首页    期刊浏览 2025年12月03日 星期三
登录注册

文章基本信息

  • 标题:Is Your Web Site at Risk of Injection?
  • 作者:Regina Kwon
  • 期刊名称:Baseline
  • 印刷版ISSN:1541-3004
  • 出版年度:2002
  • 卷号:November 2002
  • 出版社:Ziff Davis Enterprise Inc.

Is Your Web Site at Risk of Injection?

Regina Kwon

Robbing banks is dangerous and unpredictable, and it requires leaving the house. Hacking, on the other hand, has a high success rate, pays well (extortionists ask for--and get--an average of $160,000 per hack) and can be done in one's pajamas.

"The attacks work because the software most people use has vulnerabilities," says Alan Paller, Director of Research at the SANS Institute, a security watchdog. The first challenge, he says, is simply to find out what those vulnerabilities are. "It's like owning a car, and every week there are new defects. But no one tells you what they are. Instead, you're supposed to somehow divine them."

Sites that use scripts to create pages dynamically are particularly prone to attacks. Because the back-end applications of a dynamic site view the Web server as a "trusted source," seemingly innocent text fields can act as entry points for malicious requests. One such attack, SQL Injection, could lead to a site's entire back-end database being downloaded by a hacker, says Caleb Sima, chief technology officer and cofounder of security vendor SPI Dynamics. "The problem is extremely common," he says.

Sima has provided steps for testing your own Web site for SQL Injection and other vulnerabilities. Click here to get started.

Copyright © 2004 Ziff Davis Media Inc. All Rights Reserved. Originally appearing in Baseline.

联系我们|关于我们|网站声明
国家哲学社会科学文献中心版权所有