<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.msdn.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>SQL Injection continued</title><link>http://blogs.msdn.com/tom/archive/2008/06/02/sql-injection-continued.aspx</link><description>My previous post on this topic generated so much discussion that I thought I should post about it some more.&amp;#160; Specifically I wanted to write about means of checking your code for possible SQL Injection problems. The first means of checking, if you</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>SQL Injection continued</title><link>http://blogs.msdn.com/tom/archive/2008/06/02/sql-injection-continued.aspx#8569589</link><pubDate>Mon, 02 Jun 2008 18:43:41 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8569589</guid><dc:creator>DotNetKicks.com</dc:creator><description>&lt;p&gt;You've been kicked (a good thing) - Trackback from DotNetKicks.com&lt;/p&gt;
</description></item><item><title>re: SQL Injection continued</title><link>http://blogs.msdn.com/tom/archive/2008/06/02/sql-injection-continued.aspx#8571106</link><pubDate>Tue, 03 Jun 2008 10:05:21 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8571106</guid><dc:creator>roger</dc:creator><description>&lt;p&gt;I have been attacked 6 times within 2 weeks and cant run my business. Whats the best way to stop this?&lt;/p&gt;</description></item><item><title>re: SQL Injection continued</title><link>http://blogs.msdn.com/tom/archive/2008/06/02/sql-injection-continued.aspx#8571184</link><pubDate>Tue, 03 Jun 2008 11:01:58 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8571184</guid><dc:creator>Shail</dc:creator><description>&lt;p&gt;Hi Tom,&lt;/p&gt;
&lt;p&gt;So I am using Visual Studio 2005 professional edition ( we can not afford to have VS 2008 right now ). Now how I can use it to detect SQL Injection pron queries, Also what other tools or add-ins I can use with my professional edition so that I can detect XSS attacks and any other possible threats.&lt;/p&gt;
&lt;p&gt;Something like I ask the &amp;quot;tool&amp;quot; check my code for all possible attacks and vulnerability.&lt;/p&gt;
&lt;p&gt;Can you please suggest something ??&lt;/p&gt;
&lt;p&gt;Thanks,&lt;/p&gt;
&lt;p&gt;Shail&lt;/p&gt;</description></item><item><title>re: SQL Injection continued</title><link>http://blogs.msdn.com/tom/archive/2008/06/02/sql-injection-continued.aspx#8571247</link><pubDate>Tue, 03 Jun 2008 11:53:53 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8571247</guid><dc:creator>StevenMcD</dc:creator><description>&lt;p&gt;Maybe its just me, but I feel inline SQL is incredibly bad design. Especially with the introduction of LiNQ. To me, there is no longer a reason to include inline SQL in any project ever.&lt;/p&gt;</description></item><item><title>re: SQL Injection continued</title><link>http://blogs.msdn.com/tom/archive/2008/06/02/sql-injection-continued.aspx#8571627</link><pubDate>Tue, 03 Jun 2008 17:53:57 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8571627</guid><dc:creator>Tom</dc:creator><description>&lt;p&gt;Roger,&lt;/p&gt;
&lt;p&gt;Are you discovering problems or they are just trying to get in? &amp;nbsp;If you have problems, I'd suggest contacting someone to help you figure out how you can stop the attacks. &amp;nbsp;If you are using Microsoft products, we will be glad to assist you in locking down the server and protecting it. &amp;nbsp;So my &amp;quot;Contacting Tom&amp;quot; post:&lt;/p&gt;
&lt;p&gt;&lt;a rel="nofollow" target="_new" href="http://blogs.msdn.com/tom/archive/2007/11/15/contacting-tom.aspx"&gt;http://blogs.msdn.com/tom/archive/2007/11/15/contacting-tom.aspx&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;For information on how to contact support.&lt;/p&gt;
</description></item><item><title>re: SQL Injection continued</title><link>http://blogs.msdn.com/tom/archive/2008/06/02/sql-injection-continued.aspx#8571631</link><pubDate>Tue, 03 Jun 2008 17:59:25 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8571631</guid><dc:creator>Tom</dc:creator><description>&lt;p&gt;Shail,&lt;/p&gt;
&lt;p&gt;Have you checked the tools that I linked to this post? &amp;nbsp;The 3 towards the bottom don't rely on VS2008 and may help you.&lt;/p&gt;
</description></item><item><title>re: SQL Injection continued</title><link>http://blogs.msdn.com/tom/archive/2008/06/02/sql-injection-continued.aspx#8571635</link><pubDate>Tue, 03 Jun 2008 18:00:45 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8571635</guid><dc:creator>Tom</dc:creator><description>&lt;p&gt;StevenMcD,&lt;/p&gt;
&lt;p&gt;While I agree that Linq does help a lot, there are still some legacy projects that have this code it is that someone may be update to upgrade to Linq right away. &amp;nbsp;Hopefully I will have a post about Linq soon to help with this also.&lt;/p&gt;
</description></item><item><title>re: SQL Injection continued</title><link>http://blogs.msdn.com/tom/archive/2008/06/02/sql-injection-continued.aspx#8573781</link><pubDate>Wed, 04 Jun 2008 21:36:16 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8573781</guid><dc:creator>theredhead</dc:creator><description>&lt;p&gt;Tom, great to see this, too bad I didn't see it until now!&lt;/p&gt;</description></item><item><title>re: SQL Injection continued</title><link>http://blogs.msdn.com/tom/archive/2008/06/02/sql-injection-continued.aspx#8765965</link><pubDate>Wed, 23 Jul 2008 08:34:45 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8765965</guid><dc:creator>jay</dc:creator><description>&lt;p&gt;hi tom&lt;/p&gt;
&lt;p&gt;im jay and im a comsci student..At this moment im still searching for my thesis..&amp;quot;SQL Injection Analysis: Attacks and Vulnerabilities&amp;quot;&lt;/p&gt;
&lt;p&gt;i want to ask some opinion from you.&lt;/p&gt;
&lt;p&gt;you can email me at (me_comsci@yahoo.com)&lt;/p&gt;</description></item></channel></rss>