A while back I made a blog post about a video describing SQL Server Data Services here: Video: SQL Server Data Services Architecture

Channel 9 has posted another SQL Server Data Services video; in this one Group Program Manager Tudor Toma and Architect Soumitra Sengupta talk about the business value of SSDS. You can watch the video here: http://channel9.msdn.com/ShowPost.aspx?PostID=401696#401696

There are several formats including MP# if you just want to listen to it.


Posted by Denis Gobo, filed under Uncategorized. Date: May 2, 2008, 12:16 pm | No Comments »

I found this SQL Server Testing (not unit but vulnerability) page and decided I would post a link to it since it has some useful stuff. The link is below

http://www.owasp.org/index.php/Testing_for_SQL_Server

Here is what is covered. Enjoy (or live in fear over the weekend)


1 Brief Summary
2 Short Description of the Issue
3 Black Box testing and example
3.1 SQL Server Peculiarities
3.2 Example 1: Testing for SQL Injection in a GET request.
3.3 Example 2: Testing for SQL Injection in a GET request (2).
3.4 Example 3: Testing in a POST request
3.5 Example 4: Yet another (useful) GET example
3.6 Example 5: custom xp_cmdshell
3.7 Example 6: Referer / User-Agent
3.8 Example 7: SQL Server as a port scanner
3.9 Example 8: Upload of executables
3.10 Obtain information when it is not displayed (Out of band)
3.11 Blind SQL injection attacks
3.11.1 Trial and error
3.11.2 In case more than one error message is displayed
3.11.3 Timing attacks
3.11.4 Checking for version and vulnerabilities
3.12 Example 9: bruteforce of sysadmin password
4 References 


Posted by Denis Gobo, filed under Uncategorized. Date: May 2, 2008, 11:27 am | No Comments »


Search Engine Optimization and SEO Tools