MySQL Security

MySQL Security News, Articles, and Blogs

Browse by Tag

blog blog archive categories code css database database security databases development exploit flat for webmasters mysql portal guitar injection internet javascript Links linux menu mysql MySQL Security mysql shell new news oracle password perl mysql php php mysql security programming rails really simple syndication registerwidget search security server software sql sql injection technology tools update users utf vulnerability web widgetinfo widgetmanager wordpress xml



Virtual Workshop MySQL

… Temporary Tables, Full Text Searches. Part 9 - Built-in Functions. Date Functions, Mathmatics Functions, String Functions. Part A - Quick Answers. Securing MySQL and using MySQL with MS Access. …

View original post here:
Virtual Workshop MySQL

, , , , , , ,
June 25th, 2008. Comment now »

06.07.2008

18 hours rollback due to SQL injection *MySQL remote disabled to prevent further SQL injection attempt *20m mesos will be added to everyone accounts on the next servercheck - 2X EXP, 2X DROP, 2X MESOS extend till June 15th …
dynamic web design http web server php programming webdynamic web design, http web server, php, programming, web

Read more from the original source:
06.07.2008

, , , ,
June 9th, 2008. Comment now »

New Exploit In WordPress

Login to your instance of MySQL: mysql -u -p -h; Find the active plugins registered in WordPress: select option_value from wp_options where option_name=’active_plugins’ Look for a plugin you don’t recognize: You should probably be …

Read more from the original source:
New Exploit In WordPress

, , , , , , , , , , , ,
June 7th, 2008. Comment now »

SQL Injection Paper

10.IDS Signature Evasion. 11.mySQL Input Validation Circumvention using Char(). 12.IDS Signature Evasion using comments. 13.Strings without quotes. SQL Injection Paper: liga al sitio original, liga al mirror en mi blog.
accepts automagic canonical configuration connections default leaves mysql rails thingsaccepts, automagic, canonical, configuration, connections, default, leaves, mysql, rails, things

See more here:
SQL Injection Paper

, , , , ,
May 15th, 2008. Comment now »

Firewall Script - do you need one?

I’ve been running websites on various servers for a long time and I can say that protecting them from various kinds of exploits has always kept me busy several weekends. Especially when it is someone who is using …

Go here to see the original:
Firewall Script - do you need one?

, , , ,

Database Security Functions

These two functions escape data for sql queries, and apply backticks to table/column names. They can be used in conjunction with the mysql functions for easy updating, insertion, etc. that I will be posting soon. DB Security Functions.
configuring datamal blog …

See the original post here:
Database Security Functions

, , , , , , , , , , ,
March 11th, 2008. Comment now »

Nice Exploit Code I Found in my Wordpress

Someone with more patience than myself will probably take the time to disassemble that. To find …

Here is the original post:
Nice Exploit Code I Found in my Wordpress

, , , , , , , ,
March 10th, 2008. Comment now »

Part 6. Introduction to Linux Command-Line Basics The (Web host sites)

Introduction to Linux Command-Line Basics The following parts of the manual are aimed at those wishing to better understand their Mandriva Linux system, and who want to exploit its huge capabilities. After reading them, we hope that you …
application blog archive davidge items mac mac articles macsysadmin net ssh tom tunnelingapplication, blog archive, davidge, items, mac, mac articles, macsysadmin net, ssh, tom, tunneling

Original post:
Part 6. Introduction to Linux Command-Line Basics The (Web host sites)

, , , , , , , , , ,
February 26th, 2008. Comment now »

MS.Services 1.1.0 published

A new executor is introduced; the “SQL Executor” which executes SQL statements, also handles injection attacks. “SQL …

Here is the original post:
MS.Services 1.1.0 published

, , , , , , , , , , , , ,
January 29th, 2008. Comment now »

How does simpleContact deal with spam?

This is a database security measure more than an anti-spam thing. In simple terms, if you don’t process submitted values for certain characters like ” then a hacker could submit SQL code through your form to either expose data in your …
exploit securityexploit security

Read more from the original source:
How does simpleContact deal with spam?

, , , , , , , , , , ,
January 24th, 2008. Comment now »

Protecting WordPress from SQL Injection Attacks

What he means is that in general WordPress does not sanitize MySQL queries. He recommends that WordPress provide “a proper set of SQL safe functions (ie $wpdb->escape_int and $wpdb->escape_str” and “use mysql_real_escape_string(), …
escalation http local php privilege tools vulnerabilities x org x serverescalation, http, local, php, privilege, tools, vulnerabilities, x org x server

Read the original:
Protecting WordPress from SQL Injection Attacks

, , , , , , , , , , , ,
January 23rd, 2008. Comment now »

yaSSL - Remote hacker automatic control

These vulnerabilities include allowing authentication bypass and arbitrary code execution. These vulnerabilities also affect other products, due to yaSSL being included in products such as MySQL. Exploit code samples have also been …
mysql iismysql iis

See more here:
yaSSL - Remote hacker automatic control

, , , , , , , , , , , , , ,
January 9th, 2008. Comment now »

Protect your application against SQL injections part 1

The problem of using ID’s is if they aren’t validated, bad guys and girls can spy, change or destroy your database by manipulating the SQL query. This attack is called SQL injection. An example to get the field “title” in the row with …
vulnerability securityvulnerability security

See the rest here:
Protect your application against SQL injections part 1

, , , , , , , , , ,
December 5th, 2007. Comment now »

Log Buffer #73: a Carnival of the Vanities for DBAs

Alexander Kornbrust of red database security reviews the ebook Practical Oracle Security and lists some potential problems and inaccuracies he found in the book. Yasin Baskan of Oracle Today, while upgrading to 10g, discovers that bind …
exploit mp3 port port 1025 port 1029 exploit sandisk sansa m240 tcp udp virus windows wormexploit, mp3, port, port 1025, port 1029 exploit, sandisk sansa m240, tcp, udp, virus, windows, worm

Go here to see the original:
Log Buffer #73: a Carnival of the Vanities for DBAs

, , , , , , , , , , , , , ,
November 30th, 2007. Comment now »

Funky google

He did it via some weaknesses in their Wordpress installation, upgrading himself from a plain “can post” user to an admnistrator of the blog using a zero-day (that is, previously unnoted) vulnerability, via SQL injection. …
follow irc links html java post thread toolfollow irc links, html, java, post, thread, tool

View original post here:
Funky google

, , , , , , ,
November 23rd, 2007. Comment now »


 Search Engine Submission   Reg2.us Domain Name Registration   Premium Domain Names


Virtual Machine Security | Online banking guide | assuring.us


Cheap Web Hosting