<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://www.websitemagazine.com/content/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>'Net Features : urlscan</title><link>http://www.websitemagazine.com/content/blogs/posts/archive/tags/urlscan/default.aspx</link><description>Tags: urlscan</description><dc:language>en</dc:language><generator>CommunityServer 2008 SP2 (Build: 31104.93)</generator><item><title>SQL Injection Detection and Defense</title><link>http://www.websitemagazine.com/content/blogs/posts/archive/2008/06/25/SQL-Injection-Detection-and-Defense.aspx</link><pubDate>Wed, 25 Jun 2008 16:00:00 GMT</pubDate><guid isPermaLink="false">1e469e21-c924-44fa-a132-47b5d0a8ad47:5736</guid><dc:creator>Pete Prestipino</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://www.websitemagazine.com/content/blogs/posts/rsscomments.aspx?PostID=5736</wfw:commentRss><comments>http://www.websitemagazine.com/content/blogs/posts/archive/2008/06/25/SQL-Injection-Detection-and-Defense.aspx#comments</comments><description>Microsoft has released tools to help website developers in their defense against SQL injection on sites that use ASP and ASP.Net technologies. The tools include &lt;a href="http://learn.iis.net/page.aspx/473/using-urlscan"&gt;&lt;b&gt;URLScan 3.0&lt;/b&gt;&lt;/a&gt; (which is in beta release) and Microsoft Source Code Analyzer for SQL Injection (MSCASI), available as a Community Technology Preview. &lt;br /&gt;&lt;br /&gt;&lt;b&gt;Hewlett Packard has also developed a free scanner which can identify whether sites are susceptible to SQL injection dubbed &lt;a href="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2008/06/23/finding-sql-injection-with-scrawlr.aspx"&gt;Scrawlr&lt;/a&gt;. &lt;/b&gt;&lt;br /&gt;&lt;br /&gt;Developed to help battle recent SQL injection attacks as per a Microsoft Security Advisory bulletin, the tools are intended to help developers build more secure code and promote a more trusted ecosystem, Microsoft said.&lt;br /&gt;&lt;br /&gt;There has been a recent rise in SQL injection attacks exploiting unverified user data input. When these attacks are successful, a hacker/ attacker can compromise data stored in databases and possibly execute remote code. Clients browsing to a compromised server could be forwarded to malicious sites that may install malware on the client machine.&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.websitemagazine.com/content/aggbug.aspx?PostID=5736" width="1" height="1"&gt;</description><category domain="http://www.websitemagazine.com/content/blogs/posts/archive/tags/microsoft/default.aspx">microsoft</category><category domain="http://www.websitemagazine.com/content/blogs/posts/archive/tags/urlscan/default.aspx">urlscan</category><category domain="http://www.websitemagazine.com/content/blogs/posts/archive/tags/SQL/default.aspx">SQL</category></item></channel></rss>