<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.msdn.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>XPath Injection attacks - the "other white meat"?</title><link>http://blogs.msdn.com/asanto/archive/2004/06/16/157517.aspx</link><description>Everyone knows about securing apps from SQL injection attacks, but how many of you have given consideration to XPath injection protection? This (PDF:"Blind Xpath Injection") is a good introduction. A short excerpt shows why XPath injection can be more</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>re: XPath Injection attacks - the "other white meat"?</title><link>http://blogs.msdn.com/asanto/archive/2004/06/16/157517.aspx#157618</link><pubDate>Thu, 17 Jun 2004 01:51:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:157618</guid><dc:creator>Bertrand Le Roy</dc:creator><description>On the other hand, you only risk information disclosure, whereas the dangers of SQL injection usually are the complete destruction of your database and/or taking control of the machine if the dba is careless enough.&lt;br&gt;So as usual, validate and escape user data, and don't store unencoded secrets in a xml file.</description></item><item><title>re: XPath Injection attacks - the "other white meat"?</title><link>http://blogs.msdn.com/asanto/archive/2004/06/16/157517.aspx#157860</link><pubDate>Thu, 17 Jun 2004 08:51:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:157860</guid><dc:creator>Addy Santo</dc:creator><description>You are correct, however I would suggest that theft of data is much more severe than a mere server crash. One is typically remedied by a simple restore operation, while the other is irreversible and cause serious monetary losses, not to mention tarnished reputations. &lt;br&gt;&lt;br&gt;Do you think Valve would have been in worse shape if someone crashed their database instead of stealing the halflife 2 codebase? I doubt it.</description></item><item><title>XPath Injection Attacks</title><link>http://blogs.msdn.com/asanto/archive/2004/06/16/157517.aspx#160314</link><pubDate>Sun, 20 Jun 2004 10:20:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:160314</guid><dc:creator>paul.bz</dc:creator><description /></item><item><title>XPath Injection Attacks</title><link>http://blogs.msdn.com/asanto/archive/2004/06/16/157517.aspx#160906</link><pubDate>Mon, 21 Jun 2004 04:44:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:160906</guid><dc:creator>SecureCoder by Anil John</dc:creator><description /></item><item><title>XPath Injection Attacks</title><link>http://blogs.msdn.com/asanto/archive/2004/06/16/157517.aspx#160907</link><pubDate>Mon, 21 Jun 2004 04:44:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:160907</guid><dc:creator>SecureCoder by Anil John</dc:creator><description /></item><item><title>http://cyberforge.com/weblog/aniltj/</title><link>http://blogs.msdn.com/asanto/archive/2004/06/16/157517.aspx#190756</link><pubDate>Thu, 22 Jul 2004 03:48:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:190756</guid><dc:creator>TrackBack</dc:creator><description>http://cyberforge.com/weblog/aniltj/</description></item><item><title> Santomania XPath Injection attacks the other white meat | Wood TV Stand</title><link>http://blogs.msdn.com/asanto/archive/2004/06/16/157517.aspx#9672645</link><pubDate>Mon, 01 Jun 2009 02:23:52 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9672645</guid><dc:creator> Santomania XPath Injection attacks the other white meat | Wood TV Stand</dc:creator><description>&lt;p&gt;PingBack from &lt;a rel="nofollow" target="_new" href="http://woodtvstand.info/story.php?id=10067"&gt;http://woodtvstand.info/story.php?id=10067&lt;/a&gt;&lt;/p&gt;
</description></item><item><title> Santomania XPath Injection attacks the other white meat | Cast Iron Cookware</title><link>http://blogs.msdn.com/asanto/archive/2004/06/16/157517.aspx#9692324</link><pubDate>Wed, 03 Jun 2009 22:39:55 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9692324</guid><dc:creator> Santomania XPath Injection attacks the other white meat | Cast Iron Cookware</dc:creator><description>&lt;p&gt;PingBack from &lt;a rel="nofollow" target="_new" href="http://castironbakeware.info/story.php?title=santomania-xpath-injection-attacks-the-other-white-meat"&gt;http://castironbakeware.info/story.php?title=santomania-xpath-injection-attacks-the-other-white-meat&lt;/a&gt;&lt;/p&gt;
</description></item></channel></rss>