<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.msdn.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>BLOG CHAT: SQL Injection</title><link>http://blogs.msdn.com/tom/archive/2008/07/11/blog-chat-sql-injection.aspx</link><description>So finally all the details have been worked out.&amp;#160; We are going to have this chat on Friday July 18th.&amp;#160; At 2:00 PM EST.&amp;#160; That is 11:00 AM PST. Shortly I will have a link where you can add a reminder to your calendar about this chat.&amp;#160;</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>BLOG CHAT: SQL Injection</title><link>http://blogs.msdn.com/tom/archive/2008/07/11/blog-chat-sql-injection.aspx#8721348</link><pubDate>Fri, 11 Jul 2008 17:16:53 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8721348</guid><dc:creator>DotNetKicks.com</dc:creator><description>&lt;p&gt;You've been kicked (a good thing) - Trackback from DotNetKicks.com&lt;/p&gt;
</description></item><item><title>re: BLOG CHAT: SQL Injection</title><link>http://blogs.msdn.com/tom/archive/2008/07/11/blog-chat-sql-injection.aspx#8721826</link><pubDate>Fri, 11 Jul 2008 21:33:22 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8721826</guid><dc:creator>Neil Carpenter</dc:creator><description>&lt;p&gt;Excellent idea! &amp;nbsp;I hope I can make it.&lt;/p&gt;</description></item><item><title>re: BLOG CHAT: SQL Injection</title><link>http://blogs.msdn.com/tom/archive/2008/07/11/blog-chat-sql-injection.aspx#8731444</link><pubDate>Mon, 14 Jul 2008 15:56:10 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8731444</guid><dc:creator>Ronnie Hoogland</dc:creator><description>&lt;p&gt;Tom,&lt;/p&gt;
&lt;p&gt;why is this such an hot topic? If you use parameters with your sqlCommand you shouldn't be affected by sql injection? or am i missing something?&lt;/p&gt;</description></item><item><title>re: BLOG CHAT: SQL Injection</title><link>http://blogs.msdn.com/tom/archive/2008/07/11/blog-chat-sql-injection.aspx#8731773</link><pubDate>Mon, 14 Jul 2008 20:16:26 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8731773</guid><dc:creator>Tom</dc:creator><description>&lt;p&gt;Ronnie,&lt;/p&gt;
&lt;p&gt;That is correct, I have had a few posts recently on this topic and there was a lot of discussion around that then. &amp;nbsp;The main problem is with all the code that is already there, and that sometimes people don't think to use that. &amp;nbsp;But that would be a good question for the chat if you come :)&lt;/p&gt;
&lt;p&gt;Take a look at:&lt;/p&gt;
&lt;p&gt;&lt;a rel="nofollow" target="_new" href="http://blogs.msdn.com/tom/archive/2008/05/29/sql-injection-and-how-to-avoid-it.aspx"&gt;http://blogs.msdn.com/tom/archive/2008/05/29/sql-injection-and-how-to-avoid-it.aspx&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a rel="nofollow" target="_new" href="http://blogs.msdn.com/tom/archive/2008/06/02/sql-injection-continued.aspx"&gt;http://blogs.msdn.com/tom/archive/2008/06/02/sql-injection-continued.aspx&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a rel="nofollow" target="_new" href="http://blogs.msdn.com/tom/archive/2008/06/26/sql-injection-some-tools-to-help.aspx"&gt;http://blogs.msdn.com/tom/archive/2008/06/26/sql-injection-some-tools-to-help.aspx&lt;/a&gt;&lt;/p&gt;
</description></item></channel></rss>