Wvlet is a cross-SQL flow-style query language for functional data modeling and interactive data analysis. Analyze As You WriteThe flow-style query enables you to analyze data as you write queries for interactive data exploration. Use our interactive REPL or write queries in VS Code with full syntax highlighting. Functional Data ModelingWvlet enables to build functional (i.e., reusable and composa
ã¯ããã« ããã«ã¡ã¯ãcalloc134 ã§ãã ããã¯ã¨ã³ãéçºã«ããã¦ãDB ã«ãã¼ã¿ãä¿åãããã¨ã¯ãããããã¨ã§ãã DB ã¨æ¥ç¶ãã¦ãã¼ã¿ã®ããåããè¡ãå¿ è¦ãããã¾ãããçããã¯ã©ã®ããã«ãã¦ãã¼ã¿ãåå¾ãã¦ãã¾ããï¼ ORM ãã¯ã¨ãªãã«ããå©ç¨ããããéã« SQL ãè¨è¿°ãã¦ã³ã¼ãçæãè¡ã£ããã¨ãæ§ã ãªæ¹æ³ãããã¾ãã ä»åã¯ãããã®ã¢ããã¼ãã«ã¤ãã¦æ¯è¼ããæ¯è¼çæ¬æ°ãªæ¹éãåã£ã¦ãããã®ã¨ã㦠SafeQL ãç´¹ä»ãã¾ãã æ³¨æç¹ ããã§ã¯ãTypeScript ã®ããã¯ã¨ã³ãéçºã¨ãããã§å©ç¨ãããã©ã¤ãã©ãªãåæã¨ãã¦è©±ãé²ãã¾ãã Go ã Python ãªã©ä»ã®è¨èªã§ã®å©ç¨æ¹æ³ã«ã¤ãã¦ã¯ãå¥é調æ»ãå¿ è¦ã§ãã SQL ã«å¯¾ããã¢ããã¼ã ã¾ããSQL ã«å¯¾ããã¢ããã¼ãã«ã¯å¤§ããåã㦠2 ã¤ã®æ¹æ³ãããã¾ãã ããããã®ã©ã¤ãã©ãªã®ä½¿ãæ¹ããç°¡åã«è¦ã¦ããã¾
éçºè åãã®SQLã¤ã³ããã¯ã¹è§£èª¬ãµã¤ãã管çã«ã¤ãã¦ã®ééããªãç¥èãæä¾ãã¾ãã ã¤ã³ããã¯ã¹ã¯éçºæã«ã¯å¿ããããã¡ã§ãã䏿¹ã§ãé常ã«å¹æçãªSQLã®ãã¥ã¼ãã³ã°æ¹æ³ã§ããUse The Index, Lukeã§ã¯ãHibernateãªã©ã®ORMãã¼ã«ã®è§£èª¬ã«ã¨ã©ã¾ãããSQLã®ã¤ã³ããã¯ã¹ã«ã¤ãã¦åºç¤ãã説æãã¾ãã Use The Index, Lukeã¯SQLããã©ã¼ãã³ã¹è©³è§£ã®Webä¸ã®ç¡æçã§ãããµã¤ããæ°ã«å ¥ã£ã¦é ãããããã²æ¸ç±ãè³¼å ¥ãã¦ã¿ã¦ä¸ãããã¾ãããã®ãµã¤ãã®éå¶ããµãã¼ãããæ§ã ãªã°ããºã販売ãã¦ãã¾ãã MySQLãOracleãSQL Serverãªã©ã«ãããSQLã®ã¤ã³ããã¯ã¹Use The Index, Lukeã§ã¯ããã³ãã«ã¨ããããªãã¤ã³ããã¯ã¹ã®èª¬æãå¿ããã¦ãã¾ãã製åç¹æã®äºæã«ã¤ãã¦ã¯ã以ä¸ã®ãããªè¡¨ç¤ºããã¦ãã¾ãã Db2 (LUW)U
ããã«ã¡ã¯ã@hamayanhamayan ã§ãã æ¬ç¨¿ã§ã¯Webã»ãã¥ãªãã£ã«å¯¾ããæç¨ãªææ¸ã¨ãã¦åºãåç §ããã¦ããOWASP Top 10ã®1ã¤ãã¤ã³ã¸ã§ã¯ã·ã§ã³ãã«ã¤ãã¦èãã¦ããã¾ããè²ã ãªã¤ã³ã¸ã§ã¯ã·ã§ã³ãä¾ã«æããªãããã©ã®ããã«ã¤ã³ã¸ã§ã¯ã·ã§ã³ãèµ·ããã®ãã¨ããçºçåçãããã©ã®ããã«ã¤ã³ã¸ã§ã¯ã·ã§ã³ãæããããåºãã¤ã³ã¸ã§ã¯ã·ã§ã³ã®èãæ¹ãèªèº«ã®ãããã¯ãéçºã«é©ç¨ãã¦ãããã«ã¤ãã¦æ±ã£ã¦ããã¾ãã SQLã¤ã³ã¸ã§ã¯ã·ã§ã³ãã³ãã³ãã¤ã³ã¸ã§ã¯ã·ã§ã³ãXSSã®ãããªã¤ã³ã¸ã§ã¯ã·ã§ã³ã«é¢ããæåãªææ³ã«ã¤ãã¦æ¨ªæçã«è§£èª¬ãããªãããã¤ã³ã¸ã§ã¯ã·ã§ã³ã®æ¦å¿µã説æãã¦ããã¾ããåãã¦ã¤ã³ã¸ã§ã¯ã·ã§ã³ã«è§¦ããæ¹ã«ã¨ã£ã¦ã¯ãã¤ã³ã¸ã§ã¯ã·ã§ã³ã®å®ä¾ãåºæ¬çãªèãæ¹ã«è§¦ãããã¨ãã§ãããã®å ¨ä½åãææ¡ããå©ãã«ãªããã¨æãã¾ãã ã¾ããæ¢ã«ããã¤ãã®ã¤ã³ã¸ã§ã¯ã·ã§ã³ææ³ãç¥ã£ã¦ããæ¹ã«ã¨
sql-execute-os-command.md Defending new vectors: Threat actors attempt SQL Server to cloud lateral movement | Microsoft Security Blog SQLãµã¼ãããå¥ã®ã¨ããã«ä¾µå ¥ãããã¿ã¼ã³ã§ãSQLãµã¼ãä¸ã§OSã®ã³ãã³ããå©ç¨ãã¦ãã±ã¼ã¹ãå¢ãã¦ããã åSQLãµã¼ãã§OSã³ãã³ããå®è¡ããæ¹æ³ãç¥ãããã Type How To Status SQL Server xp_cmdshell Disable by Default MySQL system (\!) Enable in Terminal PostgreSQL COPY Require pg_execute_server_program role Related Exploiting PostgreSQL
Microsoft security researchers recently identified a campaign where attackers attempted to move laterally to a cloud environment through a SQL Server instance. This attack technique demonstrates an approach weâve seen in other cloud services such as VMs and Kubernetes cluster, but not in SQL Server. The attackers initially exploited a SQL injection vulnerability in an application within the target
(2009.3.5 ãã¹ããã¼ã¿ã«ã¤ãã¦ã¡ãã£ã¨è¿½è¨) Working Effectively with Legacy Codeãèªãã§ãã¾ããååããã¹ãã®æç¾©ã¨ãæ¦å¿µã®ç´¹ä»(test harness, seamãªã©)ã¯ãã°ããããå¾åã®ãåå¥ã®ç¶æ³ã¸ã®å¯¾çããæ´çããã¦ãã¦ãããããã§ããèªåã§ã使ã£ã¦ããããªãã¿ã®ææ³ãããã°ãç®ã¦ãã³ãªãã¨ãããã ã§ããããããâç« ããã£ããããã£ããªãã ããã¹ããæ¸ãããããã©ããã°ã©ã ã巨大ãªSQLã®åºã¾ãã ã ãã¾ä»äºããã¦ããä¿å®ããã¸ã§ã¯ãããããããç¶æ³ãªããã§ãããããããæ´çããã¨ã ãã¼ãã«æ°ãå¤ã(100以ä¸)ãéè¤ããé ç®ãå¤ã(鿣è¦å) ã²ã¨ã¤ã®å¦çãããã®ã«ã ããããæä½5ã¤ä»¥ä¸(10ãè¶ ãããã®ãå¤ã)ã®ãã¼ãã«ãæ±ã£ã¦ãã(åç §ãªãJOINãUNIONãæ´æ°ãªãããããã«UPDATE/INSERT) å¦çãèµ°ãã
Using pluginsï To use plugins, you must be using Version 2 of the configuration file. The top-level plugins array defines the available plugins. WASM pluginsï WASM plugins are fully sandboxed; they do not have access to the network, filesystem, or environment variables. In the codegen section, the out field dictates what directory will contain the new files. The plugin key must reference a plugin
ã¯ãã㫠失æè¨äºã§ãï¼SQLI ä¸åãè¦ã¤ããã¾ããã§ããï¼ã ååã®è¨äºã§ã¯ GitHub ã«æ¼ãåºãã³ã¼ãã GitHub Code Search ã使ã£ã¦æ¤ç´¢ãã¾ããã brutalgoblin.hatenablog.jp ä»åã¯å°ãç¹æ®ãª SQL Injection ãåååæ§ã« GitHub Code Search ã®åãåãã¦æ¢ããã¨æãã¾ãã ç¹æ®ãª SQLI ã¨ã¯ãä¸è¬çãªæååçµåã§ã¯ãªãã æååãã³ãã¬ã¼ããªãã©ã«ã使ã£ãçµåã«ãã SQLI ã§ãï¼å¾è¿°ï¼ 失æè¨äºã§ã¯ããã®ã§ããã観ç¹çã«ã¯çµæ§é¢ç½ãã¨æãã®ã§ã軽ãã¾ã¨ãã¦ã¿ã¾ãã ã¾ããä»å㯠ORM ã«éå®ãã¦æ¢ãã¾ããããéå®ããªããã°çµæ§è¦ã¤ããã®ãããªã¼ã¨æã£ã¦ã¾ãã è¦ã¤ãããã¨ãããã® ãåç¥ã®éããSQL Injection ã®ä¸çªè¯ããããã¹ã¯ã æååçµåãã SQL ãçºè¡ãããã®ã¾ã¾ In
Did you know that GitHub maintains a public database of known CVEs and security advisories for open-source codebases? The database is a public Git repository that holds JSON files in OSV format, partitioned by date. This is the data that's displayed on the github.com/advisories page, which also powers Dependabot alerts! Since it's just a Git repo, we wanted to take it for a spin with MergeStat to
Via this comment on Hacker News I started exploring the ClickHouse Playground. It's really cool, and among other things it allows CORS-enabled API hits that can query a decade of history from the GitHub events archive in less than a second. ClickHouse is an open source column-oriented database, originally developed at Yandex but spun out into a separate, VC-funded company in 2021. It's designed fo
sqldef is the easiest idempotent schema management tool for MySQL, PostgreSQL, SQLite3, and SQL Server that uses plain SQL DDLs. Define your desired schema in SQL, and sqldef generates and applies the migrations to update your database. With sqldef, you maintain a single SQL file with your complete schema. To modify your schema - add columns, change constraints, or create indexes - simply edit thi
Executive SummaryTeam82 has developed a generic bypass of industry-leading web application firewalls (WAF). The attack technique involves appending JSON syntax to SQL injection payloads that a WAF is unable to parse. Major WAF vendors lacked JSON support in their products, despite it being supported by most database engines for a decade. Most WAFs will easily detect SQLi attacks, but prepending JS
techfeed çµç±ã§ä¸è¨ã®ã¹ã¬ãããè¦ãããã®ã§ãããã¿ã¤ãã«ã ãã§ãæ¢ã«é¢ç½ããã§ãã ã¾ããã¡ãã£ã¨åãã Notion ã®ãã¼ã¿ãã¼ã¹ãå種ã³ã³ãã³ãã¸å¤æãããã¼ã«ãä½ã£ã¦ãã¾ãã¦ããããçµã¿åãããã¨ããããæ¥½ã§ããããªäºæããã¾ãã ãã®ãããªããã§ãã¹ã¬ããã§ç´¹ä»ããã¦ãã columnq-cli ã«ã¤ãã¦ã®è¨äºã§ãã columnq-cli ã¨ã¯ï¼ README ãèªãã¨ãå種ãã¼ã¿ããã¼ãã«ã¨ã㦠SELECT ã§ããããã«ãã CLI ãã¼ã«ãã§ããã¼ãã«ã½ã¼ã¹ã«ã¯ JSON ãªã©ã®ä»ã« ROAPI ã§ãµãã¼ãããã¦ãããã®ãæ±ããã¨ã®ãã¨ã (SELECT ã®ã¿ã§æ´æ°ã¯ã§ããªã) ããã§ ROAPI ã¨ã¯ãªãããã¨ãªãã¾ããããã¡ãã¯ããã¼ã«ã«ã®ãã¡ã¤ã«ã·ã¹ãã ãå種ãµã¼ãã¹ã®ãã¼ã¿ãçµ±åçã«æ±ãã(SELECT ã§ãã)ãµã¼ãã¼ããæ§ç¯ã§ããããã§ãã å³ 1-
ã©ã³ãã³ã°
ã©ã³ãã³ã°
ã¡ã³ããã³ã¹
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}