<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Latest info on SQL injection attack.</title>
	<atom:link href="http://www.rumblepup.com/latest-info-on-sql-injection-attack/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.rumblepup.com/latest-info-on-sql-injection-attack/</link>
	<description>I&#039;m not a player, I just crush alot</description>
	<lastBuildDate>Wed, 28 Jul 2010 07:30:10 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Hacked -- Help - DIY Themes Forums</title>
		<link>http://www.rumblepup.com/latest-info-on-sql-injection-attack/comment-page-1/#comment-41</link>
		<dc:creator>Hacked -- Help - DIY Themes Forums</dc:creator>
		<pubDate>Sun, 17 Aug 2008 04:23:37 +0000</pubDate>
		<guid isPermaLink="false">http://www.rumblepup.com/?p=32#comment-41</guid>
		<description>[...] looks like a sql injection hack to me, which I&#039;ve had some experience enduring Latest info on SQL injection attack. &#124; rumblepup. I don&#039;t know if there is some vulnerability not seem in wordpress before, or if the databases for [...]</description>
		<content:encoded><![CDATA[<p>[...] looks like a sql injection hack to me, which I&#8217;ve had some experience enduring Latest info on SQL injection attack. | rumblepup. I don&#8217;t know if there is some vulnerability not seem in wordpress before, or if the databases for [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rit Man</title>
		<link>http://www.rumblepup.com/latest-info-on-sql-injection-attack/comment-page-1/#comment-40</link>
		<dc:creator>Rit Man</dc:creator>
		<pubDate>Thu, 03 Jul 2008 15:45:38 +0000</pubDate>
		<guid isPermaLink="false">http://www.rumblepup.com/?p=32#comment-40</guid>
		<description>We got attacked on a clients website, and the DECLARE statement had an @ symbol in it, and for some reason when I was parsing the input, that charactor made it seem like the variable was empty, so the parsing for the offending code was useless.

I fixed the problem by parsing the length of the total input not just the individaul variable and we survived MANY MANY subsequent attacks. If your reading this, good luck with your battle!</description>
		<content:encoded><![CDATA[<p>We got attacked on a clients website, and the DECLARE statement had an @ symbol in it, and for some reason when I was parsing the input, that charactor made it seem like the variable was empty, so the parsing for the offending code was useless.</p>
<p>I fixed the problem by parsing the length of the total input not just the individaul variable and we survived MANY MANY subsequent attacks. If your reading this, good luck with your battle!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ADAC</title>
		<link>http://www.rumblepup.com/latest-info-on-sql-injection-attack/comment-page-1/#comment-39</link>
		<dc:creator>ADAC</dc:creator>
		<pubDate>Fri, 06 Jun 2008 17:01:10 +0000</pubDate>
		<guid isPermaLink="false">http://www.rumblepup.com/?p=32#comment-39</guid>
		<description>&quot;If the offending script does not appear, you’ll have clean code and timestamp as to when the last time your code was clean.&quot;

Sounds like your saying that this hack can alter your code. I would think that it can only use weakly written code to alter your database.

Thanks for the info, this is the first time this has happened to one of my site. Visual studio be default block SQL injection, you have to turn this off if you want to be able to pass html and scripts.

I was caught on some old legacy asp code.</description>
		<content:encoded><![CDATA[<p>&#8220;If the offending script does not appear, you’ll have clean code and timestamp as to when the last time your code was clean.&#8221;</p>
<p>Sounds like your saying that this hack can alter your code. I would think that it can only use weakly written code to alter your database.</p>
<p>Thanks for the info, this is the first time this has happened to one of my site. Visual studio be default block SQL injection, you have to turn this off if you want to be able to pass html and scripts.</p>
<p>I was caught on some old legacy asp code.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: The xiaobaishan bomb is now the flyzhu.9966 bomb. &#124; rumblepup</title>
		<link>http://www.rumblepup.com/latest-info-on-sql-injection-attack/comment-page-1/#comment-38</link>
		<dc:creator>The xiaobaishan bomb is now the flyzhu.9966 bomb. &#124; rumblepup</dc:creator>
		<pubDate>Fri, 06 Jun 2008 15:53:26 +0000</pubDate>
		<guid isPermaLink="false">http://www.rumblepup.com/?p=32#comment-38</guid>
		<description>[...] I&#8217;ve got new info on this.  It&#8217;s a pure sql injection [...]</description>
		<content:encoded><![CDATA[<p>[...] I&#8217;ve got new info on this.  It&#8217;s a pure sql injection [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>
