Anonymous :anarchism: 🏴 · @YourAnonRiots
6070 followers · 37980 posts · Server mstdn.social

.NET developers: is there any indication that parameterized SQL queries using System.Data.SqlClient.SqlCommand do not protect against SQL injection?

A new developer on a project believes that it's necessary to detect and block parameterized queries if their parameters contain SQL keywords, otherwise the database can potentially execute them as SQL. I cannot find evidence of this, or reproduce it.

Do parameterized queries have known vulnerabilities?

#dotnet #sqlserver #sqlinjection

Last updated 1 year ago

Mr.Trunk · @mrtrunk
6 followers · 13177 posts · Server dromedary.seedoubleyou.me

SecurityOnline: jSQL Injection v0.91 releases: Java application for automatic SQL database injection securityonline.info/jsql-injec

#webapppentest #jsqlinjection #sqlinjection #sqli

Last updated 1 year ago

Mr.Trunk · @mrtrunk
4 followers · 7314 posts · Server dromedary.seedoubleyou.me

SecurityOnline: jSQL Injection v0.90 releases: Java application for automatic SQL database injection securityonline.info/jsql-injec

#webapppentest #jsqlinjection #sqlinjection #sqli

Last updated 1 year ago

Mr.Trunk · @mrtrunk
4 followers · 6951 posts · Server dromedary.seedoubleyou.me

SecurityOnline: jSQL Injection v0.89 releases: Java application for automatic SQL database injection securityonline.info/jsql-injec

#webapppentest #jsqlinjection #sqlinjection #sqli

Last updated 1 year ago

Mr.Trunk · @mrtrunk
5 followers · 6044 posts · Server dromedary.seedoubleyou.me

SecurityOnline: jSQL Injection v0.88 releases: Java application for automatic SQL database injection securityonline.info/jsql-injec

#webapppentest #jsqlinjection #sqlinjection #sqli

Last updated 1 year ago

Nerd-Enzyklopädie · @ne
4 followers · 12 posts · Server det.social
👾 Rene Rehme · @renereh1
665 followers · 147 posts · Server neos.social

It looks like an angle bracket is filtered on the backend. I need this operator for a time-based injection because there is no response output. Alternative filter evasion? .

#sqli #sqlinjection #payload #bugbounty #bugbountytiphelp

Last updated 1 year ago

ApisNecros · @ApisNecros
94 followers · 1029 posts · Server ioc.exchange

Been out of the game for a bit on account of life moving fast, but after only a couple hours I managed to find a completely transparent vuln on a target. After building a strong case, it's now reported. Feels good, man 💪

#sqlinjection #cybersecurity #infosec #hacking #hacktheplanet #bugbounty

Last updated 1 year ago

Tech news from Canada · @TechNews
790 followers · 21591 posts · Server mastodon.roitsystems.ca
IT News · @itnewsbot
3456 followers · 265882 posts · Server schleuss.online

MOVEit app mass-exploited last month patches new critical vulnerability - Enlarge (credit: Lino Mirgeler/picture alliance via Getty Images)

... - arstechnica.com/?p=1952233

#moveit #biz #exploits #security #sqlinjection #vulnerabilities

Last updated 1 year ago

LisPi · @lispi314
538 followers · 11497 posts · Server mastodon.top

@lewdthewides Wait what the fuck? en.wikipedia.org/wiki/2023_MOV

How in the hell do you still have vulnerable frontends in this day and age in government-used systems? Has no one heard of / (yay type-safety) and ? What, did they hire some intern with no supervision for writing a high-liability system?

#sqlinjection #preparedqueries #storedprocedures #sql #sqli #preparedstatements

Last updated 1 year ago

Nightfighter · @Optimus
42 followers · 1416 posts · Server social.tchncs.de

The 'Visforms Base Package for Joomla 3' is vulnerable to SQL Injection as concatenation is used to construct an SQL Query. An attacker can interact with the database and could be able to read, modify and delete data on it.
(CVE-2023-23753)

#sqlinjection #joomla #vulnerability #cve #extension

Last updated 1 year ago

ITSEC News · @itsecbot
1317 followers · 35675 posts · Server schleuss.online

MOVEit mayhem 3: “Disable HTTP and HTTPS traffic immediately” - Twice more unto the breach... patch being tested, in the meantime, shut down web access. nakedsecurity.sophos.com/2023/

#moveit #progress #sqlinjection #vulnerability

Last updated 1 year ago

FastRuby.io · @FastRuby
27 followers · 79 posts · Server ruby.social

⚠️ Got this warning upgrading your app? 👇

Don’t worry. Gelsey Torres explains through a step-by-step guide how to address the issue if you come across it in your codebase. 🔒

#rails #fastruby #UpgradeRails #sqlinjection #CISO

Last updated 1 year ago

heise Security · @heisec
10340 followers · 568 posts · Server social.heise.de

Cybersecurity-Bericht: Durchschnittlich 11.000 Sicherheitslücken in Unternehmen

Im Bereich Security hat Deutschland laut einem Bericht viel Nachholbedarf. Ein zur Schwarz-Gruppe gehörendes IT-Unternehmen stellt ein desaströses Zeugnis aus.

heise.de/news/Cybersecurity-Be

#darknet #security #sqlinjection #news

Last updated 1 year ago

Anonymous :anarchism: 🏴 · @YourAnonRiots
5625 followers · 35235 posts · Server mstdn.social

Attention! Multiple new vulnerabilities discovered in MOVEit Transfer, posing a risk of unauthorized access to the database.

thehackernews.com/2023/06/new-

Upgrade to the latest versions to protect sensitive information.

#InfoSec #CyberSecurity #sqlinjection

Last updated 1 year ago

fthy · @fthy
8 followers · 83 posts · Server mastodon.green

New MOVEit Transfer web application patch fixing multiple SQL Injection (CVE pending) community.progress.com/s/artic Affected MOVEit Transfer versions: before 2021.0.7 (13.0.7), 2021.1.5 (13.1.5), 2022.0.5 (14.0.5), 2022.1.6 (14.1.6), 2023.0.2 (15.0.2)

#vulnerability #infosec #moveit #rce #sqlinjection

Last updated 1 year ago

Salvatore Lombardo · @Slvlombardo
5 followers · 171 posts · Server mstdn.social
FastRuby.io · @FastRuby
18 followers · 39 posts · Server ruby.social

⚠️ Got this warning upgrading your app? 👇

Don’t worry. Gelsey Torres explains through a step-by-step guide how to address the issue if you come across it in your codebase. 🔒

#rails #fastruby #UpgradeRails #sqlinjection #CISO

Last updated 1 year ago