<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Angels of security &#187; news</title>
	<atom:link href="http://angelsofsecurity.com/blog/tag/news/feed/" rel="self" type="application/rss+xml" />
	<link>http://angelsofsecurity.com/blog</link>
	<description>Musings of an infosec renegade</description>
	<lastBuildDate>Tue, 02 Aug 2011 19:01:53 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>SQL injection DoS attacks.</title>
		<link>http://angelsofsecurity.com/blog/2008/06/13/__af_d_f_n_r_xa-9/</link>
		<comments>http://angelsofsecurity.com/blog/2008/06/13/__af_d_f_n_r_xa-9/#comments</comments>
		<pubDate>Fri, 13 Jun 2008 16:13:21 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[application security]]></category>
		<category><![CDATA[databases]]></category>
		<category><![CDATA[DoS]]></category>
		<category><![CDATA[news]]></category>
		<category><![CDATA[SQL injection]]></category>

		<guid isPermaLink="false">http://angelsofsecurity.com/blog/2008/06/13/__af_d_f_n_r_xa-9/</guid>
		<description><![CDATA[_[^!_%/%a?F%_D)_(F%)_%([)({}%){()}£$&#38;N%_)$*£()$*R"_)][%](%[x])%a][$*"£$-9] There&#8217;s a new paper out on SQL injection DoS attacks. Given the severity of the claims, I don&#8217;t see why this isn&#8217;t getting more coverage. The authors purport that almost any server with a SQL back-end and a search form is vulnerable. Essentially, they craft SQL queries that take an exorbitantly long amount of [...]]]></description>
			<content:encoded><![CDATA[<p>_[^!_%/%a?F%_D)_(F%)_%([)({}%){()}£$&amp;N%_)$*£()$*R"_)][%](%[x])%a][$*"£$-9]</p>
<p>There&#8217;s a <a href="http://www.portcullis-security.com/uplds/wildcard_attacks.pdf">new paper out</a> on SQL injection DoS attacks. Given the severity of the claims, I don&#8217;t see why this isn&#8217;t getting more coverage. The authors purport that almost any server with a SQL back-end and a search form is vulnerable. Essentially, they craft SQL queries that take an exorbitantly long amount of time to execute. When launching a small handful of them, you can actually make a database completely unresponsive. Although perhaps not as damaging as traditional SQL injection (most people would rather have their data unavailable rather than in the hands of an attacker), it appears to be much easier to execute, so it probably won&#8217;t be long before people start seeing this show up everywhere.</p>
]]></content:encoded>
			<wfw:commentRss>http://angelsofsecurity.com/blog/2008/06/13/__af_d_f_n_r_xa-9/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Schadenfreude goes to whole new levels</title>
		<link>http://angelsofsecurity.com/blog/2008/04/09/schadenfreude-goes-to-whole-new-levels/</link>
		<comments>http://angelsofsecurity.com/blog/2008/04/09/schadenfreude-goes-to-whole-new-levels/#comments</comments>
		<pubDate>Wed, 09 Apr 2008 18:56:40 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[news]]></category>
		<category><![CDATA[epilepsy]]></category>
		<category><![CDATA[Schadenfreude]]></category>

		<guid isPermaLink="false">http://angelsofsecurity.com/blog/2008/04/09/schadenfreude-goes-to-whole-new-levels/</guid>
		<description><![CDATA[I know that many people have done many bad things on the internet, just as many people have done many bad things off of the internet, but this still surprises me. Internet griefers descended on an epilepsy support message board last weekend and used JavaScript code and flashing computer animation to trigger migraine headaches and [...]]]></description>
			<content:encoded><![CDATA[<p>I know that many people have done many bad things on the internet, just as many people have done many bad things off of the internet, but <a href="http://www.wired.com/politics/security/news/2008/03/epilepsy">this still surprises me</a>.</p>
<blockquote><p>Internet griefers descended on an <a href="http://www.epilepsyfoundation.org/efforums/forum/index.cfm">epilepsy support message board</a> last weekend and used JavaScript code and flashing computer animation to trigger migraine headaches and seizures in some users.</p>
<p>The attackers turned to a more effective tactic on Sunday, injecting JavaScript into some posts that redirected users&#8217; browsers to a page with a more complex image designed to trigger seizures in both photosensitive and pattern-sensitive epileptics.</p></blockquote>
<p>Although I had never heard of a <a href="http://en.wikipedia.org/wiki/Griefer">Griefer</a> before, I find this activity remarkable in it&#8217;s crude indifference to other human beings. Even stealing money from people&#8217;s bank accounts makes more sense &#8211; at least there human greed can be used as a motive. In this instance, there is no possible benefit to the attacker from causing physical harm to anonymous epilepsy sufferers, and there can be no motive other than the most malicious and reprehensible form of <a href="http://dictionary.reference.com/wordoftheday/archive/2000/05/10.html">Schadenfreude</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://angelsofsecurity.com/blog/2008/04/09/schadenfreude-goes-to-whole-new-levels/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

