Welcome to TechNet Blogs Sign in | Join | Help

Browse by Tags

Err

I might be the last person to know this but one of my favorite internal Microsoft tools is now external. Err.exe is a command-line tool that looks up error codes and spits out possible matches from various header files. This is invaluable when you're
Posted by neilcar | 0 Comments
Filed under:

Input Validation Is Not The Answer

I just sent a piece of e-mail to my team about input validation and SQL injection and it occurred to me that I've been meaning to get into this here, too: If you're trying to solve a SQL injection problem, input validation is NOT the answer! There, I've
Posted by neilcar | 1 Comments
Filed under: ,

Forefront Server Security Management Console, Templates, and Revisions

Sometimes, working in support, you come across a best practice or a bit of knowledge that is well-known to some people...but that bit of knowledge has never actually been documented. Today was one of those days. While working in an environment with multiple
Posted by neilcar | 0 Comments
Filed under: , ,

Does This Make Me A Fanboy?

I upgraded my iPhone to the 2.0 firmware today and I've been playing with the app store all day. It's pretty neat stuff. Since I'm on a conference call tonight but I'm only here in an advisory/observational way, I put my phone on mute and kept playing
Posted by neilcar | 0 Comments
Filed under: ,

Antigen 9.1 Hotfix Rollup 3 and Performance Monitor

While investigating an issue where mail was queuing in the Exchange Information Store, we discovered an issue that affects customers running Antigen 9.1 Hotfix Rollup 3 when there are performance monitoring tools such as Perfmon, Perfwiz, and the MOM
Posted by neilcar | 0 Comments
Filed under: ,

SQL Storm: Possible ASP.Net

I’ve had an unconfirmed report that the SQL Storm attacks are now also affecting ASP.Net pages, specifically with a  URL of http://www.chliyi.com/m.js (this appears to be offline currently but I wouldn't suggest browsing there...) being injected
Posted by neilcar | 0 Comments
Filed under: , ,

SQL Injection: Trends & Guidance

I've been working with the SWI team to write a comprehensive overview of the SQL Storm attacks with guidance for IT administrators, developers, and end users.  That article is posted at sql-injection-attack.aspx . For developers, specifically, Bala
Posted by neilcar | 0 Comments
Filed under: , ,

SQLInjectionFinder

My colleague Greg , who has forgotten more about command line scripting than I will ever know, put together a sample on CodePlex that automates finding SQL injection attacks from the ongoing mass SQL injection attack ("SQL Storm", as I saw it
Posted by neilcar | 0 Comments

SQL Injection Mitigation: Using Parameterized Queries part 2 (types and recordsets)

(Part 1 is here ) Previously, I provided a simple example of using parameterized queries in classic ASP; however, that sample lacked a few things such as explicit typing for the parameters. It also created a read-only ADODB.RecordSet which, obviously,
Posted by neilcar | 7 Comments
Filed under: , ,

SQL Injection Mitigation: Using Parameterized Queries

Michael Howard wrote an excellent article yesterday on how the SDL addresses SQL injection . He walks through three coding requirements/defenses: Use SQL Parameterized Queries Use Stored Procedures Use SQL Execute-only Permissions As Michael points out,
Posted by neilcar | 12 Comments
Filed under: , ,

SQL Injection -- A Comment

Kumar comments here and I think he has some questions/concerns that are worth addressing.  I'm going to add my own comments (and, please note, the comments I make here are my own and do not necessarily reflect Microsoft's corporate opinions). ---------------------------------------------------------------------------------------
Posted by neilcar | 1 Comments

Mass SQL Injection -- Get Used To It

It looks like another wave of the mass SQL injection I talked about last month is going on.  The inserted link is different and, in the one specific incident I've seen, the source IP address is different; however, other than that, the attack looks
Posted by neilcar | 0 Comments

Good News

The good news is that, whatever else might happen, these guys won't get pwned by SQL injection.   (Via GrumpySecurityGuy .)
Posted by neilcar | 0 Comments
Filed under: ,

Anatomy of a SQL Injection Incident, Part 2: Meat

Intro It would appear that the incident I wrote about yesterday is still ongoing. I've been using a search engine to query for the *.js file that's being injected and it looks something like this: Wednesday: 10K hits (This is Avert's number. I didn't
Posted by neilcar | 14 Comments

Anatomy of a SQL Injection Incident

A number of people are reporting that 10K+ websites have been hacked via a SQL injection attack that injected a link to a malicious .js file into text fields in their database. For example, here's Avert Labs report . The reports that I've seen talk about
Posted by neilcar | 14 Comments
More Posts Next page »
 
Page view tracker