<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:creativeCommons="http://backend.userland.com/creativeCommonsRssModule"
	>
<channel>
	<title>Comments on: &#8220;All Injection Attack Vectors&#8221;</title>
	<atom:link href="http://isisblogs.poly.edu/2007/02/08/all-injection-attack-vectors/feed/" rel="self" type="application/rss+xml" />
	<link>http://isisblogs.poly.edu/2007/02/08/all-injection-attack-vectors/</link>
	<description>Information Systems and Internet Security</description>
	<lastBuildDate>Sat, 26 Sep 2009 11:11:21 -0400</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.5</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Dan Guido</title>
		<link>http://isisblogs.poly.edu/2007/02/08/all-injection-attack-vectors/comment-page-1/#comment-5</link>
		<dc:creator>Dan Guido</dc:creator>
		<pubDate>Thu, 08 Feb 2007 06:47:33 +0000</pubDate>
		<guid isPermaLink="false">http://isisblogs.poly.edu/2007/02/08/all-injection-attack-vectors/#comment-5</guid>
		<description>Your link to elharo.com seems down at the moment, but at least for the XML injection... iSEC Partners have been doing quality XML injection work for the past few years with lots of it showing up at Blackhat and Defcon.  Just check https://www.isecpartners.com/speaking.html for &quot;Breaking AJAX Web Applications: Vulns 2.0 in Web 2.0.&quot;</description>
		<content:encoded><![CDATA[<p>Your link to elharo.com seems down at the moment, but at least for the XML injection&#8230; iSEC Partners have been doing quality XML injection work for the past few years with lots of it showing up at Blackhat and Defcon.  Just check <a href="https://www.isecpartners.com/speaking.html" rel="nofollow">https://www.isecpartners.com/speaking.html</a> for &#8220;Breaking AJAX Web Applications: Vulns 2.0 in Web 2.0.&#8221;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Yan Ivnitskiy</title>
		<link>http://isisblogs.poly.edu/2007/02/08/all-injection-attack-vectors/comment-page-1/#comment-4</link>
		<dc:creator>Yan Ivnitskiy</dc:creator>
		<pubDate>Thu, 08 Feb 2007 05:32:37 +0000</pubDate>
		<guid isPermaLink="false">http://isisblogs.poly.edu/2007/02/08/all-injection-attack-vectors/#comment-4</guid>
		<description>When one talks about a SQL injection, the only thing that makes it an &#039;injection&#039; is that it&#039;s in the SQL domain. When we inject code into some pre-rendered HTML it&#039;s a cross site scripting attack. When we overflow a buffer of machine code, we&#039;re overflowing the buffer. In reality, in all of these cases we are simply mixing the data with the control channel and assigning each variation a different name.

You can argue that the majority of security issues deal with this unclear separation of data and control, we just end up giving it a new buzzword every time we reference it. After all, saying a &quot;SQL overflow&quot; is too ambiguous, or a &quot;HTML injection&quot; is at the danger of just sounding lame :P</description>
		<content:encoded><![CDATA[<p>When one talks about a SQL injection, the only thing that makes it an &#8216;injection&#8217; is that it&#8217;s in the SQL domain. When we inject code into some pre-rendered HTML it&#8217;s a cross site scripting attack. When we overflow a buffer of machine code, we&#8217;re overflowing the buffer. In reality, in all of these cases we are simply mixing the data with the control channel and assigning each variation a different name.</p>
<p>You can argue that the majority of security issues deal with this unclear separation of data and control, we just end up giving it a new buzzword every time we reference it. After all, saying a &#8220;SQL overflow&#8221; is too ambiguous, or a &#8220;HTML injection&#8221; is at the danger of just sounding lame <img src='http://isisblogs.poly.edu/wp-includes/images/smilies/icon_razz.gif' alt=':P' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
</channel>
</rss>
