<?xml version="1.0" encoding="UTF-8"?><rss
version="2.0"
xmlns:content="http://purl.org/rss/1.0/modules/content/"
xmlns:dc="http://purl.org/dc/elements/1.1/"
xmlns:atom="http://www.w3.org/2005/Atom"
xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
> <channel><title>Comments on: Infoweek security issues</title> <atom:link href="http://blog.razuna.com/2008/09/23/infoweek-security-issues/feed/" rel="self" type="application/rss+xml" /><link>http://blog.razuna.com/2008/09/23/infoweek-security-issues/</link> <description>Razuna - Open Source Digital Asset Management (DAM) / Open Source Media Asset Management (MAM), Hosted SaaS DAM</description> <lastBuildDate>Wed, 08 Sep 2010 20:35:56 +0000</lastBuildDate> <generator>http://wordpress.org/?v=2.9.2</generator> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <item><title>By: Randy Johnson</title><link>http://blog.razuna.com/2008/09/23/infoweek-security-issues/comment-page-1/#comment-430</link> <dc:creator>Randy Johnson</dc:creator> <pubDate>Wed, 24 Sep 2008 12:54:43 +0000</pubDate> <guid
isPermaLink="false">http://blog.sixsigns.com/?p=499#comment-430</guid> <description>@Brad,wow I did not know about the allowMultiQueries flag.Yep you are right, injection attacks do not require two statements. The latest round of injection attacks which have been hitting my sites are multi-statement which I was referring to.  I have captured 18000 distinct ipaddresses in the past two months.  Crazy.</description> <content:encoded><![CDATA[<p><!-- google_ad_section_start -->@Brad,</p><p>wow I did not know about the allowMultiQueries flag.</p><p>Yep you are right, injection attacks do not require two statements. The latest round of injection attacks which have been hitting my sites are multi-statement which I was referring to.  I have captured 18000 distinct ipaddresses in the past two months.  Crazy.<!-- google_ad_section_end --></p> ]]></content:encoded> </item> <item><title>By: Brad Wood</title><link>http://blog.razuna.com/2008/09/23/infoweek-security-issues/comment-page-1/#comment-428</link> <dc:creator>Brad Wood</dc:creator> <pubDate>Wed, 24 Sep 2008 06:17:59 +0000</pubDate> <guid
isPermaLink="false">http://blog.sixsigns.com/?p=499#comment-428</guid> <description>@Randy and @Alan:  You most certainly can perform SQLi with BD and Adobe CF on MySQL since not all SQL injection requires two statements.  Secondly many people (including myself) enable the allowMultiQueries flag because they find the single statement limitation annoying.  Regardless, it&#039;s a feature of the DBMS, not the app server.In regards to the original post, that site really needs to get a site-wide error handler.</description> <content:encoded><![CDATA[<p><!-- google_ad_section_start -->@Randy and @Alan:  You most certainly can perform SQLi with BD and Adobe CF on MySQL since not all SQL injection requires two statements.  Secondly many people (including myself) enable the allowMultiQueries flag because they find the single statement limitation annoying.  Regardless, it&#8217;s a feature of the DBMS, not the app server.</p><p>In regards to the original post, that site really needs to get a site-wide error handler.<!-- google_ad_section_end --></p> ]]></content:encoded> </item> <item><title>By: SixSigns</title><link>http://blog.razuna.com/2008/09/23/infoweek-security-issues/comment-page-1/#comment-427</link> <dc:creator>SixSigns</dc:creator> <pubDate>Tue, 23 Sep 2008 14:04:58 +0000</pubDate> <guid
isPermaLink="false">http://blog.sixsigns.com/?p=499#comment-427</guid> <description>There are issues with about every application server. Some drivers recognizes this others don&#039;t. There is much information about this from Ben Forta at http://www.forta.com/blog/index.cfm/2008/7/22/For-Goodness-Sake-Use-CFQUERYPARAM-AlreadyJudging from the date this is recent! Just wade through the comments....</description> <content:encoded><![CDATA[<p><!-- google_ad_section_start -->There are issues with about every application server. Some drivers recognizes this others don&#8217;t. There is much information about this from Ben Forta at <a
href="http://www.forta.com/blog/index.cfm/2008/7/22/For-Goodness-Sake-Use-CFQUERYPARAM-Already" rel="nofollow">http://www.forta.com/blog/index.cfm/2008/7/22/For-Goodness-Sake-Use-CFQUERYPARAM-Already</a></p><p>Judging from the date this is recent! Just wade through the comments&#8230;.<!-- google_ad_section_end --></p> ]]></content:encoded> </item> <item><title>By: Randy Johnson</title><link>http://blog.razuna.com/2008/09/23/infoweek-security-issues/comment-page-1/#comment-426</link> <dc:creator>Randy Johnson</dc:creator> <pubDate>Tue, 23 Sep 2008 13:58:36 +0000</pubDate> <guid
isPermaLink="false">http://blog.sixsigns.com/?p=499#comment-426</guid> <description>Alan,You cannot with Adobe CF either.-Randy</description> <content:encoded><![CDATA[<p><!-- google_ad_section_start -->Alan,</p><p>You cannot with Adobe CF either.</p><p>-Randy<!-- google_ad_section_end --></p> ]]></content:encoded> </item> <item><title>By: Alan</title><link>http://blog.razuna.com/2008/09/23/infoweek-security-issues/comment-page-1/#comment-425</link> <dc:creator>Alan</dc:creator> <pubDate>Tue, 23 Sep 2008 13:21:14 +0000</pubDate> <guid
isPermaLink="false">http://blog.sixsigns.com/?p=499#comment-425</guid> <description>I am not sure how Adobe do things, but with OpenBD, you cannot perform an SQL injection with CFQUERY for MySQL.  this is because the MYSQL driver will not permit two statements in one go.  Try it, you will find you will not be able to do it.</description> <content:encoded><![CDATA[<p><!-- google_ad_section_start -->I am not sure how Adobe do things, but with OpenBD, you cannot perform an SQL injection with CFQUERY for MySQL.  this is because the MYSQL driver will not permit two statements in one go.  Try it, you will find you will not be able to do it.<!-- google_ad_section_end --></p> ]]></content:encoded> </item> <item><title>By: SixSigns</title><link>http://blog.razuna.com/2008/09/23/infoweek-security-issues/comment-page-1/#comment-424</link> <dc:creator>SixSigns</dc:creator> <pubDate>Tue, 23 Sep 2008 12:29:21 +0000</pubDate> <guid
isPermaLink="false">http://blog.sixsigns.com/?p=499#comment-424</guid> <description>This error was coming from a form. Forgot to mention this, but I thought it was obvious.</description> <content:encoded><![CDATA[<p><!-- google_ad_section_start -->This error was coming from a form. Forgot to mention this, but I thought it was obvious.<!-- google_ad_section_end --></p> ]]></content:encoded> </item> <item><title>By: Salvo</title><link>http://blog.razuna.com/2008/09/23/infoweek-security-issues/comment-page-1/#comment-423</link> <dc:creator>Salvo</dc:creator> <pubDate>Tue, 23 Sep 2008 12:29:10 +0000</pubDate> <guid
isPermaLink="false">http://blog.sixsigns.com/?p=499#comment-423</guid> <description>OK no way to post code here. Sorry for spamming your blog  ;-)</description> <content:encoded><![CDATA[<p><!-- google_ad_section_start -->OK no way to post code here. Sorry for spamming your blog <img
src='http://blog.razuna.com/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /> <!-- google_ad_section_end --></p> ]]></content:encoded> </item> <item><title>By: Salvo</title><link>http://blog.razuna.com/2008/09/23/infoweek-security-issues/comment-page-1/#comment-421</link> <dc:creator>Salvo</dc:creator> <pubDate>Tue, 23 Sep 2008 12:26:09 +0000</pubDate> <guid
isPermaLink="false">http://blog.sixsigns.com/?p=499#comment-421</guid> <description>Too bad for them...
The FORM scope is the one to use for POST submission though </description> <content:encoded><![CDATA[<p><!-- google_ad_section_start -->Too bad for them&#8230;<br
/> The FORM scope is the one to use for POST submission though<!-- google_ad_section_end --></p> ]]></content:encoded> </item> </channel> </rss>
<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Minified using disk
Page Caching using disk
Database Caching 7/22 queries in 0.050 seconds using disk

Served from: blog.sixsigns.com @ 2010-09-09 08:16:48 -->