CyberArmy University | Open Source Institute | CyberArmy Intelligence & Security | CyberArmy Services & Projects

To be honest...


[Replies] [Reply] [View by Thread] [Help]
[Back To Security]

Posted by Lt Obscurity On 2004-03-23 08:21:38
In Reply to RE: Want Some Opinions Posted by Ker JeiAr On 2004-03-23 08:05:01

Lt
Lt Obscurity


You're logic is FAR from flawed, and it's completely viable. I've seen Security Patches punched out for far less then that. And again, to be honest, I think of it as a rather 'script-kiddie' exploit (no offense, see my explenation after this).

I see it as this:

A script kiddie can go to Security Focus, read one of their SQL Injection articles on Blind-Side Injection, read Sam's SQL in 10 minutes guide, figure out what the table names are. Then bam, he posts his specially crafted query, and you have a huge mess of a compromise.

So essentially you have a rather heavy vulnerability, and possible compromise of the entire database.

Damn... You should E-Picket their PHPbb's E-Front Doors :)

But seriously, how hard is it going to be to convince them?

Catch me on CAIRC
  • #FirewallProject
  • #CA-UUG
  • #BSD
  • #Metal



Replies:


Guest:
Subject:
Message:
Signature:
Optional Image Link:
http://

CyberArmy::Forum v0.6
Generated In 0.01064 seconds


About Us | Privacy Policy | Mission Statement | Help