<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>SQL Injection Mitigation: Using Parameterized Queries</title><link>http://blogs.technet.com/neilcar/archive/2008/05/21/sql-injection-mitigation-using-parameterized-queries.aspx</link><description>Michael Howard wrote an excellent article yesterday on how the SDL addresses SQL injection . He walks through three coding requirements/defenses: Use SQL Parameterized Queries Use Stored Procedures Use SQL Execute-only Permissions As Michael points out,</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>SQL Injection 相关文档</title><link>http://blogs.technet.com/neilcar/archive/2008/05/21/sql-injection-mitigation-using-parameterized-queries.aspx#3058663</link><pubDate>Wed, 21 May 2008 18:52:18 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3058663</guid><dc:creator>大牛蛙 da'niel'wa@secure</dc:creator><description>&lt;p&gt;攻击依然持续不断。Michael和Neil添加了关于这方面的blog，大家可以看看: Michael: How the SDL Addresses SQL injection Neil: SQL Injection&lt;/p&gt;</description></item><item><title>Filtering SQL injection from Classic ASP</title><link>http://blogs.technet.com/neilcar/archive/2008/05/21/sql-injection-mitigation-using-parameterized-queries.aspx#3059015</link><pubDate>Thu, 22 May 2008 07:20:48 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3059015</guid><dc:creator>Nazim's IIS Security Blog</dc:creator><description>&lt;p&gt;SQL injection may be over a decade old, but even the best of us need a reminder once in a while. You&lt;/p&gt;
</description></item><item><title>SQL Injection General Guidance</title><link>http://blogs.technet.com/neilcar/archive/2008/05/21/sql-injection-mitigation-using-parameterized-queries.aspx#3062047</link><pubDate>Wed, 28 May 2008 11:12:45 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3062047</guid><dc:creator>Microsoft Switzerland Security Blog</dc:creator><description>&lt;p&gt;There s a lot of noise arround currently ongoig SQL injection attacks and even if that is quite an &amp;quot;old&amp;quot;&lt;/p&gt;
</description></item><item><title>The latest SQL Injection Attacks</title><link>http://blogs.technet.com/neilcar/archive/2008/05/21/sql-injection-mitigation-using-parameterized-queries.aspx#3063324</link><pubDate>Fri, 30 May 2008 10:41:21 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3063324</guid><dc:creator>Roger's Security Blog</dc:creator><description>&lt;p&gt;Well, there was quite some chatter over the last few weeks with regards to the massive defacements we&lt;/p&gt;
</description></item><item><title>SQL Injection</title><link>http://blogs.technet.com/neilcar/archive/2008/05/21/sql-injection-mitigation-using-parameterized-queries.aspx#3063391</link><pubDate>Fri, 30 May 2008 11:47:22 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3063391</guid><dc:creator>Om Windows Vista og annen teknisk moro</dc:creator><description>&lt;p&gt;Trodde egentlig dette emnet var dekket godt nok opp i gjennom, men den siste ukas begivenheter viser&lt;/p&gt;
</description></item><item><title>http://blogs.technet.com/swi/archive/2008/05/29/sql-injection-attack.aspx</title><link>http://blogs.technet.com/neilcar/archive/2008/05/21/sql-injection-mitigation-using-parameterized-queries.aspx#3063718</link><pubDate>Fri, 30 May 2008 21:12:46 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3063718</guid><dc:creator>TrackBack</dc:creator><description /></item><item><title>Microsoft Best Practices for preventing SQL Injection Attacks</title><link>http://blogs.technet.com/neilcar/archive/2008/05/21/sql-injection-mitigation-using-parameterized-queries.aspx#3064225</link><pubDate>Sat, 31 May 2008 15:58:46 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3064225</guid><dc:creator>Harry Waldron - Microsoft MVP Blog</dc:creator><description>&lt;p&gt;Microsoft has recently published a series of best practices to help developers build SQL code that is&lt;/p&gt;
</description></item><item><title>SQL injection information from Harry's blog</title><link>http://blogs.technet.com/neilcar/archive/2008/05/21/sql-injection-mitigation-using-parameterized-queries.aspx#3064266</link><pubDate>Sat, 31 May 2008 18:31:57 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3064266</guid><dc:creator>THE OFFICIAL BLOG OF THE SBS "DIVA"</dc:creator><description>&lt;p&gt;While the default apps on a SBS 2003 (and upcoming SBS 2008) go through a SDL process so that I&amp;amp;#39;m&lt;/p&gt;
</description></item><item><title>SQL injection information from Harry's blog</title><link>http://blogs.technet.com/neilcar/archive/2008/05/21/sql-injection-mitigation-using-parameterized-queries.aspx#3064273</link><pubDate>Sat, 31 May 2008 19:17:05 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3064273</guid><dc:creator>MVPs</dc:creator><description>&lt;p&gt;While the default apps on a SBS 2003 (and upcoming SBS 2008) go through a SDL process so that I&amp;amp;#39;m&lt;/p&gt;
</description></item><item><title>Microsoft Best Practices for preventing SQL Injection Attacks</title><link>http://blogs.technet.com/neilcar/archive/2008/05/21/sql-injection-mitigation-using-parameterized-queries.aspx#3064417</link><pubDate>Sun, 01 Jun 2008 06:42:42 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3064417</guid><dc:creator>Harry Waldron - My IT Forums Blog </dc:creator><description>&lt;p&gt;Microsoft has recently published a series of best practices to help developers build SQL code that is&lt;/p&gt;
</description></item><item><title>SQL注入攻击-来自微软安全博客的建议</title><link>http://blogs.technet.com/neilcar/archive/2008/05/21/sql-injection-mitigation-using-parameterized-queries.aspx#3066257</link><pubDate>Thu, 05 Jun 2008 06:09:02 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3066257</guid><dc:creator>Applelure</dc:creator><description>&lt;p&gt;本文翻译自微软博客上刊载的相关文章，英文原文版权归原作者所有，特此声明。（特别感谢NeilCarpenter对本文写作提供的帮助）&lt;/p&gt;
&lt;p&gt;近期趋势&lt;/p&gt;
&lt;p&gt;从去年下半年开始，很多网站被损害，他们在用于生成动...&lt;/p&gt;
</description></item><item><title>Input Validation Is Not The Answer</title><link>http://blogs.technet.com/neilcar/archive/2008/05/21/sql-injection-mitigation-using-parameterized-queries.aspx#3102266</link><pubDate>Thu, 07 Aug 2008 21:27:12 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3102266</guid><dc:creator>Neil Carpenter's Blog</dc:creator><description>&lt;p&gt;I just sent a piece of e-mail to my team about input validation and SQL injection and it occurred to&lt;/p&gt;
</description></item><item><title>SQL Injection, the threat beyond the perimeter</title><link>http://blogs.technet.com/neilcar/archive/2008/05/21/sql-injection-mitigation-using-parameterized-queries.aspx#3119896</link><pubDate>Fri, 05 Sep 2008 18:03:08 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3119896</guid><dc:creator>Yuri Diogenes's Blog</dc:creator><description>&lt;p&gt;It is very common to us from CSS Security receive calls about SQL Injection and sometimes customers prefers&lt;/p&gt;
</description></item><item><title>How IAG 2007 Can Mitigate SQL Injection Attacks – Demo Scenario</title><link>http://blogs.technet.com/neilcar/archive/2008/05/21/sql-injection-mitigation-using-parameterized-queries.aspx#3126195</link><pubDate>Fri, 19 Sep 2008 21:52:16 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3126195</guid><dc:creator>Intelligent Application Gateway Product Team Blog</dc:creator><description>&lt;p&gt;1. Introduction SQL Injection is a potential threat to any web application that has a SQL based database&lt;/p&gt;
</description></item><item><title>SQL Injection Hijinks</title><link>http://blogs.technet.com/neilcar/archive/2008/05/21/sql-injection-mitigation-using-parameterized-queries.aspx#3145517</link><pubDate>Sat, 01 Nov 2008 03:02:28 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3145517</guid><dc:creator>Neil Carpenter's Blog</dc:creator><description>&lt;p&gt;or Why I Keep Harping On Blacklisting Summary: An incident reveals attempts to get around blacklisting&lt;/p&gt;
</description></item></channel></rss>