Showing posts with label SQL. Show all posts
Showing posts with label SQL. Show all posts

Wednesday, December 24, 2008

Microsoft Warns of SQL Attack

Just days after patching a critical flaw in its Internet Explorer browser, Microsoft is now warning users of a serious bug in its SQL Server database software.

Microsoft issued a security advisory late Monday, saying that the bug could be exploited to run unauthorized software on systems running versions of Microsoft SQL Server 2000 and SQL Server 2005.

Attack code that exploits the bug has been published, but Microsoft said that it has not yet seen this code used in online attacks. Database servers could be attacked using this flaw if the criminals somehow found a way to log onto the system, and Web applications that suffered from relatively common SQL injection bugs could be used as stepping stones to attack the back-end database, Microsoft said.

Desktop users running the Microsoft SQL Server 2000 Desktop Engine or SQL Server 2005 Express could be at risk in some circumstances, Microsoft said.

Monday, April 28, 2008

Half A Million Microsoft-Powered Sites Hit With SQL Injection Attack

A new SQL injection attack aimed at Microsoft IIS web servers has hit some 500,000 websites, including the United Nations, UK Government sites and the U.S. Department of Homeland Security. In other words, there’s no patch that’s going to fix the issue, the problem is with the developers who failed follow well-established security practices for handling database input. While the attack is not necessarily Microsoft's fault, it is unique to the company's IIS server.

read more | digg story

Saturday, November 17, 2007

Bad Security?

It seems like a never ending cat and mouse game between the hackers and the software programmers. To be sure much if the holes boil down to bad programing habits and also lack of imagination as it why on earth would some one do that? 

Microsoft Windows XP is a very popular OS and its very common so no surprise this week when "a Microsoft executive calls the ease with which two British e-crime specialists managed to hack into a Windows XP computer as both enlightening and frightening." It very common for an novice computer user to buy a computer and toss it on the Internet with out patching it. "After all who has time for that I have work to do!" I have been told my more then one manager the he was frustrated that I was always patching systems. "After all I can just go down to the computer store an buy a computer from the store and it's ready to go!" Scary right? Well all too common a mind set that IT Pro have to deal with.

This week a hacker found over 492,000 unprotected Oracle & Microsoft SQL database servers connected directly to the internet an not even protected by a firewall. True even with a good firewall it's possible to use an SQL injection attack to nuke a database. But IMHO some security is better then none at all. 

Even if you use a smart phone you may not be totally safe. Before Apple released the iPhone 1.1.2 patch there was a security hole that users we using to add software to their iPhone. The Fast Company recently published a story about how it might be possible to hack an iPhone. Click here to see the video.


Digg!