Friday March 12, 2010 3:44 PM AEST
 
Latest Comments
"Mifare 1K,4K,DESfire 4K,Sle4442,T5577,PVC card,KeyFob,ID card,Magstripe card Dear Sir/Madam, ..."
by Jucy | Mar 12, 2010 1:05 PM
 
"Hi Everybody Guys>> How r u? >>I Am S.M.Moshin Arafat (jony) >> I Am a Very Simple Person & I ..."
by Moshin Arafat | Mar 12, 2010 10:29 AM
 
"Sounds funny. Did they ever tell the customers in plainly-worded language that the co-lo space ..."
by Dave - The Network Mule | Mar 11, 2010 10:28 AM
 
"Sunglasses of wto-store.com www.wto-store.com Versace Sunglasses http://wto-store.com/catego..."
by Luxury Handbags 100% Authentic, 2010 Lastest Styles, Buy Now! | Mar 10, 2010 8:59 PM
 
"First Post Hooray"
by Random Stranger | Mar 10, 2010 12:38 PM
Web

Flaw detected on Yahoo! website

  • Email a Friend
  • Print Page
Flaw detected on Yahoo! website
By Dan Raywood
Nov 17, 2009 10:46 AM
Tags: Imperva | flaw | Yahoo | jobs | section | website | SQL | injection | Blind | SQLi
Imperva points to jobs section.

An SQL injection flaw has been detected on the Yahoo! website.

Detected as a Blind SQLi problem, Imperva said that the vulnerabiliy was on the Yahoo job section, and could result in the information of large numbers of people being compromised.

Amichai Shulman, CTO at Imperva, said: “Data like this can be extremely useful as far as identity thieves are concerned. This is exactly the sort of data that is traded on so-called carder forums.”

Imperva claimed that forums are causing a problem for law enforcement, because when one forum is closed down another opens, and they act as an auction/exchange for a person's data.

Shulman said that some hackers are selling the ‘fish' - the stolen data - while others provide the ‘fishing polls' – the exploits that can be used to extract the information.

“This is why it's important to warn about potential SQL injection-hacked problems like this. If the potential problem is allowed to continue for any length of time, then the risk of a hacker attack rises as a result,” said Shulman.

“SQL injection is a major thorn in the side for the website hosting community. It can be tackled with careful research and high levels of security. Unfortunately, some site operators overlook this simple fact at high risk.”

See original article on scmagazineuk.com

Secure Computing Magazine

 
Ads by Google
Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 
 
Vulnerabilities & Exploits Whitepapers