Jump to content

MrSkippyJ

Members
  • Posts

    10293
  • Joined

  • Last visited

  • Days Won

    22

Posts posted by MrSkippyJ

  1. 26 minutes ago, srp365 said:

    You'd be surprised. I handle PCI compliance for our company, so I have to make sure all form submissions in our apps are sanitized... I sometimes point our ASV to our client's and partner's web APIs and get horrifying reports.

    SQL Injection is actually a basic hack, but also one of the most neglected security holes by devs, at least in my line of work.

     

     

    But do you think that whoever wrote the API for LPR cams ever thought to sanitize whatever it gets from reading license plates?

    I suppose it's overlooked, it just seems so simple to take care of that I can't imagine it not being taken care of. I had to write a research paper in my masters program and I wrote it on SQL injection. I started telling people about it at work and we realized all of our applications we write for in house projects were completely open to it. Luckily none of those applications pointed outside of our network or were accessible off network but someone inside could have really ruined some of our databases. We started asking some of the IT folks about it and they said it's always accounted for in the stuff they do.

  2. 6 hours ago, srp365 said:

    Image result for sql injection speed camera

     

     

    So this guy apparently has a lot of speed camera tickets. He's also a developer.

    This is his attempt at using SQL injection to clear the table holding the record of his license plate number.

    Do not know if it works, but it's fucking genius.

    SQL injection is pretty easy to stop, if that works then the company likely has some pretty major security issues. 

  3. Notifications were working for me, it's the little icons beside the thread that I don't see any more. There was a dot or star and it was greyed out unless there was a new post. They are just gone now. Minor thing though, nothing to worry about, just letting it be known something is up. I'm really liking the new forum and all it's options!

×
×
  • Create New...