<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Angels of security &#187; SQL injection</title>
	<atom:link href="http://angelsofsecurity.com/blog/tag/sql-injection/feed/" rel="self" type="application/rss+xml" />
	<link>http://angelsofsecurity.com/blog</link>
	<description>Musings of an infosec renegade</description>
	<lastBuildDate>Tue, 02 Aug 2011 19:01:53 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>SQL injection DoS attacks.</title>
		<link>http://angelsofsecurity.com/blog/2008/06/13/__af_d_f_n_r_xa-9/</link>
		<comments>http://angelsofsecurity.com/blog/2008/06/13/__af_d_f_n_r_xa-9/#comments</comments>
		<pubDate>Fri, 13 Jun 2008 16:13:21 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[application security]]></category>
		<category><![CDATA[databases]]></category>
		<category><![CDATA[DoS]]></category>
		<category><![CDATA[news]]></category>
		<category><![CDATA[SQL injection]]></category>

		<guid isPermaLink="false">http://angelsofsecurity.com/blog/2008/06/13/__af_d_f_n_r_xa-9/</guid>
		<description><![CDATA[_[^!_%/%a?F%_D)_(F%)_%([)({}%){()}£$&#38;N%_)$*£()$*R"_)][%](%[x])%a][$*"£$-9] There&#8217;s a new paper out on SQL injection DoS attacks. Given the severity of the claims, I don&#8217;t see why this isn&#8217;t getting more coverage. The authors purport that almost any server with a SQL back-end and a search form is vulnerable. Essentially, they craft SQL queries that take an exorbitantly long amount of [...]]]></description>
			<content:encoded><![CDATA[<p>_[^!_%/%a?F%_D)_(F%)_%([)({}%){()}£$&amp;N%_)$*£()$*R"_)][%](%[x])%a][$*"£$-9]</p>
<p>There&#8217;s a <a href="http://www.portcullis-security.com/uplds/wildcard_attacks.pdf">new paper out</a> on SQL injection DoS attacks. Given the severity of the claims, I don&#8217;t see why this isn&#8217;t getting more coverage. The authors purport that almost any server with a SQL back-end and a search form is vulnerable. Essentially, they craft SQL queries that take an exorbitantly long amount of time to execute. When launching a small handful of them, you can actually make a database completely unresponsive. Although perhaps not as damaging as traditional SQL injection (most people would rather have their data unavailable rather than in the hands of an attacker), it appears to be much easier to execute, so it probably won&#8217;t be long before people start seeing this show up everywhere.</p>
]]></content:encoded>
			<wfw:commentRss>http://angelsofsecurity.com/blog/2008/06/13/__af_d_f_n_r_xa-9/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

