Advertisement
Promo

Security threats Toolkit

Script kiddies learn grown-up hacking techniques

Dan Ilet ZDNet.co.uk

Published: 13 Jan 2005 15:10 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

SQL injection hacking techniques are starting to be used by script kiddies -- inexperienced hackers with limited technical skills -- who are learning from a growing number of online help guides on database hacking.

According to Jason Hart, head of security for Whitehat UK, SQL injections have become common among this group. Until now, because of its complexity, this technique has generally only been associated with serious hackers.

"There's been a huge increase in guides on the Web to take you through this process," said Hart on Thursday.

"Traditionally the SQL injection was a dedicated hacker's technique. People who put up the usual defences, such as firewalls and regular patching, may not be protected against this. The upshot is security is not just at the perimeter, it has to work at the core of the network."

Every Web site with a search facility has a back-end database to answer queries. By entering particular queries against the Web site, the database gives error messages that hackers can use to extract detailed system information, such as version numbers and database structure, from the system.

Because SQL injection attacks work at the application level, most firewalls are unable to prevent them. A more sophisticated security product such as an Intrusion Detection System, which can examine the contents of each packet of data, may give more protection.

Last year Oracle Applications admitted that its products contained flaws that could let hackers commandeer databases by injecting SQL code into query windows.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
56 out of 128 people found this useful


Full Talkback thread

1 comment

  1. SQL Injection is not a problem if the application... John McVey

Company/Topic Alerts

Create a new alert from the list below:






Video icon

Video

Sentry Posts Blog

Authentication risks all too human

Risks to successful online banking identification and authentication using smartcards involve a mixture of human and technological factors, according to the European Network and Information... More

1 comment

Opera censors Chinese content

Opera has updated the Chinese version of its mobile browser to stop users accessing restricted content. Opera Mini was updated on Friday from an international to a Chinese version,... More

2 comments

Symantec website breached

Security company Symantec has said that one of its websites was successfully breached. Romanian security researcher 'Unu' posted details of the breach in a blog post on Monday. Unu... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters