<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Securing SQL Server</title>
	<atom:link href="http://securingsqlserver.com/feed" rel="self" type="application/rss+xml" />
	<link>http://securingsqlserver.com</link>
	<description>Protecting Your Database from Attackers</description>
	<lastBuildDate>Tue, 24 Apr 2012 21:33:08 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
		<item>
		<title>Securing SQL Server 2nd Edition Coming Soon</title>
		<link>http://securingsqlserver.com/securing-sql-server-2nd-edition-coming-soon</link>
		<comments>http://securingsqlserver.com/securing-sql-server-2nd-edition-coming-soon#comments</comments>
		<pubDate>Tue, 24 Apr 2012 21:13:59 +0000</pubDate>
		<dc:creator>mrdenny</dc:creator>
				<category><![CDATA[Amazon]]></category>
		<category><![CDATA[Securing SQL Server]]></category>
		<category><![CDATA[1597499471]]></category>
		<category><![CDATA[978-1597499477]]></category>
		<category><![CDATA[AlwaysOn Security]]></category>
		<category><![CDATA[Clustering Security]]></category>
		<category><![CDATA[Contained Databases]]></category>
		<category><![CDATA[Contained Logins]]></category>
		<category><![CDATA[Data Security]]></category>
		<category><![CDATA[Database Firewalls]]></category>
		<category><![CDATA[EXECUTE AS]]></category>
		<category><![CDATA[nstant File Initialization]]></category>
		<category><![CDATA[SAN Security]]></category>
		<category><![CDATA[Security SQL Server 2nd Edition]]></category>
		<category><![CDATA[SHA2]]></category>
		<category><![CDATA[SQL Injection]]></category>

		<guid isPermaLink="false">http://securingsqlserver.com/?p=108</guid>
		<description><![CDATA[I&#8217;m pleased to be able to announce that the 2nd edition of Securing SQL Server is going to be available soon.  It&#8217;s just been made available for pre-order on Amazon.com.  The second edition comes in at about 350 pages (according to Amazon, I don&#8217;t actually have a copy of it yet) while the first edition [...]]]></description>
			<content:encoded><![CDATA[<p>I&#8217;m pleased to be able to announce that the <a href="http://www.amazon.com/gp/product/1597499471/ref=as_li_ss_tl?ie=UTF8&amp;tag=sesqse-20&amp;linkCode=as2&amp;camp=1789&amp;creative=390957&amp;creativeASIN=1597499471">2nd edition of Securing SQL Server </a>is going to be available soon.  It&#8217;s just been made available for <a href="http://www.amazon.com/gp/product/1597499471/ref=as_li_ss_tl?ie=UTF8&amp;tag=sesqse-20&amp;linkCode=as2&amp;camp=1789&amp;creative=390957&amp;creativeASIN=1597499471">pre-order on Amazon.com</a>.  The second edition comes in at about 350 pages (according to Amazon, I don&#8217;t actually have a copy of it yet) while the first edition came in at about 270 pages so there has been a LOT of material added to the book.</p>
<p>While a lot of the new information is focused on SQL Server 2012, there is also a lot of new material which relates to older version of SQL Server including chapters on SQL Server Analysis Services and SQL Server Reporting Services, information on Instant File Initialization, EXECUTE AS, Database Firewalls, SAN Security, Actual Data Security (no idea how this got missed the first time around, but that&#8217;s to Brent Ozar for pointing it out).</p>
<p>As far as the SQL Server 2012 information you&#8217;ll find updated information about the SHA2 hashing algorithms, Securing AlwaysOn Availability Groups, Security and SQL Server Clustering, Security and Contained Databases and a lot more.</p>
<p>If you already have a copy of the 1st edition I encourage you to take a look at the second edition as well.  I know that it&#8217;s really soon for a second edition of a book (the first edition just came out February 2011, but this new edition comes on the release of SQL Server 2012.</p>
<p>Hopefully you <a href="http://www.amazon.com/gp/product/1597499471/ref=as_li_ss_tl?ie=UTF8&amp;tag=sesqse-20&amp;linkCode=as2&amp;camp=1789&amp;creative=390957&amp;creativeASIN=1597499471">pre-order</a> you copy today.</p>
<p>Denny</p>
<p>P.S. Yes this edition will be available for the Kindle as well, that takes a little time.  As soon as I know that it&#8217;s been posted for the Kindle (usually happens a little after Amazon gets the physical books) I&#8217;ll post another announcement here.</p>
<p>P.P.S. If you visit my <a href="http://www.securingsqlserver.com">SecuringSQLServer.com</a> site I&#8217;ve updated everything there for the new edition.  You can always find the old edition listed on the <a title="Other Books" href="http://securingsqlserver.com/other-books">Other Books</a> page on that site or on the <a href="http://mrdenny.com/books">Books </a>page on <a href="http://www.mrdenny.com">mrdenny.com</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://securingsqlserver.com/securing-sql-server-2nd-edition-coming-soon/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>180k+ websites attacked because of bad dev code</title>
		<link>http://securingsqlserver.com/180k-websites-attacked-because-of-bad-dev-code</link>
		<comments>http://securingsqlserver.com/180k-websites-attacked-because-of-bad-dev-code#comments</comments>
		<pubDate>Mon, 24 Oct 2011 21:36:46 +0000</pubDate>
		<dc:creator>mrdenny</dc:creator>
				<category><![CDATA[Securing SQL Server]]></category>
		<category><![CDATA[SQL Injection]]></category>

		<guid isPermaLink="false">http://securingsqlserver.com/?p=95</guid>
		<description><![CDATA[There is another massive SQL Injection attack going around. This time hitting 180k ASP.NET websites.  The article which I referenced has a decent write up on the actual attack and it links to a post which has detailed information about the attack.  However the article on IT World gives some really poor advice on how [...]]]></description>
			<content:encoded><![CDATA[<p>There is <a href="http://www.itworld.com/security/216125/powerful-simple-new-mass-sql-injection-attack-opens-180k-sites">another massive</a> SQL Injection attack going around. This time hitting 180k ASP.NET websites.  The article which I referenced has a decent write up on the actual attack and it links to a post which has detailed information about the <a href="http://snipt.net/armorize/decoded-httpjjghuicomurchinjs-mass-infection-script?key=7bcd613f2e43bb7fb4b53badc85c70ed">attack</a>.  However the article on IT World gives some really poor advice on how to protect yourself from a SQL Injection attack.</p>
<blockquote><p>There&#8217;s no easy way to fix the vulnerability of the database to this attack except to &#8220;harden&#8221; the database by applying all the patches and making all the security requirements consistent. Monitoring the database for unusual activity is important, too.</p></blockquote>
<p>Patching SQL Server will NOT prevent SQL Injection attack, at all.  The SQL Server isn&#8217;t the attack vector for a SQL Injection attack, the web application is the attack vector.  By the time the SQL Injection attack gets to the SQL Server database (or any database) it&#8217;s too late.</p>
<p>SQL Injection is actually really easy to protect yourself from.  Simply stop using dynamically generated SQL  and instead start using parametrized queries (also called bound queries).  That&#8217;s it, that&#8217;s the big secret.  Yes I understand that writing your .NET code as parametrized queries is harder to write than just doing string concatenation and running the query, but getting your site attacked and putting malware on your customers computers because you didn&#8217;t want to do a little typing is just no excuse.</p>
<p>As this is a blog about my book &#8220;<a href="http://rcm.amazon.com/e/cm?lt1=_blank&amp;bc1=000000&amp;IS2=1&amp;bg1=FFFFFF&amp;fc1=000000&amp;lc1=0000FF&amp;t=sesqse-20&amp;o=1&amp;p=8&amp;l=as4&amp;m=amazon&amp;f=ifr&amp;ref=ss_til&amp;asins=B004JHY9NE">Securing SQL Server</a>&#8221; here&#8217;s the sales pitch.  In the book I talk all about how to use parametrized queries.  It really isn&#8217;t that hard there is lots of sample code on how to do it.  You don&#8217;t need to use stored procedures to use parametrized queries.  You can do it with normal dynamic SQL as well, it works basically the same.</p>
<p>In case you didn&#8217;t get my point yet, parametrized queries are the ONLY WAY that you can 100% be sure that you are protecting yourself from SQL Injection attacks.  If you can&#8217;t find some links on how to use parametrized queries here are a few links for you <a href="http://blogs.msdn.com/b/sqlphp/archive/2008/09/30/how-and-why-to-use-parameterized-queries.aspx">PHP</a>, <a href="http://www.4guysfromrolla.com/webtech/092601-1.shtml">.NET</a>, and <a href="http://msdn.microsoft.com/en-us/magazine/cc163917.aspx">more .NET</a>.</p>
<p>Denny</p>
]]></content:encoded>
			<wfw:commentRss>http://securingsqlserver.com/180k-websites-attacked-because-of-bad-dev-code/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Exposing SQL Server to the public Internet is a pretty bad idea</title>
		<link>http://securingsqlserver.com/exposing-sql-server-to-the-public-internet-is-a-pretty-bad-idea</link>
		<comments>http://securingsqlserver.com/exposing-sql-server-to-the-public-internet-is-a-pretty-bad-idea#comments</comments>
		<pubDate>Tue, 23 Aug 2011 15:02:28 +0000</pubDate>
		<dc:creator>mrdenny</dc:creator>
				<category><![CDATA[Amazon]]></category>
		<category><![CDATA[Securing SQL Server]]></category>

		<guid isPermaLink="false">http://securingsqlserver.com/?p=90</guid>
		<description><![CDATA[Every once and a while we hear about the nightmare situation where a SQL Server has been broken into and data has been stolen. All to often when this happens because the SQL Server is exposed directly to the public Internet. When you ask people why the SQL Server is connected to the Internet the [...]]]></description>
			<content:encoded><![CDATA[<p>Every once and a while we hear about the nightmare situation where a SQL Server has been broken into and data has been stolen. All to often when this happens because the SQL Server is exposed directly to the public Internet. When you ask people why the SQL Server is connected to the Internet the answer is pretty much always the same, to make it easier to manage so that they don&#8217;t have to RDP to the server and manage it from there.</p>
<p>While this is easier, is sure isn&#8217;t the safest solution. A much better solution would be to setup a <a href="http://www.business.att.com/enterprise/Family/network-services/ip-vpn/">VPN Network</a> between the office and the data center so that the connection is secured so that people from the public Internet can&#8217;t access the SQL Server&#8217;s connection.  This will prevent people who aren&#8217;t supposed to be connecting to the SQL Server from connecting to the SQL Server.</p>
<p>I talk about this more in Chapter 1 of &#8220;Securing SQL Server&#8221;.  Check it out on <a href="http://www.amazon.com/gp/product/1597496251/ref=as_li_ss_tl?ie=UTF8&amp;tag=sesqse-20&amp;linkCode=as2&amp;camp=217145&amp;creative=399373&amp;creativeASIN=1597496251">Amazon</a>, which will actually let you read a good portion of Chapter 1 online for free.</p>
]]></content:encoded>
			<wfw:commentRss>http://securingsqlserver.com/exposing-sql-server-to-the-public-internet-is-a-pretty-bad-idea/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Meet the author, get your copy signed</title>
		<link>http://securingsqlserver.com/meet-the-author-get-your-copy-signed</link>
		<comments>http://securingsqlserver.com/meet-the-author-get-your-copy-signed#comments</comments>
		<pubDate>Wed, 27 Jul 2011 17:00:53 +0000</pubDate>
		<dc:creator>mrdenny</dc:creator>
				<category><![CDATA[Securing SQL Server]]></category>

		<guid isPermaLink="false">http://securingsqlserver.com/?p=86</guid>
		<description><![CDATA[There are several chances to meet the author of Securing SQL Server, ask questions, and get your copy of the book signed.  These include (and are subject to change): Dallas Tech Fest &#8211; August 13th, 2011 SQL PASS &#8211; October 11-14, 2011 SQL Saturday 95 &#8211; September 17th, 2011 SQL Excursions - May 17-19, 2012 [...]]]></description>
			<content:encoded><![CDATA[<p>There are several chances to meet the author of Securing SQL Server, ask questions, and get your copy of the book signed.  These include (and are subject to change):</p>
<p><a href="http://dallastechfest.com/">Dallas Tech Fest</a> &#8211; August 13th, 2011</p>
<p><a href="http://sqlpass.org">SQL PASS</a> &#8211; October 11-14, 2011</p>
<p><a href="http://www.sqlsaturday.com/95/eventhome.aspx">SQL Saturday 95</a> &#8211; September 17th, 2011</p>
<p><a href="http://www.sqlexcursions.com/">SQL Excursions </a>- May 17-19, 2012</p>
<p>I hope to see you at one (or all) of these great events.  Feel free to bring your copy and get it signed making it a priceless collectable (OK, probably not but I do love signing copies).</p>
<p>Denny</p>
]]></content:encoded>
			<wfw:commentRss>http://securingsqlserver.com/meet-the-author-get-your-copy-signed/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Want to take a look at Securing SQL Server for 30 days?</title>
		<link>http://securingsqlserver.com/want-to-take-a-look-at-securing-sql-server-for-30-days</link>
		<comments>http://securingsqlserver.com/want-to-take-a-look-at-securing-sql-server-for-30-days#comments</comments>
		<pubDate>Mon, 18 Jul 2011 23:08:16 +0000</pubDate>
		<dc:creator>mrdenny</dc:creator>
				<category><![CDATA[Amazon]]></category>
		<category><![CDATA[Kindle]]></category>
		<category><![CDATA[Securing SQL Server]]></category>

		<guid isPermaLink="false">http://securingsqlserver.com/?p=81</guid>
		<description><![CDATA[Thanks to Amazon, now you can rent Securing SQL Server for 30 days, and if you like it you can buy it with the cost of the rental being applied to the cost to buy the digital copy of the book.  This is all done through Amazon&#8217;s new ebook rental program for text books (which [...]]]></description>
			<content:encoded><![CDATA[<p>Thanks to Amazon, now you can rent <a href="http://www.amazon.com/gp/product/B004JHY9NE/ref=as_li_ss_tl?ie=UTF8&amp;tag=sesqse-20&amp;linkCode=as2&amp;camp=217145&amp;creative=399373&amp;creativeASIN=B004JHY9NE">Securing SQL Server for 30 days</a>, and if you like it you can buy it with the cost of the rental being applied to the cost to buy the digital copy of the book.  This is all done through Amazon&#8217;s new ebook rental program for text books (which they have marked my book as being).  So now you can rent the book starting at a little over 1/2 the current price of the book which gives you access to the entire book for 30 days.  After the 30 days is up you can extend your rental or purchase with the initial rental price counting towards your new price (you pay the difference).</p>
<p>As an author I&#8217;m not sure how I feel about this, good I guess because it gives people a chance to give the <a href="http://www.amazon.com/gp/product/B004JHY9NE/ref=as_li_ss_tl?ie=UTF8&amp;tag=sesqse-20&amp;linkCode=as2&amp;camp=217145&amp;creative=399373&amp;creativeASIN=B004JHY9NE">book a try</a>.  As a reader I like this because I can try the book for less, and if I like it keep it.  If it doesn&#8217;t serve me any purpose I don&#8217;t need to keep it, and it only cost be 1/2 the cash to find out.</p>
<p>You don&#8217;t need to have a Kindle to make use of this, just the Kindle app installed on your PC, phone, iPad, etc.</p>
<p>Denny</p>
]]></content:encoded>
			<wfw:commentRss>http://securingsqlserver.com/want-to-take-a-look-at-securing-sql-server-for-30-days/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Securing SQL Server will be available at the Tech Ed bookstore</title>
		<link>http://securingsqlserver.com/securing-sql-server-will-be-available-at-the-tech-ed-bookstore</link>
		<comments>http://securingsqlserver.com/securing-sql-server-will-be-available-at-the-tech-ed-bookstore#comments</comments>
		<pubDate>Wed, 04 May 2011 19:32:07 +0000</pubDate>
		<dc:creator>mrdenny</dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Securing SQL Server]]></category>
		<category><![CDATA[Tech Ed]]></category>

		<guid isPermaLink="false">http://securingsqlserver.com/?p=78</guid>
		<description><![CDATA[If you are going to Tech Ed 2011, and you were thinking about purchasing a copy of &#8220;Securing SQL Server&#8221; but you wanted to thumb through it before purchasing, now is your chance.  I&#8217;ve just be told that the Tech Ed book store will be stocking &#8220;Securing SQL Server&#8221;.  If you pick up a copy [...]]]></description>
			<content:encoded><![CDATA[<p>If you are going to Tech Ed 2011, and you were thinking about purchasing a copy of &#8220;Securing SQL Server&#8221; but you wanted to thumb through it before purchasing, now is your chance.  I&#8217;ve just be told that the Tech Ed book store will be stocking &#8220;Securing SQL Server&#8221;.  If you pick up a copy at Tech Ed and you want it signed I&#8217;ll be working at the SQL Server booth most afternoons.  Bring it on by, and I&#8217;ll be happy to sign it for you or at least draw funny faces in it.</p>
<p>Denny</p>
]]></content:encoded>
			<wfw:commentRss>http://securingsqlserver.com/securing-sql-server-will-be-available-at-the-tech-ed-bookstore/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Looks like MySQL isn&#8217;t the only company to be succeptable to a SQL Injection Attack (looking at you Barracuda)</title>
		<link>http://securingsqlserver.com/looks-like-mysql-isnt-the-only-company-to-be-succeptable-to-a-sql-injection-attack-looking-at-you-barracuda</link>
		<comments>http://securingsqlserver.com/looks-like-mysql-isnt-the-only-company-to-be-succeptable-to-a-sql-injection-attack-looking-at-you-barracuda#comments</comments>
		<pubDate>Tue, 12 Apr 2011 18:46:53 +0000</pubDate>
		<dc:creator>mrdenny</dc:creator>
				<category><![CDATA[Securing SQL Server]]></category>
		<category><![CDATA[Barracuda]]></category>
		<category><![CDATA[CNET]]></category>
		<category><![CDATA[SQL Injection]]></category>

		<guid isPermaLink="false">http://securingsqlserver.com/?p=75</guid>
		<description><![CDATA[Apparently Barracuda (who is in the network security business) had one of their applications broken into this week as reported by CNet.  While no source code was stolen from Barracuda, it still has to be embarrassing to have names and email addresses of employees, leads and partners to be downloaded all thanks to a poorly [...]]]></description>
			<content:encoded><![CDATA[<p>Apparently Barracuda (who is in the network security business) had one of their applications broken into<a href="http://news.cnet.com/8301-1009_3-20053125-83.html?part=rss&amp;tag=feed&amp;subj=News-Security"> this week</a> as reported by CNet.  While no source code was stolen from Barracuda, it still has to be embarrassing to have names and email addresses of employees, leads and partners to be downloaded all thanks to a poorly written PHP application.  Passwords were also downloaded as part of the data dump, but the passwords were only stored as MD5 hashes.  However MD5 isn&#8217;t considered to be very secure any more (which is one of the reasons that SQL Server &#8220;Denali&#8221; is including SHA2 which is still considered to be secure).</p>
<p>Apparently the website which was attacked is normally secured using a Barracuda Web Application Firewall, but it was taken offline during a maintenance window on Friday night (April 8th, 2011).  On Saturday night at about 5pm a script being crawling the website looking for SQL Injection weaknesses, which is found about two hours later.</p>
<p>Sadly this isn&#8217;t the first SQL Injection attack to happen recently.  Just a couple of weeks ago MySQL.com&#8217;s <a href="http://securingsqlserver.com/mysql-com-compromised-via-sql-injection-attack-someone-should-have-read-chapter-6">website was attacked</a> also using SQL Injection and a large amount of information was taken from their database as well.</p>
<p>You can read more about the Barracuda breach on <a href="http://news.cnet.com/8301-1009_3-20053125-83.html?part=rss&amp;tag=feed&amp;subj=News-Security">CNet </a>or on Barracuda&#8217;s <a href="http://www.barracudalabs.com/wordpress/index.php/2011/04/11/learning-the-importance-of-waf-technology-the-hard-way/">own blog</a>.</p>
<p>Denny</p>
]]></content:encoded>
			<wfw:commentRss>http://securingsqlserver.com/looks-like-mysql-isnt-the-only-company-to-be-succeptable-to-a-sql-injection-attack-looking-at-you-barracuda/feed</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Securing SQL Server is available at #DevConnections / #SQLConections</title>
		<link>http://securingsqlserver.com/securing-sql-server-is-available-at-devconnections-sqlconections</link>
		<comments>http://securingsqlserver.com/securing-sql-server-is-available-at-devconnections-sqlconections#comments</comments>
		<pubDate>Tue, 29 Mar 2011 17:55:10 +0000</pubDate>
		<dc:creator>mrdenny</dc:creator>
				<category><![CDATA[Securing SQL Server]]></category>
		<category><![CDATA[Dev Connections]]></category>
		<category><![CDATA[SQL Connections]]></category>

		<guid isPermaLink="false">http://securingsqlserver.com/?p=70</guid>
		<description><![CDATA[If you are at the Dev Connections / SQL Connections conference and wanted to pick up a copy of &#8220;Securing SQL Server&#8221; it is available at the Dev Connections book store over by the check in booth. Denny]]></description>
			<content:encoded><![CDATA[<p>If you are at the Dev Connections / SQL Connections conference and wanted to pick up a copy of &#8220;Securing SQL Server&#8221; it is available at the Dev Connections book store over by the check in booth.</p>
<p>Denny</p>
]]></content:encoded>
			<wfw:commentRss>http://securingsqlserver.com/securing-sql-server-is-available-at-devconnections-sqlconections/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>MySQL.com compromised via SQL Injection attack. Someone should have read Chapter 6.</title>
		<link>http://securingsqlserver.com/mysql-com-compromised-via-sql-injection-attack-someone-should-have-read-chapter-6</link>
		<comments>http://securingsqlserver.com/mysql-com-compromised-via-sql-injection-attack-someone-should-have-read-chapter-6#comments</comments>
		<pubDate>Sun, 27 Mar 2011 19:39:43 +0000</pubDate>
		<dc:creator>mrdenny</dc:creator>
				<category><![CDATA[Securing SQL Server]]></category>
		<category><![CDATA[MySql.com]]></category>
		<category><![CDATA[SQL Injection]]></category>

		<guid isPermaLink="false">http://securingsqlserver.com/?p=62</guid>
		<description><![CDATA[For those of you that were wondering, SQL Server isn&#8217;t the only platform which can be attacked via a SQL Injection attack.  Apparently the MySQL.com website which hosts the official distribution channel for the MySQL database platform was attacked using good old SQL Injection earlier today (notice sent out via seclists.org including their schema). Often [...]]]></description>
			<content:encoded><![CDATA[<p>For those of you that were wondering, SQL Server isn&#8217;t the only platform which can be attacked via a SQL Injection attack.  Apparently the MySQL.com website which hosts the official distribution channel for the MySQL database platform was attacked using good old SQL Injection earlier today (<a href="http://seclists.org/fulldisclosure/2011/Mar/309?utm_source=twitterfeed&amp;utm_medium=twitter">notice sent</a> out via seclists.org including their schema).</p>
<p>Often I hear from MySQL professionals that MySQL isn&#8217;t susceptible to SQL Injection attacks.  Apparently not only is it susceptible to SQL Injection attacks, but the company that writes the MySQL engine can&#8217;t correctly secure their website from being attacked.  According to <a href="http://blog.sucuri.net/2011/03/mysql-com-compromised.html">sucuri.net</a> the &#8220;customer view application was used as the entry point, where the  attackers were able to list the internal databases, tables and password  dump…&#8221;.  Not only was the password dump captured and posted only, but people have begun <a href="http://pastebin.com/BayvYdcP">cracking</a> the passwords, and some of these passwords are stupidly simple.  The account sysadm (which I assume is pretty important) has a password of &#8220;qa&#8221;.</p>
<p>Apparently the Director or Product Management (who has 20+ years experience with most database platforms) used a 4 digit numeric password (probably his ATM pin code) as his password.</p>
<p>Needless to say, if you have an account on mysql.com and you use that password anywhere, you should probably change that password anywhere else that you use it.</p>
<p>If you think that your application is susceptible to SQL Injection attack, I recommend chapter 6 (SQL Injection Attacks) of &#8220;<a href="http://www.amazon.com/gp/product/1597496251/ref=as_li_ss_tl?ie=UTF8&amp;tag=sesqse-20&amp;linkCode=as2&amp;camp=1789&amp;creative=390957&amp;creativeASIN=1597496251">Securing SQL Server</a>&#8221; which talks about how to prevent SQL Injection attacks.  The examples which I provide are not SQL Server specific and the techniques shown to prevent SQL Injection attacks can be used against pretty much any relational database platform.</p>
<p>Denny</p>
<p>UPDATE (1pm PST 2011/03/27): Apparently the SSL certificate for logging into the MySQL.com website expired a month ago.  The reason that I found this was that I was going to try and log in with my normal passwords (I&#8217;m pretty sure I have a mysql.com account) but with this error message, I&#8217;m not so sure about that.  It&#8217;s probably OK, but still&#8230;</p>
<p><a href="http://securingsqlserver.com/wp-content/uploads/2011/03/expired.png"><img class="alignleft size-full wp-image-65" title="expired" src="http://securingsqlserver.com/wp-content/uploads/2011/03/expired.png" alt="" width="354" height="126" /></a></p>
]]></content:encoded>
			<wfw:commentRss>http://securingsqlserver.com/mysql-com-compromised-via-sql-injection-attack-someone-should-have-read-chapter-6/feed</wfw:commentRss>
		<slash:comments>13</slash:comments>
		</item>
		<item>
		<title>Sean and Jen McCown talk about &#8220;Securing SQL Server&#8221; on their show.</title>
		<link>http://securingsqlserver.com/sean-and-jen-mccown-talk-about-securing-sql-server-on-their-show</link>
		<comments>http://securingsqlserver.com/sean-and-jen-mccown-talk-about-securing-sql-server-on-their-show#comments</comments>
		<pubDate>Sat, 26 Mar 2011 15:45:25 +0000</pubDate>
		<dc:creator>mrdenny</dc:creator>
				<category><![CDATA[Review Link]]></category>
		<category><![CDATA[Securing SQL Server]]></category>
		<category><![CDATA[Book Review]]></category>
		<category><![CDATA[Jen McCown]]></category>
		<category><![CDATA[MidnightDBA]]></category>
		<category><![CDATA[Sean McCown]]></category>

		<guid isPermaLink="false">http://securingsqlserver.com/?p=60</guid>
		<description><![CDATA[A couple of weeks ago Sean and Jen McCown (twitter &#124; Sean&#8217;s Blog &#124; Jen&#8217;s Blog) talked about &#8220;Securing SQL Server&#8221; on their DBAs@Midnight web show.  While this isn&#8217;t a full review, they got the book about six hours before the recorded the show, it does give you a little insight into the book.  Sean [...]]]></description>
			<content:encoded><![CDATA[<p>A couple of weeks ago Sean and Jen McCown (<a href="http://twitter.com/#!/midnightdba">twitter</a> | <a href="http://www.midnightdba.com/DBARant/">Sean&#8217;s Blog</a> | <a href="http://www.midnightdba.com/Jen/">Jen&#8217;s Blog</a>) talked about &#8220;<a title="Amazon Page for Securing SQL Server" href="http://www.amazon.com/gp/product/1597496251/ref=as_li_ss_tl?ie=UTF8&amp;tag=sesqse-20&amp;linkCode=as2&amp;camp=1789&amp;creative=390957&amp;creativeASIN=1597496251">Securing SQL Server</a>&#8221; on their <a href="http://midnightdba.itbookworm.com/DBAs@Midnight.aspx">DBAs@Midnight</a> web show.  While this isn&#8217;t a full review, they got the book about six hours before the recorded the show, it does give you a little insight into the book.  Sean was able to read a couple of the sections before he recorded the show, and his response to the book was pretty positive.</p>
<p>Apparently there are a couple of spelling errors that he&#8217;s found so far (I already know about the one in the dedication which he didn&#8217;t mention), but if those are the biggest problem that he finds with the book I&#8217;m doing pretty good.</p>
<p>You can download the video from the <a href="http://midnightdba.itbookworm.com/VidPages/DBAsAtMidnightGetAwayFromMe/DBAsAtMidnightGetAwayFromMe.aspx">DBAs@Midnight &#8211; Get Away From Me</a> web page on their site.  They start talking about the book at 34 minutes into the video, and they are done at about the 42 minute mark.  Sean said that he&#8217;ll be doing a full review of the book on their <a href="http://www.itbookworm.com/">IT Bookworm</a> book review site.  If his full review is as positive as this video was, I&#8217;ll be a very happy book writer.</p>
<p>Denny</p>
]]></content:encoded>
			<wfw:commentRss>http://securingsqlserver.com/sean-and-jen-mccown-talk-about-securing-sql-server-on-their-show/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

