<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>SQL Injection – again?</title><link>http://blogs.technet.com/b/rhalbheer/archive/2008/12/22/sql-injection-again.aspx</link><description>This week I had – again – a longer mail thread on SQL Injection attacks. Probably it caught me at the wrong moment, as it was a very long week preparing for the IE Out of Band making sure everybody knows what they have to do. And then… 
 I was actually</description><dc:language>en-US</dc:language><generator>Telligent Evolution Platform Developer Build (Build: 5.6.50428.7875)</generator><item><title>re: SQL Injection – again?</title><link>http://blogs.technet.com/b/rhalbheer/archive/2008/12/22/sql-injection-again.aspx#3172167</link><pubDate>Mon, 22 Dec 2008 16:26:09 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3172167</guid><dc:creator>Paschal</dc:creator><description>&lt;p&gt;Hi Roger, now one thing to add. I said also that I wish Microsft realease a future version of SQL Server where all the dnagerous bits are locked by DEFAULT. A bit like Windows Server 2008 where it's up to the user to choose what he wants to open.&lt;/p&gt;
&lt;p&gt;Things like EXECUTE or SELECT on the Master table should be locked!&lt;/p&gt;
&lt;p&gt;Remember I am the only person availabel in my organization, and I am surely n ot the only one working like that. so my job consists of DBA, Programmer, IT, Firewall guru, etc...&lt;/p&gt;
&lt;p&gt;So it has been a a pretty tough ride recently with things that should not be there from the beginning.&lt;/p&gt;
&lt;p&gt;Another thing I didn't know about is the 'httponly' attribut in we configuration files to lock the cookies in read only mode.&lt;/p&gt;
&lt;p&gt;Web config files have a huge number of methods, parameters and attributes and it's very hard to know all of them. I am proud to say I learn every day, but the same than SQL if cookies can execute their code, they shouldn't be allowed to do that by DEFAULT.&lt;/p&gt;
&lt;p&gt;Thanks&lt;/p&gt;
&lt;p&gt;Paschal&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3172167" width="1" height="1"&gt;</description></item></channel></rss>