<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>WebGratuito &#187; security</title>
	<atom:link href="http://www.webgratuito.com/index/tag/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.webgratuito.com/index</link>
	<description>software, grafica, applicazioni, news</description>
	<lastBuildDate>Thu, 15 Sep 2011 15:43:34 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Half A Million Microsoft-Powered Sites Hit With SQL Injection</title>
		<link>http://www.webgratuito.com/index/2008/04/29/half-a-million-microsoft-powered-sites-hit-with-sql-injection/</link>
		<comments>http://www.webgratuito.com/index/2008/04/29/half-a-million-microsoft-powered-sites-hit-with-sql-injection/#comments</comments>
		<pubDate>Tue, 29 Apr 2008 00:45:48 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[WWB]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[server]]></category>
		<category><![CDATA[Sicurezza]]></category>
		<category><![CDATA[sql injection]]></category>
		<category><![CDATA[Website]]></category>

		<guid isPermaLink="false">http://www.webgratuito.com/index/?p=631</guid>
		<description><![CDATA[A new SQL injection attack aimed at Microsoft IIS web servers has hit some 500,000 websites, including the United Nations, UK Government sites and the U.S. Department of Homeland Security. While the attack is not Microsoft&#8217;s fault, it is unique to the company&#8217;s IIS server. The automated attack takes advantage to the fact that Microsoft’s [...]]]></description>
			<content:encoded><![CDATA[<p>A new SQL injection attack aimed at Microsoft IIS web servers has hit some 500,000 websites, including the United Nations, UK Government sites and the U.S. Department of Homeland Security. While the attack is not Microsoft&#8217;s fault, it is unique to the company&#8217;s IIS server.</p>
<p><a href="http://xkcd.com/327/"><img class="alignleft size-full wp-image-632" title="Webcomic" src="http://www.webgratuito.com/index/wp-content/uploads/2008/04/sqltablesattack.jpg" alt="Webcomic" width="300" height="93" /></a> The automated attack takes advantage to the fact that Microsoft’s IIS servers <a href="http://hackademix.net/2008/04/26/mass-attack-faq/">allow generic commands</a> that don’t require specific table-level arguments. However, the vulnerability is the result of poor data handling by the sites’ creators, rather than a specific Microsoft flaw &#8230;</p>
<p>Read More Via: <a href="http://blog.wired.com/monkeybites/2008/04/microsoft-datab.html" target="_blank">http://blog.wired.com/</a>
<p><b>Random Link&#8217;s: <a target="_blank" href="http://www.fashionitaly.com/index"><br />
Made in Italy</a> &#8230;</b></p></p>
]]></content:encoded>
			<wfw:commentRss>http://www.webgratuito.com/index/2008/04/29/half-a-million-microsoft-powered-sites-hit-with-sql-injection/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

