Drupal websites hacked using SQL injection flaw

Hahahahahahaha. Wut. What software today still allows SQL injection? Bad dev.
 
Hahahahahahaha. Wut. What software today still allows SQL injection? Bad dev.

2 years ago i injected into our companies www.I scraped all the passwords and logins for the hosting company and then emailed them their whole database in excel.To this date I still havnt been thanked for exposing their weak ass security.
 
The problem is that it's a security problem that's been fixed for yonks. How do developers still use a method they know is unsafe, when a trivially simple secure function exists?
 
Hahahahahahaha. Wut. What software today still allows SQL injection? Bad dev.

I agree that it's bad development. OTOH SQL injection still tops OWASP's top ten ...
 
2 years ago i injected into our companies www.I scraped all the passwords and logins for the hosting company and then emailed them their whole database in excel.To this date I still havnt been thanked for exposing their weak ass security.
It's also unlikely that they have fixed the problem :)
 
Top
Sign up to the MyBroadband newsletter
X