Most Popular Stories
- Chrome 17's new features enhance speed, security
- Bug in Trendnet webcams exposes them to public viewing
- Spotlight: Intel launches 520 Series solid-state drive
- Apple's iPad 3 will be unveiled first week of March, says report
- Microsoft's Patch Tuesday for February has 9 security bulletins
- There's no escaping the app economy
Events
- COMPTEL PLUS Spring 2012
April 15-18 — San Francisco, CA - Customer Engagement Technology World
March 28-29, 2012 — San Francisco - Northwestern University Master's in Information Systems
- Ready to meet the next-generation of business?
March 4-6 2012 — San Francisco, CA
Sponsored Links
Free Newsletter
HOT TOPICS >> The tech world's top flops and fiascos of 2011 | Top 8 features in Windows 8 | Paul's Q&As
INDUSTRY >> Healthcare IT | Government IT | Financial Services IT | Biotech IT | Compliance IT
Free Newsletter
Latest News
Popular Topics
Whitepapers
- Whitepaper: Integrated Analytics and WCM Can Improve Performance & ROI
- Green Doesn't Have to be Hard
- Enterprise Portals: Harnessing Portal Power
- Business Intelligence: It's All in the Data
- IMPROVING THE MANAGEMENT OF FEDERAL GOVERNMENT IT ASSETS THROUGH BETTER COMMUNICATION WITH THE IT INDUSTRY
- The Top 4 Reasons Your Telecom Expense Management Provider Shouldn't Manage Your Wireless
SQL injection attacks could open door to more serious exploits
A new breed of SQL injection attacks could give hackers a way to take control of many of the underlying database servers powering websites. According to penetration tester Bernardo Damele Assumpcao Guimaraes, the techniques that he has discovered will work on open-source database engines, MySQL and PostgreSQL, as well as Microsoft SQL Server.
In an interview with The Register, Damele Assumpcao Guimaraes said "I use the SQL injection only as a stepping stone to my target, and my target is the operating system, not only the data on the database." Damele Assumpcao Guimaraes will be sharing more about such attacks at a Black Hat talk later this month, as well as share notes that will help other penetration testers detect this new breed of attacks.
As a whole, experts agree that SQL injection is a problem that affects all too many sites, and needs to be addressed urgently. Jeremiah Grossman, White Hat Security's CTO thinks that the cost of properly remedying flaws in web applications could cost anywhere from $3 billion to $8.5 billion. Damele Assumpcao Guimaraes advises that companies implement proper best practice such as having as few privileged users as possible.
However, considering that many of Damele Assumpcao Guimaraes's attack techniques rely on database flaws that allow privileges restrictions to be circumvented, some fundamental fixes will need to be made to vulnerable databases, in addition to fixing web applications and proper security practices.
For more on this story:
- check out this article at The Register
Related Articles:
Section of Kaspersky website compromised
Foreign attacks hit blogs
Security vulnerability found in MS SQL server 2000
Oracle is buggier than SQL server
Related Stories
- Google Chrome OS vulnerability revealed at Black Hat
- Many home routers could be vulnerable to web hack
- Mozilla issues warning over password-stealing Firefox add-on
- Researchers offer tool to break into Oracle database systems
- Mozilla: We'll patch flaws in 10 [expletive] days
- Microsoft blocks Vista hack, opens new can of worms
- Unpatched flaw revealed in Cisco firewall
- Microsoft ask hackers to try breaking Vista
- Intel offers security fixes for Centrino wireless chips
- Editor's Corner
Home
| Subscribe | Advertise | RSS |
Privacy
| Site Map
| EditorsTHE FIERCEMARKETS NETWORKFierceEnergy | FierceSmartGrid | FierceFinance | FierceFinanceIT | FierceComplianceIT | FierceHealthcare | FierceHealthFinance | FierceHealthIT | Hospital Impact | FierceMobileHealthcare | FierceHealthPayer | FiercePracticeManagement | FierceEMR | FierceCIO | FierceCIO:TechWatch | FierceContentManagement | FierceMobileIT | FierceGovernmentIT | FierceGovernment | FierceHomelandSecurity | FierceBiotech | FierceBiotech Research | FiercePharma | FierceVaccines | FierceBiotechIT | FiercePharma Manufacturing | FierceMedicalDevices | FierceDrugDelivery | FierceIPTV | FierceOnlineVideo | FierceTelecom | FierceEnterpriseCommunications | FierceBroadbandWireless | FierceDeveloper | FierceMobileContent | FierceWireless | FierceWireless:Europe | FierceCable© 2011 FierceMarkets. All rights reserved. |
![]() |




