A simple tale of SQL Injection .....
Submitted by David Goodwin on Fri, 16/05/2008 - 21:24.Today, I was giving a one-on-one PHP training course covering databases (we were trying to get mssql to work with PHP on Windows, but various factors seemed to conspire against us - possibly permissions related, as it seemed to refuse to allow us to select from a table that fricking well did exist.). Anyway, the amusing story was.....
I have a habit of "probing" most web sites to see whether they're vulnerable to SQL injection - normally inserting a simple single quote into a URL will show one way or another. Unfortunately, for the delegate, he hadn't come across SQL Injection, but had written a website for his local village, in .asp.....
Cue login as "admin" with a password of "' OR '' = '".
Suffice to say, we then had a good laugh at the classic XKCD strip about poor Robert and he now knows how someone hacked into the site a few months ago.
Technorati Tags:
Recent comments
5 days 2 hours ago
5 days 4 hours ago
5 days 14 hours ago
1 week 3 days ago
1 week 3 days ago
1 week 5 days ago
1 week 5 days ago
2 weeks 1 day ago
2 weeks 2 days ago
2 weeks 2 days ago