![]() |
|
#1
|
|||
|
|||
|
Source: http://hackersblog.org/2009/02/18/em...sql-injection/
Quote:
my point for debate is this: if big guys like symantec or f secure and kaspersky cant secure their sites, then what chance deos any small business owner or online retailer have to secure their payment system and customer data? also, is it actually possible to design a website to be completely resilient to attacks like this especially when it has probably been put together by many different people p.s be easy on me, new poster ![]() |
|
#2
|
|||
|
|||
|
Two things: 1. The larger corporations often have the worst security due to either lack of funding going into it or just plain lack of oversight. 2. Corporations as big as Norton have a bigger bullseye painted on their back because of the bigger payday attackers can receive both financially and in "bragging rights". Smaller businesses dont have as much of a problem because of this.
To answer the last question, you can't foolproof a website or anything else, because there is always someone out there working on the next method of attack. The best you can hope for is temporary safety. |
|
#3
|
|||
|
|||
|
Quote:
__________________
Windows 8 Enterprise 64-bit
Windows Defender | Hitman Pro | MBAM Pro | Macrium Reflect Last edited by ambient_88 : February 20th, 2009 at 11:14 PM. |
|
#4
|
||||
|
||||
|
Symantec's response on Unu's blog pours cold water on his claim.
"We would like to provide you with an update on the vulnerability reported yesterday, on hackersblog.org, for the emea.symantec.com website. Upon thorough investigation, we have determined that the Blind SQL Injection is, in fact, not effective. The difference in response between valid and injected queries exists because of inconsistent exception handling routine for language options. Thanks again for notifying us of the issue. We will have the modified page up again soon with better exception handling."
__________________
If it was so, it might be; and if it were so, it would be; but as it isn't, it ain't. That's logic. ~ Twiddledee |
|
#5
|
|||
|
|||
|
Quote:
That's an expected response, any serious company is going to do PR damage control. |
|
#6
|
||||
|
||||
|
Quote:
__________________
switching from one AV to another very often Rollback RX On demand: HitMan Pro |
|
#7
|
||||
|
||||
|
It seems to me that no matter what the response from the company that has been attacked it will always be regarded as lies designed to limit damage even if the hackers have not done what they have claimed
We all know nothing is 100% foolproof and that incudes security on even the most secure sites,they are only secure until someone figures out how to circumvent the measures employed. The problem is that these hackers make bold claims way beyond what they have actually been able to achieve because they are after some kind of fame(notoriety)within the circle the move
__________________
The part of a computer that causes most problems is the bit that holds the mouse! |
|
#8
|
|||
|
|||
|
Quote:
__________________
Windows 8 Enterprise 64-bit
Windows Defender | Hitman Pro | MBAM Pro | Macrium Reflect |
| « Previous Thread | Next Thread » |
| Thread Tools | Search this Thread |
|
|