<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.2.3" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>
<channel>
	<title>Comments on: Mass Attack FAQ</title>
	<link>http://hackademix.net/2008/04/26/mass-attack-faq/</link>
	<description>Giorgio Maone's answers to the Web, the Universe, and Everything</description>
	<pubDate>Tue, 07 Feb 2012 09:17:54 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.2.3</generator>

	<item>
		<title>By: Alliance Technology Partners – Veeam, Acunetix, HP » What is SQL Injection? Learn about Acunetix Web Vulnerability Scanner.</title>
		<link>http://hackademix.net/2008/04/26/mass-attack-faq/#comment-22959</link>
		<dc:creator>Alliance Technology Partners – Veeam, Acunetix, HP » What is SQL Injection? Learn about Acunetix Web Vulnerability Scanner.</dc:creator>
		<pubDate>Tue, 04 May 2010 13:31:05 +0000</pubDate>
		<guid>http://hackademix.net/2008/04/26/mass-attack-faq/#comment-22959</guid>
		<description>[...] Giorgio Maone (April 26, 2008). “Mass Attack FAQ”. [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] Giorgio Maone (April 26, 2008). “Mass Attack FAQ”. [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: SQL injection and Amazing Hacking Issue &#124; Master4Life</title>
		<link>http://hackademix.net/2008/04/26/mass-attack-faq/#comment-22601</link>
		<dc:creator>SQL injection and Amazing Hacking Issue &#124; Master4Life</dc:creator>
		<pubDate>Thu, 11 Mar 2010 03:00:15 +0000</pubDate>
		<guid>http://hackademix.net/2008/04/26/mass-attack-faq/#comment-22601</guid>
		<description>[...] injection http://hackademix.net/2008/04/26/mass-attack-faq/ http://blogs.iis.net/bills/archi … [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] injection <a href="http://hackademix.net/2008/04/26/mass-attack-faq/" rel="nofollow">http://hackademix.net/2008/04/26/mass-attack-faq/</a> <a href="http://blogs.iis.net/bills/archi" rel="nofollow">http://blogs.iis.net/bills/archi</a> … [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: BrianLang.ca » Blog Archive » links for 2009-08-14</title>
		<link>http://hackademix.net/2008/04/26/mass-attack-faq/#comment-14201</link>
		<dc:creator>BrianLang.ca » Blog Archive » links for 2009-08-14</dc:creator>
		<pubDate>Fri, 14 Aug 2009 07:02:55 +0000</pubDate>
		<guid>http://hackademix.net/2008/04/26/mass-attack-faq/#comment-14201</guid>
		<description>[...] hackademix.net » Mass Attack FAQ (tags: sql injection) [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] hackademix.net » Mass Attack FAQ (tags: sql injection) [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: WOOOPS Microsoft « 1984</title>
		<link>http://hackademix.net/2008/04/26/mass-attack-faq/#comment-10163</link>
		<dc:creator>WOOOPS Microsoft « 1984</dc:creator>
		<pubDate>Tue, 23 Dec 2008 05:17:06 +0000</pubDate>
		<guid>http://hackademix.net/2008/04/26/mass-attack-faq/#comment-10163</guid>
		<description>[...] automated attack takes advantage to the fact that Microsoft’s IIS servers allow generic commands that don’t require specific table-level arguments. However, the vulnerability is the result of [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] automated attack takes advantage to the fact that Microsoft’s IIS servers allow generic commands that don’t require specific table-level arguments. However, the vulnerability is the result of [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: hackademix.net » More Bad News for IE Users</title>
		<link>http://hackademix.net/2008/04/26/mass-attack-faq/#comment-10050</link>
		<dc:creator>hackademix.net » More Bad News for IE Users</dc:creator>
		<pubDate>Fri, 12 Dec 2008 17:08:26 +0000</pubDate>
		<guid>http://hackademix.net/2008/04/26/mass-attack-faq/#comment-10050</guid>
		<description>[...] Latest updates from Microsoft: the critical remote execution bug which we already talked about affects all IE versions (included IE8 beta) on every supported Windows operating system. The bulletin also corrects some early assumptions about this unpatched vulnerability, which is being actively exploited in the wild from apparently legitimate sites infected through automated SQL injections: [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] Latest updates from Microsoft: the critical remote execution bug which we already talked about affects all IE versions (included IE8 beta) on every supported Windows operating system. The bulletin also corrects some early assumptions about this unpatched vulnerability, which is being actively exploited in the wild from apparently legitimate sites infected through automated SQL injections: [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: hackademix.net » Escape From IE, Now!</title>
		<link>http://hackademix.net/2008/04/26/mass-attack-faq/#comment-10039</link>
		<dc:creator>hackademix.net » Escape From IE, Now!</dc:creator>
		<pubDate>Thu, 11 Dec 2008 11:32:09 +0000</pubDate>
		<guid>http://hackademix.net/2008/04/26/mass-attack-faq/#comment-10039</guid>
		<description>[...] exploits for the latter vulnerability are being massively infiltrated inside legit web sites using automated SQL injection attacks. Give yourself a Christmas gift: if there’s a best moment for switching to a safe or to a [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] exploits for the latter vulnerability are being massively infiltrated inside legit web sites using automated SQL injection attacks. Give yourself a Christmas gift: if there’s a best moment for switching to a safe or to a [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: terrina</title>
		<link>http://hackademix.net/2008/04/26/mass-attack-faq/#comment-9909</link>
		<dc:creator>terrina</dc:creator>
		<pubDate>Mon, 24 Nov 2008 07:07:31 +0000</pubDate>
		<guid>http://hackademix.net/2008/04/26/mass-attack-faq/#comment-9909</guid>
		<description>Someone may have done this before (we cannot know, anyway), but this time we’ve got the smoking gun of an automated tool built around it and probably sold in the underground, hence the impressive arding the SQL statements accepted verbatim as a query parameters by design, I’ve seen them too with horror. As you probably know, they even caused high profile data leaks recently.
Every time a project have impossible deadlines to be met with ridiculous budgets (i.e. almost always), some underpaid monkey coder “invents” some shortcut like that and — who knows? — they may even praise it as smart “code reuse”.
See the XSS equivalent, with CNN and CeBIT “vulnerable by design”.
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
terrina
&lt;a href="http://www.widecircles.com" rel="nofollow"&gt;Social Bookmarking&lt;/a&gt;</description>
		<content:encoded><![CDATA[<p>Someone may have done this before (we cannot know, anyway), but this time we’ve got the smoking gun of an automated tool built around it and probably sold in the underground, hence the impressive arding the SQL statements accepted verbatim as a query parameters by design, I’ve seen them too with horror. As you probably know, they even caused high profile data leaks recently.<br />
Every time a project have impossible deadlines to be met with ridiculous budgets (i.e. almost always), some underpaid monkey coder “invents” some shortcut like that and — who knows? — they may even praise it as smart “code reuse”.<br />
See the XSS equivalent, with CNN and CeBIT “vulnerable by design”.<br />
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~<br />
terrina<br />
<a href="http://www.widecircles.com" rel="nofollow">Social Bookmarking</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Zero in a bit » Distributing Malware Through Trusted Websites</title>
		<link>http://hackademix.net/2008/04/26/mass-attack-faq/#comment-9275</link>
		<dc:creator>Zero in a bit » Distributing Malware Through Trusted Websites</dc:creator>
		<pubDate>Mon, 15 Sep 2008 20:14:06 +0000</pubDate>
		<guid>http://hackademix.net/2008/04/26/mass-attack-faq/#comment-9275</guid>
		<description>[...] infect trusted sites like BusinessWeek? This is becoming something of a trend, as evidenced by the mass SQL Injection attacks from a few months [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] infect trusted sites like BusinessWeek? This is becoming something of a trend, as evidenced by the mass SQL Injection attacks from a few months [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: hackademix.net » Heart Touching Thingies</title>
		<link>http://hackademix.net/2008/04/26/mass-attack-faq/#comment-8946</link>
		<dc:creator>hackademix.net » Heart Touching Thingies</dc:creator>
		<pubDate>Sat, 09 Aug 2008 09:21:54 +0000</pubDate>
		<guid>http://hackademix.net/2008/04/26/mass-attack-faq/#comment-8946</guid>
		<description>[...] page. Our webpage had a link on it to sdo.1000mg.cn. I started looking and found that we had the SQL injection attack currently featured at [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] page. Our webpage had a link on it to sdo.1000mg.cn. I started looking and found that we had the SQL injection attack currently featured at [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Microsoft issues advice on SQL injection attacks « in.spite</title>
		<link>http://hackademix.net/2008/04/26/mass-attack-faq/#comment-8848</link>
		<dc:creator>Microsoft issues advice on SQL injection attacks « in.spite</dc:creator>
		<pubDate>Wed, 30 Jul 2008 13:34:17 +0000</pubDate>
		<guid>http://hackademix.net/2008/04/26/mass-attack-faq/#comment-8848</guid>
		<description>[...] Mass attack FAQ from hackademix.net (VERY handy if you do not have a clean backed up version of your database) and U.N.Patched (the story of how the UN got their site attacked) [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] Mass attack FAQ from hackademix.net (VERY handy if you do not have a clean backed up version of your database) and U.N.Patched (the story of how the UN got their site attacked) [&#8230;]</p>
]]></content:encoded>
	</item>
</channel>
</rss>

