<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: SQL Injection Tangos with Heap Overflows</title>
	<atom:link href="http://www.veracode.com/blog/2008/12/sql-injection-tangos-with-heap-overflows/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.veracode.com/blog/2008/12/sql-injection-tangos-with-heap-overflows/</link>
	<description>Application security testing, analysis, and metrics</description>
	<lastBuildDate>Thu, 09 Feb 2012 11:59:00 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: links for 2008-12-17 (Jarrett House North)</title>
		<link>http://www.veracode.com/blog/2008/12/sql-injection-tangos-with-heap-overflows/comment-page-1/#comment-2404</link>
		<dc:creator>links for 2008-12-17 (Jarrett House North)</dc:creator>
		<pubDate>Thu, 18 Dec 2008 02:01:29 +0000</pubDate>
		<guid isPermaLink="false">http://www.veracode.com/blog/?p=513#comment-2404</guid>
		<description>[...] SQL Injection Tangos with Heap Overflows Multifactor vulnerabilities lead to massive exploits. The scary bit about this is that this points out that the 500,000 or so IIS servers that got hit with SQL injection attacks are, if they remain unpatched, fertile ground for exploiting just about any other vulnerability that comes around. (tags: security sqlinjection) [...]</description>
		<content:encoded><![CDATA[<p>[...] SQL Injection Tangos with Heap Overflows Multifactor vulnerabilities lead to massive exploits. The scary bit about this is that this points out that the 500,000 or so IIS servers that got hit with SQL injection attacks are, if they remain unpatched, fertile ground for exploiting just about any other vulnerability that comes around. (tags: security sqlinjection) [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Chris Wysopal</title>
		<link>http://www.veracode.com/blog/2008/12/sql-injection-tangos-with-heap-overflows/comment-page-1/#comment-2403</link>
		<dc:creator>Chris Wysopal</dc:creator>
		<pubDate>Thu, 18 Dec 2008 00:26:05 +0000</pubDate>
		<guid isPermaLink="false">http://www.veracode.com/blog/?p=513#comment-2403</guid>
		<description>@Miguel

Agreed.  Perhaps I should change the title to &quot;IE has a three way with SQL Injection and XSS&quot;.

-Chris</description>
		<content:encoded><![CDATA[<p>@Miguel</p>
<p>Agreed.  Perhaps I should change the title to &#8220;IE has a three way with SQL Injection and XSS&#8221;.</p>
<p>-Chris</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Miguel Correia</title>
		<link>http://www.veracode.com/blog/2008/12/sql-injection-tangos-with-heap-overflows/comment-page-1/#comment-2402</link>
		<dc:creator>Miguel Correia</dc:creator>
		<pubDate>Wed, 17 Dec 2008 18:29:51 +0000</pubDate>
		<guid isPermaLink="false">http://www.veracode.com/blog/?p=513#comment-2402</guid>
		<description>Great post. There is a third in the tango: cross-site scripting. This is a heap overflow attack, made using a stored cross-site scripting attack made with SQL injection. Yak!</description>
		<content:encoded><![CDATA[<p>Great post. There is a third in the tango: cross-site scripting. This is a heap overflow attack, made using a stored cross-site scripting attack made with SQL injection. Yak!</p>
]]></content:encoded>
	</item>
</channel>
</rss>

