<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.iis.net/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:cs="http://blogs.iis.net/"><channel><title>Filtering for SQL Injection on IIS 7 and later</title><link>http://blogs.iis.net/wadeh/archive/2008/12/18/filtering-for-sql-injection-on-iis-7-and-later.aspx</link><description>This article is specific to IIS 7 and later. If you are using IIS 6.0 or earlier, please see this article . Starting with version 7.0, IIS has a built-in feature that is able to filter HTTP requests. If a request is found to have contents deemed unacceptable</description><dc:language>en</dc:language><generator>CommunityServer 2007 SP1 (Build: 20510.895)</generator><item><title>chimpanzee attack: Filtering for SQL Injection in IIS7 &amp;laquo;  zycd.net.cn</title><link>http://blogs.iis.net/wadeh/archive/2008/12/18/filtering-for-sql-injection-on-iis-7-and-later.aspx#2966996</link><pubDate>Thu, 26 Feb 2009 02:13:54 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:2966996</guid><dc:creator>chimpanzee attack: Filtering for SQL Injection in IIS7 «  zycd.net.cn</dc:creator><description>&lt;p&gt;Pingback from &amp;nbsp;chimpanzee attack: Filtering for SQL Injection in IIS7 &amp;amp;laquo; &amp;nbsp;zycd.net.cn&lt;/p&gt;
&lt;img src="http://blogs.iis.net/aggbug.aspx?PostID=2966996" width="1" height="1"&gt;</description></item><item><title>re: Filtering for SQL Injection on IIS 7 and later</title><link>http://blogs.iis.net/wadeh/archive/2008/12/18/filtering-for-sql-injection-on-iis-7-and-later.aspx#2944940</link><pubDate>Mon, 16 Feb 2009 16:35:45 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:2944940</guid><dc:creator>daniele.baldessari</dc:creator><description>&lt;p&gt;Is a bug ? After apply the SQLInjection rule settings the querystring lenght is set at max 25 char. It's not possible overriding the setting with &amp;lt;requestlimits /&amp;gt;&lt;/p&gt;
&lt;p&gt;how can I do ?&lt;/p&gt;
&lt;img src="http://blogs.iis.net/aggbug.aspx?PostID=2944940" width="1" height="1"&gt;</description></item><item><title>Filtering for SQL Injection in IIS7</title><link>http://blogs.iis.net/wadeh/archive/2008/12/18/filtering-for-sql-injection-on-iis-7-and-later.aspx#2937714</link><pubDate>Thu, 12 Feb 2009 20:21:13 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:2937714</guid><dc:creator>wsspectacular</dc:creator><description>&lt;p&gt;One of the most common attacks against websites is a SQL Injection attack. What is a SQL Injection Attack&lt;/p&gt;
&lt;img src="http://blogs.iis.net/aggbug.aspx?PostID=2937714" width="1" height="1"&gt;</description></item><item><title>Filtering for SQL Injection on IIS 7 and later &amp;laquo; Aspwebhosting&amp;#8217;s Blog</title><link>http://blogs.iis.net/wadeh/archive/2008/12/18/filtering-for-sql-injection-on-iis-7-and-later.aspx#2836817</link><pubDate>Tue, 30 Dec 2008 02:26:33 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:2836817</guid><dc:creator>Filtering for SQL Injection on IIS 7 and later « Aspwebhosting’s Blog</dc:creator><description>&lt;p&gt;Pingback from &amp;nbsp;Filtering for SQL Injection on IIS 7 and later &amp;amp;laquo; Aspwebhosting&amp;amp;#8217;s Blog&lt;/p&gt;
&lt;img src="http://blogs.iis.net/aggbug.aspx?PostID=2836817" width="1" height="1"&gt;</description></item><item><title>Filtering for SQL Injection on IIS 6 and earlier : Wade Hilmo : The Official Microsoft IIS Site</title><link>http://blogs.iis.net/wadeh/archive/2008/12/18/filtering-for-sql-injection-on-iis-7-and-later.aspx#2824166</link><pubDate>Mon, 22 Dec 2008 10:50:52 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:2824166</guid><dc:creator>Filtering for SQL Injection on IIS 6 and earlier : Wade Hilmo : The Official Microsoft IIS Site</dc:creator><description>&lt;p&gt;Pingback from &amp;nbsp;Filtering for SQL Injection on IIS 6 and earlier : Wade Hilmo : The Official Microsoft IIS Site&lt;/p&gt;
&lt;img src="http://blogs.iis.net/aggbug.aspx?PostID=2824166" width="1" height="1"&gt;</description></item><item><title>How IIS can help with SQL Injection</title><link>http://blogs.iis.net/wadeh/archive/2008/12/18/filtering-for-sql-injection-on-iis-7-and-later.aspx#2821581</link><pubDate>Sat, 20 Dec 2008 08:18:35 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:2821581</guid><dc:creator>iis</dc:creator><description>&lt;p&gt;2008 has been a busy year for attackers exploiting SQL Injection vulnerabilities in web applications&lt;/p&gt;
&lt;img src="http://blogs.iis.net/aggbug.aspx?PostID=2821581" width="1" height="1"&gt;</description></item></channel></rss>