<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Blind SQL Haxoring</title>
	<atom:link href="http://dcortesi.com/2005/09/03/blind-sql-haxoring/feed/" rel="self" type="application/rss+xml" />
	<link>http://dcortesi.com/2005/09/03/blind-sql-haxoring/</link>
	<description>Coding, Security, and maybe a little bit about Damon Cortesi</description>
	<pubDate>Thu, 20 Nov 2008 11:47:23 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.2</generator>
		<item>
		<title>By: Damon</title>
		<link>http://dcortesi.com/2005/09/03/blind-sql-haxoring/#comment-2482</link>
		<dc:creator>Damon</dc:creator>
		<pubDate>Tue, 06 Sep 2005 23:32:19 +0000</pubDate>
		<guid isPermaLink="false">http://dcortesi.com/2005/09/03/blind-sql-haxoring/#comment-2482</guid>
		<description>I should clarify for the ID query process - there were 343 tables and Absinthe was actually going through two proxies as well as over HTTPS.  Thus, there were several contributing factors that made that process slower than normal.</description>
		<content:encoded><![CDATA[<p>I should clarify for the ID query process - there were 343 tables and Absinthe was actually going through two proxies as well as over HTTPS.  Thus, there were several contributing factors that made that process slower than normal.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: nummish</title>
		<link>http://dcortesi.com/2005/09/03/blind-sql-haxoring/#comment-2481</link>
		<dc:creator>nummish</dc:creator>
		<pubDate>Tue, 06 Sep 2005 18:58:15 +0000</pubDate>
		<guid isPermaLink="false">http://dcortesi.com/2005/09/03/blind-sql-haxoring/#comment-2481</guid>
		<description>To be honest, nobody has ever suggested that before, and it was probably overlooked when I first wrote it. They are sorted as it's pulled out, so it shouldn't be too big a deal to add to the next release.

As for the 24 hours and still querying IDs.. how many tables were in that schema? That seems excessively long.. send me an email about it and I can try to figure out what might be going wrong.</description>
		<content:encoded><![CDATA[<p>To be honest, nobody has ever suggested that before, and it was probably overlooked when I first wrote it. They are sorted as it&#8217;s pulled out, so it shouldn&#8217;t be too big a deal to add to the next release.</p>
<p>As for the 24 hours and still querying IDs.. how many tables were in that schema? That seems excessively long.. send me an email about it and I can try to figure out what might be going wrong.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

