Advertisement
Promo

Security threats Toolkit in association with http://ad.doubleclick.net/clk;214682528;14505427;f?http://uk.blackberry.com/ataglance/security/

Script kiddies learn grown-up hacking techniques

Dan Ilet ZDNet.co.uk

Published: 13 Jan 2005 15:10 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

SQL injection hacking techniques are starting to be used by script kiddies -- inexperienced hackers with limited technical skills -- who are learning from a growing number of online help guides on database hacking.

According to Jason Hart, head of security for Whitehat UK, SQL injections have become common among this group. Until now, because of its complexity, this technique has generally only been associated with serious hackers.

"There's been a huge increase in guides on the Web to take you through this process," said Hart on Thursday.

"Traditionally the SQL injection was a dedicated hacker's technique. People who put up the usual defences, such as firewalls and regular patching, may not be protected against this. The upshot is security is not just at the perimeter, it has to work at the core of the network."

Every Web site with a search facility has a back-end database to answer queries. By entering particular queries against the Web site, the database gives error messages that hackers can use to extract detailed system information, such as version numbers and database structure, from the system.

Because SQL injection attacks work at the application level, most firewalls are unable to prevent them. A more sophisticated security product such as an Intrusion Detection System, which can examine the contents of each packet of data, may give more protection.

Last year Oracle Applications admitted that its products contained flaws that could let hackers commandeer databases by injecting SQL code into query windows.

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Did you find this article useful?
55 out of 123 people found this useful


Full Talkback thread

1 comment

  1. SQL Injection is not a problem if the application... John McVey

Company/Topic Alerts

Create a new alert from the list below:






Video icon

Video

Sentry Posts Blog

Behind the Scenes: Next Gen Mobile Tec...

Behind the Scenes: Next Gen Mobile Technology Author: Eric Everson, Founder MyMobiSafe.com With infrastructure speeds continually improving at the network level of the world’s leading... More

Post a comment

Nasa hacker petition presented to Numb...

Sting's wife Trudie Styler and Janis Sharp have presented a petition to Number 10 calling for Nasa hacker Gary McKinnon not to be extradited to the US. Styler, and Sharp, who is... More

Post a comment

UK to appoint cyber-sec tsar?

The UK is to appoint a cyber security tsar along the lines of the US, according to a story in the Telegraph this morning. The story is similar to one that appeared in the Guardian... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters