This is a very interesting story. Apparently attackers are automating SQL injections on vulnerable sites/apps with SQL Server backends. I've always been a big fan of automated SQL injection tools such as what HP's WebInspect has built-in but this brings a whole new meaning to automated SQL injection!Yet another reason you need to be testing your Web applications for security vulnerabilities consistently and without fail....
Continue Reading...I heard a news story this morning regarding the economy that reminded me of how we got to the point of misusing the word hacker. The essence of what this economic expert being interviewed said is that it doesn't matter if we're technically not in a recession, if the people believe we're in one, then that's all that matters. Well, we're not - but who cares, right?Just like with hacker. ...
Continue Reading...Here are my information security articles from this week that you may be interested in.Web application hacking: Inside the mind of an attacker Cross-site scripting 101: XSS attacks plague Web browsersFor all of my past information security tips and tricks be sure to check out www.principlelogic.com/resources.html.Enjoy!...
Continue Reading...