Got frozen before the snow downpour.
Just found this (again) on sql best practices
Showing posts with label SQL. Show all posts
Showing posts with label SQL. Show all posts
Wednesday, 6 January 2010
Friday, 23 October 2009
Tuesday, 14 July 2009
Random Musings - Day #195
There is more to meets the eye with SQL security. Not only is there is SQL injection a possibility on websites. This is only half the story. You really have to be familiar with innards of the database in question. Going to put together a SQL hitlist. What queries to try together. It's been done before but it's really good to know.
Scratching my head around popping remote desktop through Zonealarm Free. I don't believe you can configure ports in the free version. A lot of suggestions point to Zonealarm Pro. (my mistake, rdp doesn't work on xp home.)
Why is it when you buy something for a reason, you end up not using/needing it. For example, I bought some deep freeze for my back but my back is now fine. The remedy is not the contents of the medicine but the medicine in the box itself.
Congrats to my housemates, they gave birth to a new baby girl!
Scratching my head around popping remote desktop through Zonealarm Free. I don't believe you can configure ports in the free version. A lot of suggestions point to Zonealarm Pro. (my mistake, rdp doesn't work on xp home.)
Why is it when you buy something for a reason, you end up not using/needing it. For example, I bought some deep freeze for my back but my back is now fine. The remedy is not the contents of the medicine but the medicine in the box itself.
Congrats to my housemates, they gave birth to a new baby girl!
Friday, 10 July 2009
Random Musings - Day #190
Well after the Newcastle back to the office to do late-night web security testing. Kind of reminded me of the good old days at university really. Then you realise you're too old for tht kind of thing.
Anyways, there is a nice little SQL injection cheat sheet and one thing I was looking to do is spew back source code files using load_file. Here's another advanced SQL injection item in a nice slide show.
Also it's always useful to do your research on any framework used and sometimes they may not show on your security guide of choice (CVE|Security Focus) as seen highlights in the xss issues in qcodo.
Anyways, there is a nice little SQL injection cheat sheet and one thing I was looking to do is spew back source code files using load_file. Here's another advanced SQL injection item in a nice slide show.
Also it's always useful to do your research on any framework used and sometimes they may not show on your security guide of choice (CVE|Security Focus) as seen highlights in the xss issues in qcodo.
Saturday, 9 May 2009
Random Musings - Day #129
Articles in brief
Got a Net Addiction?
It's a Dog eat dog world!
Never mess with the Russians!
Be careful of your security questions
Successful face transplant
Security stuff
Encryptions to SQL Server
CISecurity benchmarks for Cicso!
Persistent Rootkits on hardware?
There are ways round it including dual bios
Movie
HK movie I was watching last night is translated as Lady Iron Chef.
Got a Net Addiction?
It's a Dog eat dog world!
Never mess with the Russians!
Be careful of your security questions
Successful face transplant
Security stuff
Encryptions to SQL Server
CISecurity benchmarks for Cicso!
Persistent Rootkits on hardware?
There are ways round it including dual bios
Movie
HK movie I was watching last night is translated as Lady Iron Chef.
Subscribe to:
Posts (Atom)