- September 27, 2006
- 0 comments
Michael Sutton wrote about a simple tool he wrote which uses Google to find sites vulnerable to SQL injection. (I wrote about SQL injection as it relates to online retailers in Catalog Success article last year.)
Sutton found 11% of the sites in his study have vulnerabilities. That’s a huge rate.
Sutton’s tool was written to assess the scope of the problem. The same technique could modified, easily, to attack sites en masse using an automated ‘bot. Scary.
Talk to your web folks. Make sure they’ve secured your site. Don’t allow any raw inputs to reach your database (SQL injection) or your HTML output (cross-site scripting).
Preventing SQL injection isn’t all that hard — yet 11% of sites haven’t got it right yet.
If you like this post, consider subscribing to our RSS feed. You can also have new posts sent to you via email.
Similar Posts
- Alexa and HitWise: How Accurate Their Estimates?
- Web Usability: Reflections On Best Of The Web Judging
- If you aren’t yet using MVT to increase your site conversion: you should.
- Social Tagging and Effective E-commerce
- Hacker Safe’s Ken Leonard: 75% Of Online Retail Sites Insecure
Trackback
http://www.rimmkaufman.com/rkgblog/2006/09/27/11-of-sites-vulnerable-to-sql-injection-is-yours/trackback/No Comments Yet
Your comment will be first!


Your Comment
We "do-follow" links in comments. This may help your search rankings. Learn more...