<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Unu Cracks a Wall Street Journal Conference Site, Not WSJ.com</title>
	<atom:link href="http://praetorianprefect.com/archives/2009/12/unu-cracks-a-wall-street-journal-conference-site-not-wsj-com/feed/" rel="self" type="application/rss+xml" />
	<link>http://praetorianprefect.com/archives/2009/12/unu-cracks-a-wall-street-journal-conference-site-not-wsj-com/</link>
	<description>Information security, a little slower...a little deeper</description>
	<lastBuildDate>Thu, 29 Jul 2010 21:18:11 -0400</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Jacqulyn Seeds</title>
		<link>http://praetorianprefect.com/archives/2009/12/unu-cracks-a-wall-street-journal-conference-site-not-wsj-com/comment-page-1/#comment-11680</link>
		<dc:creator>Jacqulyn Seeds</dc:creator>
		<pubDate>Thu, 15 Jul 2010 01:55:30 +0000</pubDate>
		<guid isPermaLink="false">http://praetorianprefect.com/?p=1966#comment-11680</guid>
		<description>&lt;p&gt;We really enjoy what you write about here. We try and visit your blog every day so keep up the good writing!&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>We really enjoy what you write about here. We try and visit your blog every day so keep up the good writing!</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Praetorian Prefect &#124; Intel Breach Reveals Passport Information</title>
		<link>http://praetorianprefect.com/archives/2009/12/unu-cracks-a-wall-street-journal-conference-site-not-wsj-com/comment-page-1/#comment-4598</link>
		<dc:creator>Praetorian Prefect &#124; Intel Breach Reveals Passport Information</dc:creator>
		<pubDate>Wed, 23 Dec 2009 05:28:11 +0000</pubDate>
		<guid isPermaLink="false">http://praetorianprefect.com/?p=1966#comment-4598</guid>
		<description>&lt;p&gt;[...] vulnerabilities on major sites including recently two Kaspersky international properties and a Wall Street Journal conference site has demonstrated an attack on an Intel web property, [...]&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>[...] vulnerabilities on major sites including recently two Kaspersky international properties and a Wall Street Journal conference site has demonstrated an attack on an Intel web property, [...]</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Prefect</title>
		<link>http://praetorianprefect.com/archives/2009/12/unu-cracks-a-wall-street-journal-conference-site-not-wsj-com/comment-page-1/#comment-3842</link>
		<dc:creator>Prefect</dc:creator>
		<pubDate>Sun, 06 Dec 2009 22:26:09 +0000</pubDate>
		<guid isPermaLink="false">http://praetorianprefect.com/?p=1966#comment-3842</guid>
		<description>&lt;p&gt;Dave -
Well, its a good tool for finding SQL Injections on MySQL. The pattern of requesting concat(user,0×3a,host,0×3a,password) matches what the schemafuzz tool does. The ordering, check for load_file first, is how the schemafuzz tool works also. That said, we can&#039;t guarantee it was that tool, we just think it was, so we mention it.&lt;/p&gt;

&lt;p&gt;Now that we answered your question, can you answer one for us?&lt;/p&gt;

&lt;p&gt;Why do learning disabled jackasses post comments on blog posts asking stupid questions and making asinine suggestions?&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Dave -
Well, its a good tool for finding SQL Injections on MySQL. The pattern of requesting concat(user,0×3a,host,0×3a,password) matches what the schemafuzz tool does. The ordering, check for load_file first, is how the schemafuzz tool works also. That said, we can&#8217;t guarantee it was that tool, we just think it was, so we mention it.</p>

<p>Now that we answered your question, can you answer one for us?</p>

<p>Why do learning disabled jackasses post comments on blog posts asking stupid questions and making asinine suggestions?</p>]]></content:encoded>
	</item>
	<item>
		<title>By: DAve</title>
		<link>http://praetorianprefect.com/archives/2009/12/unu-cracks-a-wall-street-journal-conference-site-not-wsj-com/comment-page-1/#comment-3702</link>
		<dc:creator>DAve</dc:creator>
		<pubDate>Sat, 05 Dec 2009 20:36:50 +0000</pubDate>
		<guid isPermaLink="false">http://praetorianprefect.com/?p=1966#comment-3702</guid>
		<description>&lt;p&gt;&quot;What tool did Unu use to find this SQL Injection vulnerability? It could be rsauron’s schemafuzz.py based on the ordering of the screenshots Unu provided and the way the URL is constructed in those screenshots&quot;&lt;/p&gt;

&lt;p&gt;Why u talk if you don&#039;t know ? :)
Please ,shut up.&lt;/p&gt;

&lt;p&gt;P.S.: I was dropped on my head as a child.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>&#8220;What tool did Unu use to find this SQL Injection vulnerability? It could be rsauron’s schemafuzz.py based on the ordering of the screenshots Unu provided and the way the URL is constructed in those screenshots&#8221;</p>

<p>Why u talk if you don&#8217;t know ? :)
Please ,shut up.</p>

<p>P.S.: I was dropped on my head as a child.</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Steve R</title>
		<link>http://praetorianprefect.com/archives/2009/12/unu-cracks-a-wall-street-journal-conference-site-not-wsj-com/comment-page-1/#comment-3506</link>
		<dc:creator>Steve R</dc:creator>
		<pubDate>Fri, 04 Dec 2009 14:09:47 +0000</pubDate>
		<guid isPermaLink="false">http://praetorianprefect.com/?p=1966#comment-3506</guid>
		<description>&lt;p&gt;Nice breakdown. I&#039;m still waiting from the WSJ communications people to get back to me. However, like before, I&#039;m going to move your comment up to the article as a brief update.&lt;/p&gt;

&lt;p&gt;-Steve&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Nice breakdown. I&#8217;m still waiting from the WSJ communications people to get back to me. However, like before, I&#8217;m going to move your comment up to the article as a brief update.</p>

<p>-Steve</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Rob</title>
		<link>http://praetorianprefect.com/archives/2009/12/unu-cracks-a-wall-street-journal-conference-site-not-wsj-com/comment-page-1/#comment-3489</link>
		<dc:creator>Rob</dc:creator>
		<pubDate>Fri, 04 Dec 2009 11:33:54 +0000</pubDate>
		<guid isPermaLink="false">http://praetorianprefect.com/?p=1966#comment-3489</guid>
		<description>&lt;p&gt;Great analysis &amp; absence of hyperbole for a pretty high profile site hack. Thanks.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Great analysis &amp; absence of hyperbole for a pretty high profile site hack. Thanks.</p>]]></content:encoded>
	</item>
</channel>
</rss>
