<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>FireBlog &#124; FireHost &#187; security bugs</title>
	<atom:link href="http://www.fireblog.com/tag/security-bugs/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.fireblog.com</link>
	<description>Secure Hosting Blog</description>
	<lastBuildDate>Wed, 11 Aug 2010 19:40:07 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>SQL Injection Vulnerability Exposes Sensitive Details about Ride Share Users in S. California</title>
		<link>http://www.fireblog.com/sql-injection-vulnerability-exposes-sensitive-details-about-ride-share-users-in-s-california/</link>
		<comments>http://www.fireblog.com/sql-injection-vulnerability-exposes-sensitive-details-about-ride-share-users-in-s-california/#comments</comments>
		<pubDate>Tue, 15 Sep 2009 14:00:50 +0000</pubDate>
		<dc:creator>FireHost Evangelist</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Hackers]]></category>
		<category><![CDATA[security bugs]]></category>
		<category><![CDATA[SQL Injections]]></category>
		<category><![CDATA[Website Vulnerabilities]]></category>

		<guid isPermaLink="false">http://www.fireblog.com/?p=2134</guid>
		<description><![CDATA[Programming errors on RideMatch.info allow hackers to access names, home addresses, phone numbers, commuting schedules, and employee ID numbers for the service's users.]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-full wp-image-2145" title="rideshareFinal" src="http://www.fireblog.com/wp-content/uploads/2009/09/rideshareFinal.jpg" alt="rideshareFinal" width="140" height="115" />Programming errors on <a href="https://www.ridematch.info/service.asp" target="_blank">RideMatch.info</a> allow hackers to access names, home addresses, phone numbers, commuting schedules, and employee ID numbers for the service&#8217;s users according to an <a href="http://www.theregister.co.uk/2009/09/08/ridematch_website_vulnerability/" target="_blank">article</a> featured in The Register.</p>
<p>The RideMatch.info flaw provides inadequate scrutiny of user-generated text entered in search boxes and fields throughout the website. Hackers exploit the SQL injection vulnerability by passing commands directly into the back end database.</p>
<p>The vulnerability was identified and reported in August by Kristian Hermansen, a security researcher who was required by his employer to sign up for the service. His report to The Register stated, &#8220;The reason I am bringing this to your attention is that the issue is not being fixed by the admins and most companies don&#8217;t even know that their employee&#8217;s personal and corporate information may be been compromised.&#8221;</p>
<p>To date, the exploit has exposed hundreds of employees&#8217; sensitive information across several organizations in S. California, including at least one military entity.</p>
<p><span id="more-2134"></span></p>
<p>The Ride Match website is a joint project between five regional transit authorities. The service pairs commuters based on home and office destinations as well as departure times. The Riverside County Transportation Commission, an agency responsible for the website, reported to have reached out to the Trapeze Group (a Canada-based development company that designed the software) right after the vulnerability was reported.</p>
<p>Once identified, SQL injection vulnerabilities can often be patched by changing a line or two of code, but The Register spoke to a Trapeze spokesperson on 9/8, and at that time she was unaware of any security bugs being reported on the software. She promised that any vulnerabilities brought to their attention would be investigated and resolved.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.fireblog.com/sql-injection-vulnerability-exposes-sensitive-details-about-ride-share-users-in-s-california/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
