12.9K...
on
15 Mar 2008
Blog Post:
Anatomy of a SQL Injection Incident
neilcar
A number of people are reporting that 10K+ websites have been hacked via a SQL injection attack that injected a link to a malicious .js file into text fields in their database. For example, here's Avert Labs report . The reports that I've seen talk about how the .js file tries to compromise clients that...
on
14 Mar 2008
Page 1 of 1 (11 items)