SQL security flaw persists in many web sites
Businesses are still failing to make basic security checks on their web sites and are leaving themselves wide open to digital attack, warn experts.
Companies with web sites that have poorly designed SQL-based database back-ends are at risk from 'SQL injection' attacks, which can result in servers being taken over and personal details stolen.
Sites most likely to be affected are those that use old software code, and haven't had sufficient penetration testing, says Phil Cracknell, managing director at security specialist CISSP.
By Emma Nash at vnunet.
[ Read more ]
- Article: Blindfolded SQL Injection (2 September 2003)
- Article: Mass-Distribution Two-Factor Authentication System (21 November 2002)
- Article: (more) Advanced SQL Injection (3 July 2002)
By subscribing to our early morning news update, you will receive a daily digest of the latest security news published on Help Net Security.
With over 500 issues so far, reading our newsletter every Monday morning will keep you up-to-date with security risks out there.