<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Shawson&#039;s Code Blog &#187; Classic ASP</title>
	<atom:link href="http://codeblog.shawson.co.uk/category/classic-asp/feed/" rel="self" type="application/rss+xml" />
	<link>http://codeblog.shawson.co.uk</link>
	<description>development notes for my failing memory</description>
	<lastBuildDate>Wed, 01 Feb 2012 11:00:16 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>Classic ASP SQL Injection vulnerability analyser</title>
		<link>http://codeblog.shawson.co.uk/classic-asp-sql-injection-vulnerability-analyser/</link>
		<comments>http://codeblog.shawson.co.uk/classic-asp-sql-injection-vulnerability-analyser/#comments</comments>
		<pubDate>Fri, 24 Oct 2008 08:50:00 +0000</pubDate>
		<dc:creator></dc:creator>
				<category><![CDATA[.net]]></category>
		<category><![CDATA[Classic ASP]]></category>
		<category><![CDATA[SQL Server]]></category>

		<guid isPermaLink="false">http://www.shawson.co.uk/codeblog/post.aspx?id=1ace09c2-3b90-44f3-8c2f-22bc0c893e34</guid>
		<description><![CDATA[If, like me, you have a whole bunch of legacy sites written by someone else long before you joined the company all code bases of varying quality, then you may find this tool useful. I read an article on the register a while ago about a command line tool Microsoft have put together which analyses [...]


Related posts:<ul><li><a href='http://codeblog.shawson.co.uk/watin-testing-tools/' rel='bookmark' title='WatiN Testing Tools'>WatiN Testing Tools</a></li>
<li><a href='http://codeblog.shawson.co.uk/random-band-generator/' rel='bookmark' title='Random Band Generator!'>Random Band Generator!</a></li>
<li><a href='http://codeblog.shawson.co.uk/runaway-sharepoint-2003-indexing/' rel='bookmark' title='Runaway Sharepoint 2003 Indexing!'>Runaway Sharepoint 2003 Indexing!</a></li>
</ul>]]></description>
			<content:encoded><![CDATA[<p>
If, like me, you have a whole bunch of legacy sites written by someone else long before you joined the company all code bases of varying quality, then you may find this tool useful.  I read <a href="http://www.theregister.co.uk/2008/06/26/microsoft_hp_sql_injection_tools/" target="_blank" title="SQL Injection code analyser article on 'The Register'">an article</a> on <a href="http://www.theregister.co.uk" target="_blank">the register</a> a while ago about a command line tool Microsoft have put together which analyses Classic ASP code, and looks for vulnerabilities that leave your pages open to SQL injection attack.&nbsp;
</p>
<p>
Incase you are unfamiliar, <a href="http://www.securitydocs.com/library/2656" target="_blank">there is a good article up on securitydocs.com</a> exaplaining what a sql injection attack is and giving some practical examples on how they work and how easily they can be executed.
</p>
<p>
It seems to do this by looking at how your code deals with input accepted from the Request.Form and Request.Querystring and making sure it goes through some kind of filtering.&nbsp; Anyway- <a href="http://support.microsoft.com/kb/954476" target="_blank">have a butchers at the tool yourself</a>.  The article title is &quot;The Microsoft Source Code Analyzer for SQL Injection tool is available to find SQL injection vulnerabilities in ASP code&quot; and the applications name is &quot;msscasi_asp.exe&quot;- i only mention this as Microsoft seem to frequently reshuffle their pages breaking loads of links so you may some to this article and find just a 404 so this will allow you to do a site search!
</p>
<p>
The article also makes a mention of a similar tool created by HP called <a href="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2008/06/23/finding-sql-injection-with-scrawlr.aspx" target="_blank">scrawlr which is available here</a></p>


<p>Related posts:<ul><li><a href='http://codeblog.shawson.co.uk/watin-testing-tools/' rel='bookmark' title='WatiN Testing Tools'>WatiN Testing Tools</a></li>
<li><a href='http://codeblog.shawson.co.uk/random-band-generator/' rel='bookmark' title='Random Band Generator!'>Random Band Generator!</a></li>
<li><a href='http://codeblog.shawson.co.uk/runaway-sharepoint-2003-indexing/' rel='bookmark' title='Runaway Sharepoint 2003 Indexing!'>Runaway Sharepoint 2003 Indexing!</a></li>
</ul></p>]]></content:encoded>
			<wfw:commentRss>http://codeblog.shawson.co.uk/classic-asp-sql-injection-vulnerability-analyser/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

