RKG Logo 434-978-4300

Michael Sutton wrote about a simple tool he wrote which uses Google to find sites vulnerable to SQL injection. (I wrote about SQL injection as it relates to online retailers in Catalog Success article last year.)

Sutton found 11% of the sites in his study have vulnerabilities. That’s a huge rate.

Sutton’s tool was written to assess the scope of the problem. The same technique could modified, easily, to attack sites en masse using an automated ‘bot. Scary.

Talk to your web folks. Make sure they’ve secured your site. Don’t allow any raw inputs to reach your database (SQL injection) or your HTML output (cross-site scripting).

Preventing SQL injection isn’t all that hard — yet 11% of sites haven’t got it right yet.

Technorati Tags: ,

If you like this post, consider subscribing to our RSS feed. You can also have new posts sent to you via email.


Related Posts

    No related posts.

Comments

  1. Prasad, September 10, 2008:

    Just got to say it was nice..

Your Comment

Tags

RKG Tags: ,

Technorati Tags: ,

Trackback

http://www.rimmkaufman.com/rkgblog/2006/09/27/11-of-sites-vulnerable-to-sql-injection-is-yours/trackback/

Email Updates

Categories

Recent Comments

  • Mark Ballard: Cory, I don’t see this as an SEO v. PPC issue. The core of my argument is that CTRs are lower primarily due to misleading...
  • Cory Grassell: What are your thoughts on stats that suggest consumers are more apt to click on organic search results than PPC results? As a...
  • George Michie: Kevin, Marc, thanks for your comments. Help is coming, but not the solution. There are a number of instances when the CTR on the...
  • Marc Adelman: George, You have been an advocate of “the advanced control option” for years now. Depressing right YEARS! Eh…listen...
  • Kevin Hill: Is what they really need is a fourth match type. Here’s google’s help documentation on broad match: This is the default...
  • Kevin Micalizzi, Dimdim Web Conferencing: Jim (& George)- We still offer a free version of Dimdim. Just click Sign Up Now at the top of the...
  • Tomas: indeed, i can’t talk about it either… :)
  • Philip Price: Thank you for the RegHack, it worked for me, tho at first when i made the reg file with the information i copied from above i also...
  • George Michie: Sorry Jim, this post was written in 2007. Apparently some of those products are gone.
  • Jim: Hey, I checked two products like dimdim and cutepdf but none is free. What are you talking about free and open source?
  • George Michie: If they keep hearing the same message, and seeing evidence in the data to back it up, something will have to give. There is hope on...
  • Tomas: I’ve been having the same argument with Google for months now and in the end there does seem to be a feature in the algorithm that...
  • George Michie: Doesn’t have to be, it can be intra-adgroup as well.
  • Josh: George – I take it you’re referencing a scenario where your exact-match keywords are not listed as negative exact match keywords...
  • George Michie: Melissa, you’re right, it’s always happened to varying degrees, particularly since the advent of extended broad match....

Blog Stats

  • Posts: 948
  • Words: 451,089
  • Comments: 2,877

Administration