Browse by Tag
blog blog archive categories code css database database security databases development exploit flat guitar hosting injection internet javascript Links linux menu mysql MySQL Security mysql shell new news oracle password php php mysql security programming rails really simple syndication registerwidget search security seo server software sql sql injection table technology update users utf vulnerability web widgetinfo widgetmanager wordpress xml0×000000 # The Hacker Webzine : Massive SQL Injection Attack on MS …
Filed under macha, day-macha, humour, politics, server-from-what, work, tumblr, sql, attack, technology, day, powered-by-tumblr, mysql
2) MS SQL “allows query stacking by separating the queries” which confirms the exploit. What? Is this like allowing multiple queries with a semicolon? But MySql and Postgresql do that as well, unless you use a “prepare” statment. …
blog database …
Read the original here:
0×000000 # The Hacker Webzine : Massive SQL Injection Attack on MS …
RailsConf Europe 2007: Day Three
Filed under day, technology, opinion, newton-gra2-com, mac, windows, news, rails, apple, blog, ruby, programming
no strip_tags (you can go around and still inject some code) - use sanitize, SafeERB plugin SQL Injection - Unauthorized reading (without using [] in finds) - Needs ‘, ” or nil + line break - Conditions hash Interpreter Injection …
programming red hat security updates slaptijack softwareprogramming, red …
See the original post here:
RailsConf Europe 2007: Day Three
RSS Full




