August 16, 2010 5:02 PM
Posted by: Dan O'Connor
sql,
sql cast,
SQL injectionhttp://isc.sans.edu/diary.html?storyid=9397
I have played with this before, the most effective method I found of blocking these was looking for the CAST statement itself.
The statement at least from the ones that I was playing with all had a "CAST", "SET", "VARCHAR", and "EXEC". I found...
July 8, 2010 11:50 AM
Posted by: Dan O'Connor
SQL injection,
thepiratebay.orgThere appears to have been more then a few SQL injection vulnerabilities on thepiratebay.org,
http://krebsonsecurity.com/2010/07/pirate-bay-hack-exposes-user-booty/
The group responsible says that none of the information gained was sold or disseminated. Still if you had an account there I...