Latest Comments
"Excellent info. If you use Gumtree Australia you will see many obvious scam posts in all ..."
by Marian Imrie | Dec 5, 2008 4:45 PM
 
"Very nice and useful information. UT4B4. Tape4backup.com"
by Lto-4 Tape | Dec 4, 2008 9:23 PM
 
"Interesting that you do not bother to list the one AV that has consistently passed the VB100. ..."
by Ben | Dec 4, 2008 6:00 PM
 
"I like this"
by nanwin | Dec 3, 2008 3:05 PM
 
"Concerned man's comments seem to intimate that if I'm using agents all will be well but the ..."
by Werner K | Nov 26, 2008 8:36 PM

US security blunder exposes residents' data

  • Email a Friend
  • Print Page
By Clement James
Apr 23, 2008 9:47 AM
Tags: US | security | blunder | exposes | residents' | data
The information was made available via a badly coded page linked to Oklahoma's Department of Corrections Sexual and Violent Offender Registry.

Anyone with a basic knowledge of SQL could view the list of sexual offenders, and query the database to bring up a host of other information on the residents.

Fredrick Lee, a software security researcher at Fortify Software, said that the problem was down to poor coding.

"This is a classic SQL injection vulnerability," he said, adding that the security lapse could easily have been caught with a simple code review.

The incident could have been avoided, according to Lee, by using some form of automated analysis during the release procedure for the website.

"The sad thing is that vulnerabilities like these indicate to attackers that other related applications and organisations are probably vulnerable as well," he said.

In this case, anyone with a basic knowledge of SQL programming could interpret the URL and other data returned by the Oklahoma site.

By the simple process of amending the long URLs returned by the site, they could retrieve tens of thousands of social security numbers and allied data.

Copyright © 2008 vnunet.com

 
Ads by Google
Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 
Tripwire - Click here to win an iTouch
 
 
Breaches & Exposures Whitepapers