<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:creativeCommons="http://backend.userland.com/creativeCommonsRssModule"	>
<channel>
	<title>Comments on: Techsoup Hit By SQL Injection Attack</title>
	<atom:link href="http://www.nonprofittechblog.org/techsoup-hit-by-sql-injection-attack/feed" rel="self" type="application/rss+xml" />
	<link>http://www.nonprofittechblog.org/techsoup-hit-by-sql-injection-attack</link>
	<description>Confessions of a Non-Profit Executive Director</description>
	<lastBuildDate>Sat, 13 Mar 2010 11:46:18 -0500</lastBuildDate>
	<generator>http://wordpress.org/?v=abc</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Allan Benamer</title>
		<link>http://www.nonprofittechblog.org/techsoup-hit-by-sql-injection-attack/comment-page-1#comment-97513</link>
		<dc:creator>Allan Benamer</dc:creator>
		<pubDate>Sat, 16 Aug 2008 08:46:14 +0000</pubDate>
		<guid isPermaLink="false">http://www.nonprofittechblog.org/?p=3517#comment-97513</guid>
		<description>@Donald Lobo: Sorry for the delay in posting your comment -- it turns out your comment got sent to spam. WP saw the multiple links and freaked out.</description>
		<content:encoded><![CDATA[<p>@Donald Lobo: Sorry for the delay in posting your comment &#8212; it turns out your comment got sent to spam. WP saw the multiple links and freaked out.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Donald Lobo</title>
		<link>http://www.nonprofittechblog.org/techsoup-hit-by-sql-injection-attack/comment-page-1#comment-97465</link>
		<dc:creator>Donald Lobo</dc:creator>
		<pubDate>Tue, 12 Aug 2008 21:20:25 +0000</pubDate>
		<guid isPermaLink="false">http://www.nonprofittechblog.org/?p=3517#comment-97465</guid>
		<description>Some tech readers might also be interested in more details at: 

http://it.slashdot.org/article.pl?sid=08/08/12/1943217
http://www.trustedsource.org/blog/142/New-SQL-Injection-Attack-Infecting-Machines

Basically a lot of coldfusion / mssql sites are open to attack. You can find more information about the attack by searching for vernyx</description>
		<content:encoded><![CDATA[<p>Some tech readers might also be interested in more details at: </p>
<p><a href="http://it.slashdot.org/article.pl?sid=08/08/12/1943217" rel="nofollow">http://it.slashdot.org/article.pl?sid=08/08/12/1943217</a><br />
<a href="http://www.trustedsource.org/blog/142/New-SQL-Injection-Attack-Infecting-Machines" rel="nofollow">http://www.trustedsource.org/blog/142/New-SQL-Injection-Attack-Infecting-Machines</a></p>
<p>Basically a lot of coldfusion / mssql sites are open to attack. You can find more information about the attack by searching for vernyx</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Allan Benamer</title>
		<link>http://www.nonprofittechblog.org/techsoup-hit-by-sql-injection-attack/comment-page-1#comment-97418</link>
		<dc:creator>Allan Benamer</dc:creator>
		<pubDate>Thu, 07 Aug 2008 18:56:26 +0000</pubDate>
		<guid isPermaLink="false">http://www.nonprofittechblog.org/?p=3517#comment-97418</guid>
		<description>@Marnie Webb: Yeah, I&#039;m glad you&#039;re trying to fix it but a security audit can take forever. No way to revert to an old version of the code and data or afraid it would just be attacked again? I really urge and implore you to consider those guidelines for notification. I can&#039;t say how important it is to reach your user community in as many offline ways as possible to ensure that your users are adequately notified.

@Jon Stahl: I guess you&#039;re right. I&#039;m wondering if it&#039;s not already time to switch over to something open source for Techsoup. There are plenty of new frameworks out there for Techsoup to choose but I&#039;m sure there&#039;s a pretty huge sunk cost that they&#039;d have to think about. 

That said, Techsoup is a utility in the nonprofit community now. It occupies a central portion of the nonprofit IT director&#039;s time. It needs more uptime and I think an open source community development effort would work. I would think plenty of folks would pitch in to help out if Techsoup&#039;s code was on an SVN or git repository out there.</description>
		<content:encoded><![CDATA[<p>@Marnie Webb: Yeah, I&#8217;m glad you&#8217;re trying to fix it but a security audit can take forever. No way to revert to an old version of the code and data or afraid it would just be attacked again? I really urge and implore you to consider those guidelines for notification. I can&#8217;t say how important it is to reach your user community in as many offline ways as possible to ensure that your users are adequately notified.</p>
<p>@Jon Stahl: I guess you&#8217;re right. I&#8217;m wondering if it&#8217;s not already time to switch over to something open source for Techsoup. There are plenty of new frameworks out there for Techsoup to choose but I&#8217;m sure there&#8217;s a pretty huge sunk cost that they&#8217;d have to think about. </p>
<p>That said, Techsoup is a utility in the nonprofit community now. It occupies a central portion of the nonprofit IT director&#8217;s time. It needs more uptime and I think an open source community development effort would work. I would think plenty of folks would pitch in to help out if Techsoup&#8217;s code was on an SVN or git repository out there.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jon Stahl</title>
		<link>http://www.nonprofittechblog.org/techsoup-hit-by-sql-injection-attack/comment-page-1#comment-97417</link>
		<dc:creator>Jon Stahl</dc:creator>
		<pubDate>Thu, 07 Aug 2008 18:31:44 +0000</pubDate>
		<guid isPermaLink="false">http://www.nonprofittechblog.org/?p=3517#comment-97417</guid>
		<description>Disappointing, but sadly, not surprising.  Techsoup&#039;s codebase is pretty old, and was written before awareness of these issues was as widespread as it is now.

I wouldn&#039;t be surprised to see a lot more attacks like this in the future against large nonprofit targets, since many of them are running similarly old, large custom apps and are tempting targets.</description>
		<content:encoded><![CDATA[<p>Disappointing, but sadly, not surprising.  Techsoup&#8217;s codebase is pretty old, and was written before awareness of these issues was as widespread as it is now.</p>
<p>I wouldn&#8217;t be surprised to see a lot more attacks like this in the future against large nonprofit targets, since many of them are running similarly old, large custom apps and are tempting targets.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: marnie webb</title>
		<link>http://www.nonprofittechblog.org/techsoup-hit-by-sql-injection-attack/comment-page-1#comment-97413</link>
		<dc:creator>marnie webb</dc:creator>
		<pubDate>Thu, 07 Aug 2008 12:31:57 +0000</pubDate>
		<guid isPermaLink="false">http://www.nonprofittechblog.org/?p=3517#comment-97413</guid>
		<description>Sorry for the additional comment: we are also keeping http://www.techsoup.org up-to-date so that we can share information as we have it.   The full text of the message you quoted is there.</description>
		<content:encoded><![CDATA[<p>Sorry for the additional comment: we are also keeping <a href="http://www.techsoup.org" rel="nofollow">http://www.techsoup.org</a> up-to-date so that we can share information as we have it.   The full text of the message you quoted is there.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: marnie webb</title>
		<link>http://www.nonprofittechblog.org/techsoup-hit-by-sql-injection-attack/comment-page-1#comment-97412</link>
		<dc:creator>marnie webb</dc:creator>
		<pubDate>Thu, 07 Aug 2008 12:29:19 +0000</pubDate>
		<guid isPermaLink="false">http://www.nonprofittechblog.org/?p=3517#comment-97412</guid>
		<description>Marnie Webb, here, co-CEO of TechSoup.  Thanks, Allan, for helping to spread the word and advising users to make password changes (below the portion of our message that you quoted).  We will, of course, be providing more information to our users through different channels. However, as we are still working on the issues, we wanted to share as quickly as possible and so posted the information on our landing page.</description>
		<content:encoded><![CDATA[<p>Marnie Webb, here, co-CEO of TechSoup.  Thanks, Allan, for helping to spread the word and advising users to make password changes (below the portion of our message that you quoted).  We will, of course, be providing more information to our users through different channels. However, as we are still working on the issues, we wanted to share as quickly as possible and so posted the information on our landing page.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
