<?xml version="1.0"?><rss version="2.0"><channel><title>SQLSecurity.com</title><link>http://sqlsecurity.com</link><description>SQL Server Security Website by Chip Andrews</description><language>en-US</language><copyright>Copyright 1999 by Chip Andrews</copyright><webMaster>chip@sqlsecurity.com</webMaster><item><title>Chip's Blog - Frank Brown Contributes New Features to SQLVer Application</title><description>Frank Brown has taken sqlver 1.0 and additional features such as:  1. default port to 1433 if none s...</description><link>http://sqlsecurity.com/Home/tabid/36/Default.aspx</link><pubDate>Thu, 21 Jan 2010 08:00:00 GMT</pubDate><guid>http://sqlsecurity.com/Home/tabid/36/Default.aspx?ItemId=853</guid></item><item><title>Chip's Blog - Metasploit Framework 3.3 Adds New SQL Server Features</title><description>With the 3.3 version of the Metasploit Framework comes the news that it now includes features specif...</description><link>http://sqlsecurity.com/Home/tabid/36/Default.aspx</link><pubDate>Fri, 20 Nov 2009 08:00:00 GMT</pubDate><guid>http://sqlsecurity.com/Home/tabid/36/Default.aspx?ItemId=852</guid></item><item><title>Chip's Blog - ISC Sends Reminder on SQL Server Service Ports</title><description>ISC has released a reminder about the dangers of TCP 1433 and UDP 1434 traffic and what it means (us...</description><link>http://sqlsecurity.com/Home/tabid/36/Default.aspx</link><pubDate>Mon, 26 Oct 2009 07:00:00 GMT</pubDate><guid>http://sqlsecurity.com/Home/tabid/36/Default.aspx?ItemId=851</guid></item><item><title>Chip's Blog - TJX Indictments Mean We Get More SQL Injection Details</title><description>With the indictments coming in for the TJX hacking incident, many more details regarding the nature ...</description><link>http://sqlsecurity.com/Home/tabid/36/Default.aspx</link><pubDate>Mon, 17 Aug 2009 07:00:00 GMT</pubDate><guid>http://sqlsecurity.com/Home/tabid/36/Default.aspx?ItemId=850</guid></item><item><title>Chip's Blog - SQL Server Considered for Future Version of Exchange</title><description>This has been kicking around for years but it appears Microsoft may be looking at this for a post-20...</description><link>http://sqlsecurity.com/Home/tabid/36/Default.aspx</link><pubDate>Sat, 25 Jul 2009 07:00:00 GMT</pubDate><guid>http://sqlsecurity.com/Home/tabid/36/Default.aspx?ItemId=849</guid></item><item><title>Chip's Blog - Suspected Turkish SQL Server Injection Attack on U.S. Military</title><description>In yet another high-profile Microsoft SQL Server injection attack, the U.S. Army appears to be the l...</description><link>http://sqlsecurity.com/Home/tabid/36/Default.aspx</link><pubDate>Fri, 29 May 2009 07:00:00 GMT</pubDate><guid>http://sqlsecurity.com/Home/tabid/36/Default.aspx?ItemId=848</guid></item><item><title>Chip's Blog - Shameless Plug for Network Toaster</title><description>While the thread of applicability to SQL Server security is virtually non-existant, I wanted to sham...</description><link>http://sqlsecurity.com/Home/tabid/36/Default.aspx</link><pubDate>Fri, 22 May 2009 07:00:00 GMT</pubDate><guid>http://sqlsecurity.com/Home/tabid/36/Default.aspx?ItemId=847</guid></item><item><title>Chip's Blog - SQL Server 2008 SP1 Released</title><description>OK - you got me - SP1 for SQL Server 2008 has been out for about a month now but in lieu of any othe...</description><link>http://sqlsecurity.com/Home/tabid/36/Default.aspx</link><pubDate>Mon, 04 May 2009 07:00:00 GMT</pubDate><guid>http://sqlsecurity.com/Home/tabid/36/Default.aspx?ItemId=846</guid></item><item><title>Chip's Blog - Excellent Article on Scripting SQLPing3cl.exe</title><description>onpnt at blogs.LessThanDot.com has put together an excellent article on scripting SQLPing3cl.exe (st...</description><link>http://sqlsecurity.com/Home/tabid/36/Default.aspx</link><pubDate>Mon, 09 Mar 2009 07:00:00 GMT</pubDate><guid>http://sqlsecurity.com/Home/tabid/36/Default.aspx?ItemId=845</guid></item><item><title>Chip's Blog - SQL Server Buffer Overflow in sp_replwritetovarbin</title><description>A buffer overflow has been identified in older (and un-patched) versions of SQL Server. The vulnerab...</description><link>http://sqlsecurity.com/Home/tabid/36/Default.aspx</link><pubDate>Tue, 10 Feb 2009 08:00:00 GMT</pubDate><guid>http://sqlsecurity.com/Home/tabid/36/Default.aspx?ItemId=844</guid></item><item><title>Chip's Blog - SQL Injection on Kaspersky Website</title><description>A SQL Injection attack has been staged against security software vendor Kaspersky.  The only thing n...</description><link>http://sqlsecurity.com/Home/tabid/36/Default.aspx</link><pubDate>Sun, 08 Feb 2009 08:00:00 GMT</pubDate><guid>http://sqlsecurity.com/Home/tabid/36/Default.aspx?ItemId=843</guid></item><item><title>Chip's Blog - Vulnerability in Extended Stored Proc Forces MS to Release a Patch 961040</title><description>You may often notice that in the SQL Server recommendations on this site, there are references to di...</description><link>http://sqlsecurity.com/Home/tabid/36/Default.aspx</link><pubDate>Thu, 25 Dec 2008 08:00:00 GMT</pubDate><guid>http://sqlsecurity.com/Home/tabid/36/Default.aspx?ItemId=842</guid></item><item><title>Chip's Blog - SQL Injection via Cookie attempts to exploit the new MSIE hole</title><description>SANS has an interesting analysis of a new SQL Injection attack that uses cookies for initial exploit...</description><link>http://sqlsecurity.com/Home/tabid/36/Default.aspx</link><pubDate>Fri, 12 Dec 2008 08:00:00 GMT</pubDate><guid>http://sqlsecurity.com/Home/tabid/36/Default.aspx?ItemId=841</guid></item><item><title>Chip's Blog - Web Application Firewall Discussion at ISC</title><description>Due to the recent outbreak of SQL Injection bots making the rounds, ISC made a recommendation of sev...</description><link>http://sqlsecurity.com/Home/tabid/36/Default.aspx</link><pubDate>Sun, 23 Nov 2008 08:00:00 GMT</pubDate><guid>http://sqlsecurity.com/Home/tabid/36/Default.aspx?ItemId=840</guid></item><item><title>Chip's Blog - BusinessWeek Hit by SQL Injection Attack</title><description>Here's another example of SQL Injection on a very popular website.  Again - I believe that the SQL I...</description><link>http://sqlsecurity.com/Home/tabid/36/Default.aspx</link><pubDate>Mon, 15 Sep 2008 07:00:00 GMT</pubDate><guid>http://sqlsecurity.com/Home/tabid/36/Default.aspx?ItemId=839</guid></item><item><title>Chip's Blog - New SQL Injection Worm Targeting MSSQL</title><description>Another worm is making the rounds.  I really don't see much new in this particular variant but it sh...</description><link>http://sqlsecurity.com/Home/tabid/36/Default.aspx</link><pubDate>Tue, 12 Aug 2008 07:00:00 GMT</pubDate><guid>http://sqlsecurity.com/Home/tabid/36/Default.aspx?ItemId=838</guid></item><item><title>Chip's Blog - Buffer Overflow in SQL Server Convert Function</title><description>As part of the Black Tuesday release this month from Microsoft, we have a critical vulnerability in ...</description><link>http://sqlsecurity.com/Home/tabid/36/Default.aspx</link><pubDate>Tue, 08 Jul 2008 07:00:00 GMT</pubDate><guid>http://sqlsecurity.com/Home/tabid/36/Default.aspx?ItemId=837</guid></item><item><title>Chip's Blog - Microsoft Releases KB Article on SQL Injection</title><description>Good grief.  You know SQL injection attacks are getting bad when Microsoft releases a KB article tha...</description><link>http://sqlsecurity.com/Home/tabid/36/Default.aspx</link><pubDate>Tue, 01 Jul 2008 07:00:00 GMT</pubDate><guid>http://sqlsecurity.com/Home/tabid/36/Default.aspx?ItemId=836</guid></item><item><title>Chip's Blog - Researcher at Blue Hat Convention Has Bad News for SQL Server</title><description>Well - SQL Server and most all other Windows services that implement impersonation - that is. Appare...</description><link>http://sqlsecurity.com/Home/tabid/36/Default.aspx</link><pubDate>Sun, 18 May 2008 07:00:00 GMT</pubDate><guid>http://sqlsecurity.com/Home/tabid/36/Default.aspx?ItemId=835</guid></item><item><title>Chip's Blog - Massive SQL Injection Attack Targets Websites Using SQL Server</title><description>Looks like another mass SQL Injection attack is making the rounds.  The attackers likely used Google...</description><link>http://sqlsecurity.com/Home/tabid/36/Default.aspx</link><pubDate>Fri, 25 Apr 2008 07:00:00 GMT</pubDate><guid>http://sqlsecurity.com/Home/tabid/36/Default.aspx?ItemId=834</guid></item><item><title>Chip's Blog - New Priv Escalation Security Vulnerability (951306) Affects SQL Server</title><description>Applications that allow users to run code in an authenticated context (IIS, SQL Server) could be at ...</description><link>http://sqlsecurity.com/Home/tabid/36/Default.aspx</link><pubDate>Sat, 19 Apr 2008 07:00:00 GMT</pubDate><guid>http://sqlsecurity.com/Home/tabid/36/Default.aspx?ItemId=833</guid></item><item><title>Chip's Blog - Quick SQL 2008 Security Highlights Article</title><description>Kevin Beaver has highlighted some SQL Server 2008 features that may interest readers.  Feel free to ...</description><link>http://sqlsecurity.com/Home/tabid/36/Default.aspx</link><pubDate>Wed, 19 Mar 2008 07:00:00 GMT</pubDate><guid>http://sqlsecurity.com/Home/tabid/36/Default.aspx?ItemId=832</guid></item><item><title>Chip's Blog - SQL Server 2008 CTP Released</title><description>Microsoft has released the CTP for SQL Server 2008.  On the security side, Microsoft is touting the ...</description><link>http://sqlsecurity.com/Home/tabid/36/Default.aspx</link><pubDate>Tue, 26 Feb 2008 08:00:00 GMT</pubDate><guid>http://sqlsecurity.com/Home/tabid/36/Default.aspx?ItemId=831</guid></item><item><title>Chip's Blog - Apologies for Forum Moderation Delays</title><description>I wanted to personally apologize for the delay in Discussion Forum moderations.  Usually I stay on t...</description><link>http://sqlsecurity.com/Home/tabid/36/Default.aspx</link><pubDate>Sun, 03 Feb 2008 08:00:00 GMT</pubDate><guid>http://sqlsecurity.com/Home/tabid/36/Default.aspx?ItemId=830</guid></item><item><title>Chip's Blog - First Mass SQL Injection Worm? </title><description>Apparently a new worm has appeared on the Internet that uses SQL injection to infect sites with mali...</description><link>http://sqlsecurity.com/Home/tabid/36/Default.aspx</link><pubDate>Tue, 08 Jan 2008 08:00:00 GMT</pubDate><guid>http://sqlsecurity.com/Home/tabid/36/Default.aspx?ItemId=829</guid></item><item><title>Chip's Blog - New "Tiger Team" TV Show Focuses on Penetration Testing</title><description>While the overall effectiveness of penetration testing as a security mechanism is debatable, it sure...</description><link>http://sqlsecurity.com/Home/tabid/36/Default.aspx</link><pubDate>Wed, 26 Dec 2007 08:00:00 GMT</pubDate><guid>http://sqlsecurity.com/Home/tabid/36/Default.aspx?ItemId=828</guid></item><item><title>Chip's Blog - Commercial Tools Page Added</title><description>I have added a page to the site to host security tools I have created for security engagements and/o...</description><link>http://sqlsecurity.com/Home/tabid/36/Default.aspx</link><pubDate>Sun, 04 Nov 2007 07:00:00 GMT</pubDate><guid>http://sqlsecurity.com/Home/tabid/36/Default.aspx?ItemId=827</guid></item><item><title>Chip's Blog - SQLPing3 Command Line - Alpha release</title><description>I have finally posted an alpha release of the command-line version of SQLPing3. Please provide any f...</description><link>http://sqlsecurity.com/Home/tabid/36/Default.aspx</link><pubDate>Wed, 24 Oct 2007 07:00:00 GMT</pubDate><guid>http://sqlsecurity.com/Home/tabid/36/Default.aspx?ItemId=826</guid></item><item><title>Chip's Blog - Acunetix Whitepaper on Web Services Vulnerabilities</title><description>Acunetix has posted an article of web services security that discusses (at a high level) some of the...</description><link>http://sqlsecurity.com/Home/tabid/36/Default.aspx</link><pubDate>Sun, 13 May 2007 07:00:00 GMT</pubDate><guid>http://sqlsecurity.com/Home/tabid/36/Default.aspx?ItemId=817</guid></item><item><title>Chip's Blog - Imperva Releases Free "Scuba" Vulnerability Scanner for Multiple Databases</title><description>Hey - I'm always a fan of free so check it out (from their press release):  "Scuba by Imperva is a f...</description><link>http://sqlsecurity.com/Home/tabid/36/Default.aspx</link><pubDate>Sun, 06 May 2007 07:00:00 GMT</pubDate><guid>http://sqlsecurity.com/Home/tabid/36/Default.aspx?ItemId=816</guid></item><item><title>Chip's Blog - SQLPing3 Released</title><description>SQLPing 3.0 is the evolution of the SQLPing product to the .NET Framework using code from SQLRecon. ...</description><link>http://sqlsecurity.com/Home/tabid/36/Default.aspx</link><pubDate>Sun, 22 Apr 2007 07:00:00 GMT</pubDate><guid>http://sqlsecurity.com/Home/tabid/36/Default.aspx?ItemId=814</guid></item><item><title>Chip's Blog - SQLRecon/SQLPing Updates</title><description>I have re-compiled SQLRecon 1.0 with .NET Framework 2.0 for those of you who have been keeping up.  ...</description><link>http://sqlsecurity.com/Home/tabid/36/Default.aspx</link><pubDate>Tue, 27 Mar 2007 07:00:00 GMT</pubDate><guid>http://sqlsecurity.com/Home/tabid/36/Default.aspx?ItemId=812</guid></item><item><title>Blog - 03-20-07  Site Undergoing a Version Upgrade</title><description>SQLSecurity.com is currently in the middle of a software upgrade.  I will re-post the older blog ent...</description><link>http://sqlsecurity.com/Home/tabid/36/Default.aspx</link><pubDate>Tue, 20 Mar 2007 07:00:00 GMT</pubDate><guid>http://sqlsecurity.com/Home/tabid/36/Default.aspx?ItemId=625</guid></item><item><title>Blog - 02-12-07 A Collection of Excellent Articles about SQL Injection</title><description>Acunetix has posted an excellent series of articles on web application security including several on...</description><link>http://sqlsecurity.com/Home/tabid/36/Default.aspx</link><pubDate>Tue, 13 Feb 2007 02:18:57 GMT</pubDate><guid>http://sqlsecurity.com/Home/tabid/36/Default.aspx?ItemId=660</guid></item><item><title>Blog - 01-30-07 Microsoft Releases KB Article on the SQL 2005 Express/Vista Issue</title><description>It appears Microsoft has finally presented an explanation and workaround for those wishing to run SQ...</description><link>http://sqlsecurity.com/Home/tabid/36/Default.aspx</link><pubDate>Tue, 30 Jan 2007 19:48:29 GMT</pubDate><guid>http://sqlsecurity.com/Home/tabid/36/Default.aspx?ItemId=659</guid></item><item><title>Blog - 12-16-06 SQL Server 2005 Express not compatible with Vista</title><description>For those of you planning to jump on Windows Vista for all those supposed new security improvements ...</description><link>http://sqlsecurity.com/Home/tabid/36/Default.aspx</link><pubDate>Sat, 16 Dec 2006 19:49:23 GMT</pubDate><guid>http://sqlsecurity.com/Home/tabid/36/Default.aspx?ItemId=658</guid></item><item><title>Blog - 11-7-2006 Article on Forensic Tamper Detection is SQL Server Tables</title><description>Amit Basu has submitted an excellent article on implementing forensic tamper detection in SQL Server...</description><link>http://sqlsecurity.com/Home/tabid/36/Default.aspx</link><pubDate>Tue, 07 Nov 2006 18:14:10 GMT</pubDate><guid>http://sqlsecurity.com/Home/tabid/36/Default.aspx?ItemId=657</guid></item><item><title>Blog - 10-23-06 New Organization Created To Promote Application Security </title><description>Tim Mullen has started a new open-membership security organization with a provocative name. The orga...</description><link>http://sqlsecurity.com/Home/tabid/36/Default.aspx</link><pubDate>Mon, 23 Oct 2006 23:55:45 GMT</pubDate><guid>http://sqlsecurity.com/Home/tabid/36/Default.aspx?ItemId=656</guid></item><item><title>Blog - 09-10-06 Article on Building Secure Protocols - SSPI discussed</title><description>For anyone who has ever assembled a SQL Server connection string, the phrase "Integrated Security=SS...</description><link>http://sqlsecurity.com/Home/tabid/36/Default.aspx</link><pubDate>Sun, 10 Sep 2006 12:57:21 GMT</pubDate><guid>http://sqlsecurity.com/Home/tabid/36/Default.aspx?ItemId=655</guid></item><item><title>Blog - 07-21-06  Looks like ISC has solved the mystery </title><description>ISC has concluded that the spike in TCP 1433 is probably due to someone using the old MSSQL 2000 pre...</description><link>http://sqlsecurity.com/Home/tabid/36/Default.aspx</link><pubDate>Fri, 21 Jul 2006 16:04:58 GMT</pubDate><guid>http://sqlsecurity.com/Home/tabid/36/Default.aspx?ItemId=654</guid></item><item><title>Blog - 07-19-06 TCP port 1433 scans spiking at ISC</title><description>ISC is reporting a spike in TCP 1433 (default SQL Server posrt) scans across the internet as detecte...</description><link>http://sqlsecurity.com/Home/tabid/36/Default.aspx</link><pubDate>Wed, 19 Jul 2006 11:42:16 GMT</pubDate><guid>http://sqlsecurity.com/Home/tabid/36/Default.aspx?ItemId=653</guid></item><item><title>Blog - 07-11-06 Application Security Scanners Galore</title><description>I've been adding plenty of products to the Assessment Tools section of the site under "SQL Server Re...</description><link>http://sqlsecurity.com/Home/tabid/36/Default.aspx</link><pubDate>Sun, 09 Jul 2006 23:21:26 GMT</pubDate><guid>http://sqlsecurity.com/Home/tabid/36/Default.aspx?ItemId=652</guid></item><item><title>Blog - 05-11-06 What should we do when we find a vulnerability?</title><description>You've been there.  You're on some site, tooling around looking at news, articles, whatever.  Sudden...</description><link>http://sqlsecurity.com/Home/tabid/36/Default.aspx</link><pubDate>Thu, 11 May 2006 19:12:31 GMT</pubDate><guid>http://sqlsecurity.com/Home/tabid/36/Default.aspx?ItemId=651</guid></item><item><title>Blog - 04-18-2006 SQL Server 2005 SP1 goes RTM</title><description>SQL Server 2005 Service Pack 1 has been released.  One noticable difference right off the top is tha...</description><link>http://sqlsecurity.com/Home/tabid/36/Default.aspx</link><pubDate>Sun, 23 Apr 2006 17:03:15 GMT</pubDate><guid>http://sqlsecurity.com/Home/tabid/36/Default.aspx?ItemId=650</guid></item><item><title>Blog - Migration largely complete - Wednesday, March 01, 2006</title><description>Well - that was fast - the tools are back online and the free analysis page is working again.  Pleas...</description><link>http://sqlsecurity.com/Home/tabid/36/Default.aspx</link><pubDate>Thu, 02 Mar 2006 04:50:21 GMT</pubDate><guid>http://sqlsecurity.com/Home/tabid/36/Default.aspx?ItemId=648</guid></item><item><title>Blog - Site Upgrade in Progress - Tuesday, February 28, 2006</title><description>In case you haven't noticed, I have upgraded the site to DNN 4.0.2 and am in the process on integrat...</description><link>http://sqlsecurity.com/Home/tabid/36/Default.aspx</link><pubDate>Wed, 01 Mar 2006 03:29:19 GMT</pubDate><guid>http://sqlsecurity.com/Home/tabid/36/Default.aspx?ItemId=647</guid></item><item><title>Blog - Excellent article on SQL Server Security Testing - Tuesday, February 28, 2006</title><description>This is an excellent TechTarget article on SQL Server security testing by Kevin Beaver. The highligh...</description><link>http://sqlsecurity.com/Home/tabid/36/Default.aspx</link><pubDate>Wed, 01 Mar 2006 01:45:30 GMT</pubDate><guid>http://sqlsecurity.com/Home/tabid/36/Default.aspx?ItemId=645</guid></item><item><title>Blog - Article on 10 tricks attackers use to access SQL Server - Tuesday, February 28, 2006</title><description>Informative article on how attackers commonly compromise SQL Server systems. Besides the scenarios, ...</description><link>http://sqlsecurity.com/Home/tabid/36/Default.aspx</link><pubDate>Wed, 01 Mar 2006 01:44:12 GMT</pubDate><guid>http://sqlsecurity.com/Home/tabid/36/Default.aspx?ItemId=646</guid></item><item><title>Blog - Testing Testing Testing</title><description>Now that we have a release for SQL 2005 in our grubby little hands, its time for some good ole pen t...</description><link>http://sqlsecurity.com/Home/tabid/36/Default.aspx</link><pubDate>Fri, 16 Dec 2005 00:56:08 GMT</pubDate><guid>http://sqlsecurity.com/Home/tabid/36/Default.aspx?ItemId=795</guid></item><item><title>Blog - SQL Server 2005 goes RTM</title><description>SQL Server 2005 and Visual Studio 2005 Professionsal have been released to manufacturing.  You shoul...</description><link>http://sqlsecurity.com/Home/tabid/36/Default.aspx</link><pubDate>Fri, 28 Oct 2005 15:49:55 GMT</pubDate><guid>http://sqlsecurity.com/Home/tabid/36/Default.aspx?ItemId=794</guid></item><item><title>Blog - SQL Server Security School</title><description>Not sure how I forgot to post this earlier but I did record a webcast series on SearchSQLServer.com ...</description><link>http://sqlsecurity.com/Home/tabid/36/Default.aspx</link><pubDate>Fri, 07 Oct 2005 21:12:52 GMT</pubDate><guid>http://sqlsecurity.com/Home/tabid/36/Default.aspx?ItemId=793</guid></item><item><title>Blog - SQL Server 2005 coming soon - Need a Preview?</title><description>OK - it's been kinda quiet lately on the SQL Server front that's for sure.  But look on the bright s...</description><link>http://sqlsecurity.com/Home/tabid/36/Default.aspx</link><pubDate>Fri, 30 Sep 2005 23:20:16 GMT</pubDate><guid>http://sqlsecurity.com/Home/tabid/36/Default.aspx?ItemId=792</guid></item><item><title>Blog - Never made it to Black Hat - Apologies to all!</title><description>OK - so I had every intention of going to Black Hat this week.  I was packed.  I had my new laptop r...</description><link>http://sqlsecurity.com/Home/tabid/36/Default.aspx</link><pubDate>Sat, 30 Jul 2005 00:45:22 GMT</pubDate><guid>http://sqlsecurity.com/Home/tabid/36/Default.aspx?ItemId=791</guid></item><item><title>Blog - Web Application Security Training at Black Hat</title><description>I will be one of many trainers for a course on web application security at Black Hat in Vegas July 2...</description><link>http://sqlsecurity.com/Home/tabid/36/Default.aspx</link><pubDate>Sun, 10 Jul 2005 19:08:13 GMT</pubDate><guid>http://sqlsecurity.com/Home/tabid/36/Default.aspx?ItemId=790</guid></item><item><title>Blog - Microsoft gives us a date for SQL Server 2005</title><description>At Teched Orlando, Paul Flessner announced that Nov 7, 2005 is the release date for SQL Server 2005 ...</description><link>http://sqlsecurity.com/Home/tabid/36/Default.aspx</link><pubDate>Thu, 09 Jun 2005 01:49:24 GMT</pubDate><guid>http://sqlsecurity.com/Home/tabid/36/Default.aspx?ItemId=789</guid></item><item><title>Blog - Microsoft WSUS goes RTM - At last!</title><description>Microsoft's WSUS product has been released to manufacturing and was distributed attendees at Teched....</description><link>http://sqlsecurity.com/Home/tabid/36/Default.aspx</link><pubDate>Thu, 09 Jun 2005 01:44:30 GMT</pubDate><guid>http://sqlsecurity.com/Home/tabid/36/Default.aspx?ItemId=788</guid></item><item><title>Blog - SQL Server 2000 SP4 Released</title><description>In case you haven't heard by now SP4 for SQL Server 2000 has finally been released.  This release in...</description><link>http://sqlsecurity.com/Home/tabid/36/Default.aspx</link><pubDate>Tue, 10 May 2005 01:10:37 GMT</pubDate><guid>http://sqlsecurity.com/Home/tabid/36/Default.aspx?ItemId=787</guid></item><item><title>Blog - MSDN Article on Security in SQL Server 2005</title><description>Article by Don Kiely on the new security features of SQL Server 2005 and what it means for you.  Sub...</description><link>http://sqlsecurity.com/Home/tabid/36/Default.aspx</link><pubDate>Sat, 07 May 2005 03:31:14 GMT</pubDate><guid>http://sqlsecurity.com/Home/tabid/36/Default.aspx?ItemId=786</guid></item><item><title>Blog - Idera SQL Compliance Manager</title><description>Idera's SQL compliance manager provides a powerful auditing and compliance solution for Microsoft SQ...</description><link>http://sqlsecurity.com/Home/tabid/36/Default.aspx</link><pubDate>Fri, 22 Apr 2005 18:04:06 GMT</pubDate><guid>http://sqlsecurity.com/Home/tabid/36/Default.aspx?ItemId=785</guid></item><item><title>Blog - SQL Server 2005 Virtual Labs from Microsoft</title><description>Are you ready to experience SQL Server 2005? 

Announcing the launch of the SQL Server 2005 Virtua...</description><link>http://sqlsecurity.com/Home/tabid/36/Default.aspx</link><pubDate>Thu, 07 Apr 2005 14:38:41 GMT</pubDate><guid>http://sqlsecurity.com/Home/tabid/36/Default.aspx?ItemId=784</guid></item><item><title>Blog - WMSDE - Something else to keep our eyes on</title><description>Microsoft has released a special version of MSDE to be released with Windows Sharepoint Server and r...</description><link>http://sqlsecurity.com/Home/tabid/36/Default.aspx</link><pubDate>Mon, 28 Mar 2005 17:48:30 GMT</pubDate><guid>http://sqlsecurity.com/Home/tabid/36/Default.aspx?ItemId=781</guid></item><item><title>Blog - SUS - too hot!  WUS - too cold! WSUS - just right?</title><description>Microsoft has announced the release candidate open evaluation for the successor to Windows Update Se...</description><link>http://sqlsecurity.com/Home/tabid/36/Default.aspx</link><pubDate>Mon, 28 Mar 2005 17:41:02 GMT</pubDate><guid>http://sqlsecurity.com/Home/tabid/36/Default.aspx?ItemId=783</guid></item><item><title>Blog - Patching SQL Server Checklist at TechTarget</title><description>I just finished a two-part series on finding and patching SQL Servers in your organization for TechT...</description><link>http://sqlsecurity.com/Home/tabid/36/Default.aspx</link><pubDate>Mon, 28 Mar 2005 17:02:07 GMT</pubDate><guid>http://sqlsecurity.com/Home/tabid/36/Default.aspx?ItemId=782</guid></item><item><title>Blog - SQLRecon 1.0 Released</title><description>SQLRecon v1.0 has been released to the public as a free tool.  SQLRecon performs both active and pas...</description><link>http://sqlsecurity.com/Home/tabid/36/Default.aspx</link><pubDate>Tue, 22 Mar 2005 18:53:16 GMT</pubDate><guid>http://sqlsecurity.com/Home/tabid/36/Default.aspx?ItemId=779</guid></item><item><title>Blog - Chip Andrews a Founding Member of Special Ops Security, Inc.</title><description>In case you haven't figured it out by now, I've joined forces with some of my favorite IT  security ...</description><link>http://sqlsecurity.com/Home/tabid/36/Default.aspx</link><pubDate>Tue, 22 Mar 2005 16:49:36 GMT</pubDate><guid>http://sqlsecurity.com/Home/tabid/36/Default.aspx?ItemId=780</guid></item><item><title>Blog - Jimmers releases code to reveal DTS connection passwords</title><description>DTSConnPass - utility to decrypt DTS package Connection passwords.   If you export a DTS package as ...</description><link>http://sqlsecurity.com/Home/tabid/36/Default.aspx</link><pubDate>Wed, 02 Mar 2005 01:09:26 GMT</pubDate><guid>http://sqlsecurity.com/Home/tabid/36/Default.aspx?ItemId=778</guid></item><item><title>Blog - Debate on the security of stored procedures and parameterized queries</title><description>This debate occurred on TheServerSide.NET and the original poster was way off on this topic but the ...</description><link>http://sqlsecurity.com/Home/tabid/36/Default.aspx</link><pubDate>Thu, 24 Feb 2005 05:54:33 GMT</pubDate><guid>http://sqlsecurity.com/Home/tabid/36/Default.aspx?ItemId=777</guid></item><item><title>Blog - New SQL Server discovery tool "SQLRecon" to be released soon</title><description>In association with Special Ops Security, I will soon be releasing a tool called SQLRecon to the gen...</description><link>http://sqlsecurity.com/Home/tabid/36/Default.aspx</link><pubDate>Wed, 09 Feb 2005 19:02:33 GMT</pubDate><guid>http://sqlsecurity.com/Home/tabid/36/Default.aspx?ItemId=776</guid></item><item><title>Blog - SQL Server Brute Force Scanning Surge</title><description>According to ISC SANS, there have been a large number of SQL Server authentication brute force attem...</description><link>http://sqlsecurity.com/Home/tabid/36/Default.aspx</link><pubDate>Fri, 31 Dec 2004 12:14:14 GMT</pubDate><guid>http://sqlsecurity.com/Home/tabid/36/Default.aspx?ItemId=775</guid></item><item><title>Blog - Microsoft Webcast on SQL 2005 Security</title><description>Want a glimpse at some of the new security features in SQL Server 2005?  Check out this webcast - it...</description><link>http://sqlsecurity.com/Home/tabid/36/Default.aspx</link><pubDate>Thu, 09 Dec 2004 17:59:15 GMT</pubDate><guid>http://sqlsecurity.com/Home/tabid/36/Default.aspx?ItemId=774</guid></item><item><title>Blog - FxCop 1.312 Adds Check for SQL Injection</title><description>The FxCop tool from Microsoft, which scans .NET assemblies for various development flaws, has added ...</description><link>http://sqlsecurity.com/Home/tabid/36/Default.aspx</link><pubDate>Thu, 04 Nov 2004 20:44:24 GMT</pubDate><guid>http://sqlsecurity.com/Home/tabid/36/Default.aspx?ItemId=773</guid></item><item><title>Blog - New SQLSecurity Group Policy Template Project</title><description>I've started a new project concerning the construction of a custom administrative template for Group...</description><link>http://sqlsecurity.com/Home/tabid/36/Default.aspx</link><pubDate>Tue, 26 Oct 2004 18:20:05 GMT</pubDate><guid>http://sqlsecurity.com/Home/tabid/36/Default.aspx?ItemId=772</guid></item><item><title>Blog - Nicholas Petreley on Linux vs Windows Security</title><description>Why is this relevant to SQL Server you ask?  Well, in his discussion of Windows Design he uses the S...</description><link>http://sqlsecurity.com/Home/tabid/36/Default.aspx</link><pubDate>Fri, 22 Oct 2004 18:33:08 GMT</pubDate><guid>http://sqlsecurity.com/Home/tabid/36/Default.aspx?ItemId=771</guid></item><item><title>Blog - SQL Server Remains on the SANS Top 20 List</title><description>Despite the fact that most visitors think SQL Server security is improving (according to a recent no...</description><link>http://sqlsecurity.com/Home/tabid/36/Default.aspx</link><pubDate>Mon, 11 Oct 2004 23:44:35 GMT</pubDate><guid>http://sqlsecurity.com/Home/tabid/36/Default.aspx?ItemId=770</guid></item><item><title>Blog - Free MS Webcast on Runing MSSQL on XPSP2 </title><description>Microsoft is hosting a free webcast on resolving issues related to running SQL Server 2000 on XP SP2...</description><link>http://sqlsecurity.com/Home/tabid/36/Default.aspx</link><pubDate>Mon, 04 Oct 2004 15:00:54 GMT</pubDate><guid>http://sqlsecurity.com/Home/tabid/36/Default.aspx?ItemId=769</guid></item><item><title>Blog - SQL Server 7.0 Denial of Service Vulnerability</title><description>While I have seen no verification from Microsoft of this and have not tested it myself, a denial of ...</description><link>http://sqlsecurity.com/Home/tabid/36/Default.aspx</link><pubDate>Thu, 30 Sep 2004 20:49:22 GMT</pubDate><guid>http://sqlsecurity.com/Home/tabid/36/Default.aspx?ItemId=768</guid></item><item><title>Blog - Quiet Times in SQL Server Land</title><description>Let's face it - It's been real quiet in the world of SQL Server security as of late.  Not a lot of n...</description><link>http://sqlsecurity.com/Home/tabid/36/Default.aspx</link><pubDate>Fri, 17 Sep 2004 14:55:50 GMT</pubDate><guid>http://sqlsecurity.com/Home/tabid/36/Default.aspx?ItemId=767</guid></item><item><title>Blog - SQL Server 2005 Express Edition Replaces MSDE</title><description>According to MSDN, SQL Server 2005 Express Edition will replace MSDE as the free offering to get peo...</description><link>http://sqlsecurity.com/Home/tabid/36/Default.aspx</link><pubDate>Wed, 30 Jun 2004 11:55:02 GMT</pubDate><guid>http://sqlsecurity.com/Home/tabid/36/Default.aspx?ItemId=765</guid></item><item><title>Blog - Microsoft SQL Server Security Analyzer</title><description>Tool to inspect a SQL Server installation and compare its configurating against Microsoft's security...</description><link>http://sqlsecurity.com/Home/tabid/36/Default.aspx</link><pubDate>Fri, 25 Jun 2004 14:14:01 GMT</pubDate><guid>http://sqlsecurity.com/Home/tabid/36/Default.aspx?ItemId=764</guid></item><item><title>Blog - Windows XP SP2 and how it will affect SQL Server</title><description>Microsoft is warning you ahead of time of some changes that will take place in Windows XP Service Pa...</description><link>http://sqlsecurity.com/Home/tabid/36/Default.aspx</link><pubDate>Wed, 23 Jun 2004 17:54:07 GMT</pubDate><guid>http://sqlsecurity.com/Home/tabid/36/Default.aspx?ItemId=763</guid></item><item><title>Blog - SANS - SQL Server Scanning on the rise- beware</title><description>There is a disturbing report from SANS about some increased SQL Server scanning activity from what m...</description><link>http://sqlsecurity.com/Home/tabid/36/Default.aspx</link><pubDate>Tue, 01 Jun 2004 07:00:00 GMT</pubDate><guid>http://sqlsecurity.com/Home/tabid/36/Default.aspx?ItemId=766</guid></item><item><title>Blog - Slashdot Blog on new SQL Server Security Features in Yukon</title><description>There's a link on the Slashdot blog to an article with the details.  Plenty of humorous commentary o...</description><link>http://sqlsecurity.com/Home/tabid/36/Default.aspx</link><pubDate>Tue, 01 Jun 2004 07:00:00 GMT</pubDate><guid>http://sqlsecurity.com/Home/tabid/36/Default.aspx?ItemId=762</guid></item><item><title>Blog - Imperva Releases Whitepaper on SQL Injection Signatures Evasion</title><description>Some excellent technical analyses of how attacks might circumvent SQL Injection Signatures.  The con...</description><link>http://sqlsecurity.com/Home/tabid/36/Default.aspx</link><pubDate>Wed, 28 Apr 2004 15:37:35 GMT</pubDate><guid>http://sqlsecurity.com/Home/tabid/36/Default.aspx?ItemId=761</guid></item><item><title>Blog - Phatbot/Agobot/Gaobot May Use SQL Server for Injection</title><description>Looks like past flaws in SQL Server are part of a new variant of an existing worm now propogating.  ...</description><link>http://sqlsecurity.com/Home/tabid/36/Default.aspx</link><pubDate>Mon, 26 Apr 2004 04:06:06 GMT</pubDate><guid>http://sqlsecurity.com/Home/tabid/36/Default.aspx?ItemId=760</guid></item><item><title>Blog - Article from Jeremiah Grossman on SQL Injection </title><description>For anyone who's looking for an article on the subject of SQL Injection targeted at the layman, Jere...</description><link>http://sqlsecurity.com/Home/tabid/36/Default.aspx</link><pubDate>Tue, 06 Apr 2004 00:49:56 GMT</pubDate><guid>http://sqlsecurity.com/Home/tabid/36/Default.aspx?ItemId=759</guid></item><item><title>Blog - New Tool added - SQLVer - Enumerate SQL Server Versions</title><description>OK - this one's for those that want to get the version of a SQL Server instance withuot logging into...</description><link>http://sqlsecurity.com/Home/tabid/36/Default.aspx</link><pubDate>Fri, 27 Feb 2004 13:44:35 GMT</pubDate><guid>http://sqlsecurity.com/Home/tabid/36/Default.aspx?ItemId=756</guid></item><item><title>Blog - New!  Version Database Added to SQLSecurity.com</title><description>I've added a new tab for the SQL Server version database.  I'm especially glad to see this since it ...</description><link>http://sqlsecurity.com/Home/tabid/36/Default.aspx</link><pubDate>Sat, 31 Jan 2004 03:37:56 GMT</pubDate><guid>http://sqlsecurity.com/Home/tabid/36/Default.aspx?ItemId=755</guid></item><item><title>Blog - MSDE appears in Windows Update...Sort of</title><description>While I have yet to see the first instance of a SQL Server service pack or hotfix in Windows Update ...</description><link>http://sqlsecurity.com/Home/tabid/36/Default.aspx</link><pubDate>Thu, 22 Jan 2004 21:41:47 GMT</pubDate><guid>http://sqlsecurity.com/Home/tabid/36/Default.aspx?ItemId=754</guid></item><item><title>Blog - SQLSecurity.com has changed hosting providers</title><description>I want apologize in advance for any interruptions in service anyone may have endured as SQLSecurity....</description><link>http://sqlsecurity.com/Home/tabid/36/Default.aspx</link><pubDate>Tue, 20 Jan 2004 13:04:59 GMT</pubDate><guid>http://sqlsecurity.com/Home/tabid/36/Default.aspx?ItemId=753</guid></item><item><title>Blog - Remote MDAC Vulnerabilty using UDP 1434</title><description>New MDAC Vulnerability is a reverse spin on MS02-039 whereby a response to a discovery packet sent b...</description><link>http://sqlsecurity.com/Home/tabid/36/Default.aspx</link><pubDate>Wed, 14 Jan 2004 06:44:38 GMT</pubDate><guid>http://sqlsecurity.com/Home/tabid/36/Default.aspx?ItemId=752</guid></item><item><title>Blog - Here comes 2004!</title><description>In an effort to update the user interface and streamline future updates, I've ported the SQLSecurity...</description><link>http://sqlsecurity.com/Home/tabid/36/Default.aspx</link><pubDate>Mon, 29 Dec 2003 06:12:28 GMT</pubDate><guid>http://sqlsecurity.com/Home/tabid/36/Default.aspx?ItemId=751</guid></item></channel></rss>