<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Уязвимости в MySQL и SQL запросах</title>
	<atom:link href="http://www.simplecoding.org/uyazvimosti-v-mysql-i-sql-zaprosax.html/feed" rel="self" type="application/rss+xml" />
	<link>http://www.simplecoding.org/uyazvimosti-v-mysql-i-sql-zaprosax.html</link>
	<description>Блог о программировании</description>
	<lastBuildDate>Wed, 08 Feb 2012 08:50:00 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
	<item>
		<title>By: head Gr.</title>
		<link>http://www.simplecoding.org/uyazvimosti-v-mysql-i-sql-zaprosax.html#comment-20465</link>
		<dc:creator>head Gr.</dc:creator>
		<pubDate>Thu, 12 Jan 2012 09:30:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.simplecoding.org/?p=437#comment-20465</guid>
		<description>Ok, tnx.</description>
		<content:encoded><![CDATA[<p>Ok, tnx.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: broschüren</title>
		<link>http://www.simplecoding.org/uyazvimosti-v-mysql-i-sql-zaprosax.html#comment-20462</link>
		<dc:creator>broschüren</dc:creator>
		<pubDate>Wed, 11 Jan 2012 23:38:54 +0000</pubDate>
		<guid isPermaLink="false">http://www.simplecoding.org/?p=437#comment-20462</guid>
		<description>&lt;strong&gt;... [Trackback]...&lt;/strong&gt;

[...] Read More: simplecoding.org/uyazvimosti-v-mysql-i-sql-zaprosax.html [...]...</description>
		<content:encoded><![CDATA[<p><strong>&#8230; [Trackback]&#8230;</strong></p>
<p>[...] Read More: simplecoding.org/uyazvimosti-v-mysql-i-sql-zaprosax.html [...]&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: software security</title>
		<link>http://www.simplecoding.org/uyazvimosti-v-mysql-i-sql-zaprosax.html#comment-20461</link>
		<dc:creator>software security</dc:creator>
		<pubDate>Wed, 11 Jan 2012 23:24:40 +0000</pubDate>
		<guid isPermaLink="false">http://www.simplecoding.org/?p=437#comment-20461</guid>
		<description>&lt;strong&gt;... [Trackback]...&lt;/strong&gt;

[...] Read More: simplecoding.org/uyazvimosti-v-mysql-i-sql-zaprosax.html [...]...</description>
		<content:encoded><![CDATA[<p><strong>&#8230; [Trackback]&#8230;</strong></p>
<p>[...] Read More: simplecoding.org/uyazvimosti-v-mysql-i-sql-zaprosax.html [...]&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Владимир</title>
		<link>http://www.simplecoding.org/uyazvimosti-v-mysql-i-sql-zaprosax.html#comment-19885</link>
		<dc:creator>Владимир</dc:creator>
		<pubDate>Tue, 23 Aug 2011 07:25:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.simplecoding.org/?p=437#comment-19885</guid>
		<description>No. You should check login &amp; pass string length
if (strlen($login) &gt; 100) {
//hack attempt, 100 - size of according column in user table
}</description>
		<content:encoded><![CDATA[<p>No. You should check login &amp; pass string length<br />
if (strlen($login) &gt; 100) {<br />
//hack attempt, 100 &#8211; size of according column in user table<br />
}</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: head Gr.</title>
		<link>http://www.simplecoding.org/uyazvimosti-v-mysql-i-sql-zaprosax.html#comment-19884</link>
		<dc:creator>head Gr.</dc:creator>
		<pubDate>Mon, 22 Aug 2011 20:57:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.simplecoding.org/?p=437#comment-19884</guid>
		<description>addslashes
select id,pwd ... where login = $login
if md5($pass)  pwd // :)
getuserinfo &#039;select where id&#039;.

is enough?</description>
		<content:encoded><![CDATA[<p>addslashes<br />
select id,pwd &#8230; where login = $login<br />
if md5($pass)  pwd // <img src='http://www.simplecoding.org/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /><br />
getuserinfo &#039;select where id&#039;.</p>
<p>is enough?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: alibabaevich</title>
		<link>http://www.simplecoding.org/uyazvimosti-v-mysql-i-sql-zaprosax.html#comment-19587</link>
		<dc:creator>alibabaevich</dc:creator>
		<pubDate>Sun, 29 May 2011 16:46:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.simplecoding.org/?p=437#comment-19587</guid>
		<description>Спасибо! Очень полезно!</description>
		<content:encoded><![CDATA[<p>Спасибо! Очень полезно!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Svetsvetoch</title>
		<link>http://www.simplecoding.org/uyazvimosti-v-mysql-i-sql-zaprosax.html#comment-19553</link>
		<dc:creator>Svetsvetoch</dc:creator>
		<pubDate>Wed, 18 May 2011 06:00:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.simplecoding.org/?p=437#comment-19553</guid>
		<description>В дополнение:
Не надо определять права юзера только на основании логина.
Используйте для этого пару md5(логин.пароль)  </description>
		<content:encoded><![CDATA[<p>В дополнение:<br />
Не надо определять права юзера только на основании логина.<br />
Используйте для этого пару md5(логин.пароль) </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: AlexG</title>
		<link>http://www.simplecoding.org/uyazvimosti-v-mysql-i-sql-zaprosax.html#comment-11716</link>
		<dc:creator>AlexG</dc:creator>
		<pubDate>Fri, 03 Sep 2010 00:49:10 +0000</pubDate>
		<guid isPermaLink="false">http://www.simplecoding.org/?p=437#comment-11716</guid>
		<description>Статья супер</description>
		<content:encoded><![CDATA[<p>Статья супер</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Baragaru</title>
		<link>http://www.simplecoding.org/uyazvimosti-v-mysql-i-sql-zaprosax.html#comment-7851</link>
		<dc:creator>Baragaru</dc:creator>
		<pubDate>Sat, 19 Dec 2009 01:19:57 +0000</pubDate>
		<guid isPermaLink="false">http://www.simplecoding.org/?p=437#comment-7851</guid>
		<description>А задуматься стоит!
Спасибо!</description>
		<content:encoded><![CDATA[<p>А задуматься стоит!<br />
Спасибо!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Baragaru</title>
		<link>http://www.simplecoding.org/uyazvimosti-v-mysql-i-sql-zaprosax.html#comment-14686</link>
		<dc:creator>Baragaru</dc:creator>
		<pubDate>Sat, 19 Dec 2009 01:19:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.simplecoding.org/?p=437#comment-14686</guid>
		<description>А задуматься стоит!
Спасибо!</description>
		<content:encoded><![CDATA[<p>А задуматься стоит!<br />
Спасибо!</p>
]]></content:encoded>
	</item>
</channel>
</rss>

