ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Script kiddies learn grown-up hacking techniques

Dan Ilet ZDNet.co.uk

Published: 13 Jan 2005 15:10 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

SQL injection hacking techniques are starting to be used by script kiddies -- inexperienced hackers with limited technical skills -- who are learning from a growing number of online help guides on database hacking.

According to Jason Hart, head of security for Whitehat UK, SQL injections have become common among this group. Until now, because of its complexity, this technique has generally only been associated with serious hackers.

"There's been a huge increase in guides on the Web to take you through this process," said Hart on Thursday.

"Traditionally the SQL injection was a dedicated hacker's technique. People who put up the usual defences, such as firewalls and regular patching, may not be protected against this. The upshot is security is not just at the perimeter, it has to work at the core of the network."

Every Web site with a search facility has a back-end database to answer queries. By entering particular queries against the Web site, the database gives error messages that hackers can use to extract detailed system information, such as version numbers and database structure, from the system.

Because SQL injection attacks work at the application level, most firewalls are unable to prevent them. A more sophisticated security product such as an Intrusion Detection System, which can examine the contents of each packet of data, may give more protection.

Last year Oracle Applications admitted that its products contained flaws that could let hackers commandeer databases by injecting SQL code into query windows.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
52 out of 120 people found this useful


Full Talkback thread

1 comment

  1. SQL Injection is not a problem if the application... John McVey

Company/Topic Alerts

Create a new alert from the list below:






Related Jobs

SAS Credit Risk Analyst - London - SAS

Delivering financial reports on a monthly and quarterly basis - Supporting the business in the pricing strategy of new products - Undertaking project ...

Credit Risk Analyst: North West 23-30K+Extensive benefits

Provide support and expert advice to business areas where queries arise regarding risk strategies in place 3. Consumer Credit Act The ability to ...

Quality Lead - Unilever - Level C-00055185

Support implementation coordination for agreed QPI, SOX and Security controls Manage one quality team member who will support these activities Main ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment