<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Anatomy of a SQL Injection Incident</title><link>http://blogs.technet.com/neilcar/archive/2008/03/14/anatomy-of-a-sql-injection-incident.aspx</link><description>A number of people are reporting that 10K+ websites have been hacked via a SQL injection attack that injected a link to a malicious .js file into text fields in their database. For example, here's Avert Labs report . The reports that I've seen talk about</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>Mass SQL injection coming to an IIS + ASP server near you  . . . </title><link>http://blogs.technet.com/neilcar/archive/2008/03/14/anatomy-of-a-sql-injection-incident.aspx#3001982</link><pubDate>Sat, 15 Mar 2008 12:21:14 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3001982</guid><dc:creator>Robert Hensing's Blog</dc:creator><description>&lt;p&gt;My friend Neil has a pretty good post on the mass SQL injection stuff that was reported in the press&lt;/p&gt;
</description></item><item><title>re: Anatomy of a SQL Injection Incident</title><link>http://blogs.technet.com/neilcar/archive/2008/03/14/anatomy-of-a-sql-injection-incident.aspx#3009118</link><pubDate>Mon, 17 Mar 2008 14:07:17 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3009118</guid><dc:creator>anonymous</dc:creator><description>&lt;p&gt;This seems to repeat what the Internet Storm Center wrote on Januari 9th, and they linked it back to November 2007.&lt;/p&gt;</description></item><item><title>re: Anatomy of a SQL Injection Incident</title><link>http://blogs.technet.com/neilcar/archive/2008/03/14/anatomy-of-a-sql-injection-incident.aspx#3009482</link><pubDate>Mon, 17 Mar 2008 16:20:06 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3009482</guid><dc:creator>neilcar</dc:creator><description>&lt;p&gt;You're quite right -- this looks like another wave of the same attack. &amp;nbsp;I was aware of the earlier incidents but I hadn't seen any data from them.&lt;/p&gt;
</description></item><item><title>re: Anatomy of a SQL Injection Incident</title><link>http://blogs.technet.com/neilcar/archive/2008/03/14/anatomy-of-a-sql-injection-incident.aspx#3010086</link><pubDate>Mon, 17 Mar 2008 22:09:57 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3010086</guid><dc:creator>eponymous</dc:creator><description>&lt;p&gt;isn't this the same or similar attack vector to the RIAA hack a few months ago&lt;/p&gt;</description></item><item><title>Se prémunir des attaques de type "SQL Injection"...</title><link>http://blogs.technet.com/neilcar/archive/2008/03/14/anatomy-of-a-sql-injection-incident.aspx#3014909</link><pubDate>Wed, 19 Mar 2008 11:35:17 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3014909</guid><dc:creator>SQL Server, BizTalk Server, le 64 bits et au-delà !...</dc:creator><description>&lt;p&gt;Pour mieux comprendre les risques auxquels sont expos&amp;amp;#233;es vos bases de donn&amp;amp;#233;es, il est int&amp;amp;#233;ressant&lt;/p&gt;
</description></item><item><title>re: Anatomy of a SQL Injection Incident</title><link>http://blogs.technet.com/neilcar/archive/2008/03/14/anatomy-of-a-sql-injection-incident.aspx#3018368</link><pubDate>Sat, 22 Mar 2008 20:18:26 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3018368</guid><dc:creator>Michael Doe</dc:creator><description>&lt;p&gt;Hi Neil,&lt;/p&gt;
&lt;p&gt;I work as System Engineer in a large ISP company and we are hosting a large number of legacy ASP applications which contain SQL Injection flaws. I have been using this tool when clients agree:&lt;/p&gt;
&lt;p&gt;&lt;a rel="nofollow" target="_new" href="http://www.codeplex.com/IIS6SQLInjection"&gt;http://www.codeplex.com/IIS6SQLInjection&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;So far the results have been very good and I have not had problems (except that I cannot install in 64 bit). Do you know something about this tool? Is there a way to make it work in 64 bit?&lt;/p&gt;
&lt;p&gt;Thanks,&lt;/p&gt;
&lt;p&gt;P.S.: I am not using my real name to avoid problem with my clients.&lt;/p&gt;</description></item><item><title>Anatomy of a SQL Injection Incident</title><link>http://blogs.technet.com/neilcar/archive/2008/03/14/anatomy-of-a-sql-injection-incident.aspx#3021164</link><pubDate>Wed, 26 Mar 2008 10:11:56 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3021164</guid><dc:creator>Microsoft Switzerland Security Blog</dc:creator><description>&lt;p&gt;Blog Posting from Neil Carpenter: &amp;quot;A number of people are reporting that 10K+ Web sites have been hacked&lt;/p&gt;
</description></item><item><title>Mass SQL Injection -- Get Used To It</title><link>http://blogs.technet.com/neilcar/archive/2008/03/14/anatomy-of-a-sql-injection-incident.aspx#3028909</link><pubDate>Fri, 04 Apr 2008 21:00:45 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3028909</guid><dc:creator>Neil Carpenter's Blog</dc:creator><description>&lt;p&gt;It looks like another wave of the mass SQL injection I talked about last month is going on.&amp;amp;#160; The&lt;/p&gt;
</description></item><item><title>SQLInjectionFinder</title><link>http://blogs.technet.com/neilcar/archive/2008/03/14/anatomy-of-a-sql-injection-incident.aspx#3061756</link><pubDate>Tue, 27 May 2008 20:51:27 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3061756</guid><dc:creator>Neil Carpenter's Blog</dc:creator><description>&lt;p&gt;My colleague Greg , who has forgotten more about command line scripting than I will ever know, put together&lt;/p&gt;
</description></item><item><title>SQL Injection General Guidance</title><link>http://blogs.technet.com/neilcar/archive/2008/03/14/anatomy-of-a-sql-injection-incident.aspx#3062049</link><pubDate>Wed, 28 May 2008 11:13:10 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3062049</guid><dc:creator>Microsoft Switzerland Security Blog</dc:creator><description>&lt;p&gt;There s a lot of noise arround currently ongoig SQL injection attacks and even if that is quite an &amp;quot;old&amp;quot;&lt;/p&gt;
</description></item><item><title>The latest SQL Injection Attacks</title><link>http://blogs.technet.com/neilcar/archive/2008/03/14/anatomy-of-a-sql-injection-incident.aspx#3063325</link><pubDate>Fri, 30 May 2008 10:41:22 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3063325</guid><dc:creator>Roger's Security Blog</dc:creator><description>&lt;p&gt;Well, there was quite some chatter over the last few weeks with regards to the massive defacements we&lt;/p&gt;
</description></item><item><title>Inyección SQL... esta bajo ataque?</title><link>http://blogs.technet.com/neilcar/archive/2008/03/14/anatomy-of-a-sql-injection-incident.aspx#3071786</link><pubDate>Mon, 16 Jun 2008 11:55:24 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3071786</guid><dc:creator>Todo es posible, nada es seguro</dc:creator><description>&lt;p&gt;Hay muchos sitios y blogs que hablan sobre el tema de inyecci&amp;#243;n SQL. Puede encontrar toda la informaci&amp;#243;n&lt;/p&gt;
</description></item><item><title>SQL Injection attacks</title><link>http://blogs.technet.com/neilcar/archive/2008/03/14/anatomy-of-a-sql-injection-incident.aspx#3077506</link><pubDate>Wed, 25 Jun 2008 03:17:56 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3077506</guid><dc:creator>Troubleshooting and Tips - Cindy Gross</dc:creator><description>&lt;p&gt;&amp;amp;lt;p&amp;amp;gt;This year SQL injection attacks are being stepped up and even automated against SQL Server. While SQL injection attacks can occur against any DBMS, my blog will only address SQL Server.&amp;amp;lt;/p ...&lt;/p&gt;
</description></item><item><title>SQL Injection Atacken</title><link>http://blogs.technet.com/neilcar/archive/2008/03/14/anatomy-of-a-sql-injection-incident.aspx#3077651</link><pubDate>Wed, 25 Jun 2008 09:03:07 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3077651</guid><dc:creator>Schweizer IT Professional und TechNet Blog</dc:creator><description>&lt;p&gt;Vielen von Ihnen ist es beretis bekannt, dass es seit einigen Monaten SQL injection Attacken gegen angreifbare&lt;/p&gt;
</description></item><item><title>Análisis de logs de IIS utilizando Log Parser </title><link>http://blogs.technet.com/neilcar/archive/2008/03/14/anatomy-of-a-sql-injection-incident.aspx#3233417</link><pubDate>Thu, 30 Apr 2009 15:48:18 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3233417</guid><dc:creator>Gabriel Carreras</dc:creator><description>&lt;p&gt;Log Parser es una herramienta que permite analizar gran cantidad de datos de forma muy eficiente utilizando&lt;/p&gt;
</description></item></channel></rss>