<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>FireBlog &#124; FireHost &#187; SQL Injections</title>
	<atom:link href="http://www.fireblog.com/tag/sql-injections/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.fireblog.com</link>
	<description>Secure Hosting Blog</description>
	<lastBuildDate>Thu, 29 Jul 2010 14:23:20 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>USA Today: Cyberthieves find workplace networks are easy pickings</title>
		<link>http://www.fireblog.com/usa-today-cyberthieves-find-workplace-networks-are-easy-pickings/</link>
		<comments>http://www.fireblog.com/usa-today-cyberthieves-find-workplace-networks-are-easy-pickings/#comments</comments>
		<pubDate>Fri, 16 Oct 2009 14:00:17 +0000</pubDate>
		<dc:creator>FireHost Evangelist</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[data theft]]></category>
		<category><![CDATA[SQL Injections]]></category>
		<category><![CDATA[war driving]]></category>

		<guid isPermaLink="false">http://www.fireblog.com/?p=1821</guid>
		<description><![CDATA[On average, it takes five to six months before companies detect data leaks and network breaches. TJ Max and Heartland breaches revealed that war driving and SQL injection attacks are some of the most popular means by which cyber criminals carry out malicious data theft schemes.]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.fireblog.com/wp-content/uploads/2009/10/officeplace_r2_c2.jpg" alt="officeplace_r2_c2" title="officeplace_r2_c2" width="163" height="106" class="alignright size-full wp-image-2391" />Between TJ Max and Heartland Payment Systems, cyber thieves compromised a quarter of a million credit card numbers. Court records from the trial of Albert Gonzalez, a hacker that plead guilty to fraud and conspiracy charges in both cases, reveal just how easily the thieves behind these breaches were able to obtain the information.</p>
<p><strong>Cyber Criminal Technique #1: War Driving</strong></p>
<p>War driving means &#8220;cruising&#8221; for WiFi signals. Once detected, cybercriminals use FREE password-breaking software to intercept the signal broadcasting from any home or business.</p>
<p>Monitoring WiFi networks over time, cyberthieves can establish a virtual private network and connect directly to a server or database.</p>
<p><strong>Cyber Criminal Technique #2: SQL Injection</strong></p>
<p>SQL injections are a popular way for cybercriminals to get inside &#8220;protected networks&#8221;. In a SQL injection attack, the hacker types random characters into a web form, such as a log in page. The attack may be carried out manually or using a robot to penetrate the form. Once inside, hackers can gain access to databases containing sensitive, personal information.</p>
<p>War driving and SQL injection attacks are the means to a cyber criminal&#8217;s end. Once the target server is breached, he or she implants a &#8220;sniffer&#8221; program. (<em>Sniffers are widely available for free, and they are capable of logging all traffic moving across a network)</em>. Savvy hackers have devised and sell sniffers designed specifically to detect and record credit and debit card information.</p>
<p><span id="more-1821"></span></p>
<p>Wade Baker, Verizon Business&#8217; principal researcher told <a href="http://www.usatoday.com/tech/news/computersecurity/2009-10-08-cyberthieves-network-hackers_N.htm" target="_blank">USA Today</a>, it takes five to six months (on average) before companies detect cybercrimes of this nature. In the vast majority of cases he has researched, cyberthieves spent days after the initial breach to locate databases with the most valuable information, then methodically extracted the sensitive data for weeks or years before being detected. He warns, &#8220;Many organizations right now have breaches they don&#8217;t know about and won&#8217;t discover for some time to come.&#8221;</p>
<p>The Identity Theft Resource Center (<a href="http://www.idtheftcenter.org/" target="_blank">ITRC</a>) has investigated about 400 incidents consisting of over 220 million exposed records so far this year. The list of victims proves that lengthy and destructive breaches are not reserved for global enterprise. SMBs, particularly businesses that provide retail, financial, and healthcare services are prime targets.</p>
<p>&#8220;The highly available and free nature of the tools necessary to carry out war driving and SQL injection attacks means novice hackers are capable of producing devastating breaches. Achieving PCI Compliance and partnering with a hosting partner that provides security will help prevent you from making the ITRC&#8217;s list,&#8221; advises Chris Drake, CEO and Founder of FireHost.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.fireblog.com/usa-today-cyberthieves-find-workplace-networks-are-easy-pickings/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Inquisitive Hackers Compromise Curious George Website</title>
		<link>http://www.fireblog.com/inquisitive-hackers-compromise-curious-george/</link>
		<comments>http://www.fireblog.com/inquisitive-hackers-compromise-curious-george/#comments</comments>
		<pubDate>Fri, 25 Sep 2009 14:00:12 +0000</pubDate>
		<dc:creator>FireHost Evangelist</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[ftp vulnerability]]></category>
		<category><![CDATA[Secure Web Hosting]]></category>
		<category><![CDATA[Security Threats]]></category>
		<category><![CDATA[SQL Injections]]></category>

		<guid isPermaLink="false">http://www.fireblog.com/?p=2198</guid>
		<description><![CDATA[The Curious George childrens' television show was propagating malware from at least Monday until Thursday last week. It's not clear how how hackers were able to break into the site, but it is possible that they obtained the credentials to an FTP account or exploited an SQL injection vulnerability.]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-full wp-image-2236" title="effedGeorge" src="http://www.fireblog.com/wp-content/uploads/2009/09/effedGeorge.jpg" alt="effedGeorge" width="118" height="184" />The <a href="http://pbskids.org/curiousgeorge/" target="_blank">Curious George</a> childrens&#8217; television show, which is run by  the Public Broadcasting Service (PBS), was propagating malware from at least Monday until Thursday last week.</p>
<p>Nidhi Shah, a research scientist at Purewire told <a href="http://www.scmagazineus.com/PBS-Curious-George-site-hacked-to-serve-malware/article/149244/" target="_blank">SCMagazineUS.com</a>, &#8220;It&#8217;s not clear how how hackers were able to break into the site, but it is possible that they obtained the credentials to an FTP account or exploited an SQL injection vulnerability.&#8221;</p>
<p>The exploit manifested as a pop up for visitors to authenticate their session with a username and password before viewing the site contents. When users canceled the message screen or entered the wrong credentials, an error page informed them that they had failed to login properly. That error page contained JavaScript code which loaded malware from an exploit site targeting a number of known software vulnerabilities in Adobe Acrobat Reader, AOL Radio AmpX and SuperBuddy and Apple QuickTime. Any user not patched against these bugs received the malware.</p>
<p><span id="more-2198"></span></p>
<p>It&#8217;s undetermined how many people encountered the attack, but Kevin Dando, director of digital and education communications at PBS believes the exposure to be very low since PBS has not received complaints. Mr. Dando told SCMagazineUS.com that internal triggers had alerted them to the situation. They  addressed it quickly, and that the situation has been completely fixed as of last Friday.</p>
<p>In his closing comments, Mr. Dando warned &#8220;that this incident should serve as a reminder that any system can potentially be exposed to infection, and service providers must remain vigilant against threats and be prepared to act aggressively and be ready with pre-established procedures.&#8221;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.fireblog.com/inquisitive-hackers-compromise-curious-george/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SQL Injection Vulnerability Exposes Sensitive Details about Ride Share Users in S. California</title>
		<link>http://www.fireblog.com/sql-injection-vulnerability-exposes-sensitive-details-about-ride-share-users-in-s-california/</link>
		<comments>http://www.fireblog.com/sql-injection-vulnerability-exposes-sensitive-details-about-ride-share-users-in-s-california/#comments</comments>
		<pubDate>Tue, 15 Sep 2009 14:00:50 +0000</pubDate>
		<dc:creator>FireHost Evangelist</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Hackers]]></category>
		<category><![CDATA[security bugs]]></category>
		<category><![CDATA[SQL Injections]]></category>
		<category><![CDATA[Website Vulnerabilities]]></category>

		<guid isPermaLink="false">http://www.fireblog.com/?p=2134</guid>
		<description><![CDATA[Programming errors on RideMatch.info allow hackers to access names, home addresses, phone numbers, commuting schedules, and employee ID numbers for the service's users.]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-full wp-image-2145" title="rideshareFinal" src="http://www.fireblog.com/wp-content/uploads/2009/09/rideshareFinal.jpg" alt="rideshareFinal" width="140" height="115" />Programming errors on <a href="https://www.ridematch.info/service.asp" target="_blank">RideMatch.info</a> allow hackers to access names, home addresses, phone numbers, commuting schedules, and employee ID numbers for the service&#8217;s users according to an <a href="http://www.theregister.co.uk/2009/09/08/ridematch_website_vulnerability/" target="_blank">article</a> featured in The Register.</p>
<p>The RideMatch.info flaw provides inadequate scrutiny of user-generated text entered in search boxes and fields throughout the website. Hackers exploit the SQL injection vulnerability by passing commands directly into the back end database.</p>
<p>The vulnerability was identified and reported in August by Kristian Hermansen, a security researcher who was required by his employer to sign up for the service. His report to The Register stated, &#8220;The reason I am bringing this to your attention is that the issue is not being fixed by the admins and most companies don&#8217;t even know that their employee&#8217;s personal and corporate information may be been compromised.&#8221;</p>
<p>To date, the exploit has exposed hundreds of employees&#8217; sensitive information across several organizations in S. California, including at least one military entity.</p>
<p><span id="more-2134"></span></p>
<p>The Ride Match website is a joint project between five regional transit authorities. The service pairs commuters based on home and office destinations as well as departure times. The Riverside County Transportation Commission, an agency responsible for the website, reported to have reached out to the Trapeze Group (a Canada-based development company that designed the software) right after the vulnerability was reported.</p>
<p>Once identified, SQL injection vulnerabilities can often be patched by changing a line or two of code, but The Register spoke to a Trapeze spokesperson on 9/8, and at that time she was unaware of any security bugs being reported on the software. She promised that any vulnerabilities brought to their attention would be investigated and resolved.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.fireblog.com/sql-injection-vulnerability-exposes-sensitive-details-about-ride-share-users-in-s-california/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Social Networks Targeted by Hackers More Often than Government &amp; Law Agencies in &#8217;09</title>
		<link>http://www.fireblog.com/social-networks-targeted-by-hackers-more-often-than-government-law-agencies-in-09/</link>
		<comments>http://www.fireblog.com/social-networks-targeted-by-hackers-more-often-than-government-law-agencies-in-09/#comments</comments>
		<pubDate>Fri, 21 Aug 2009 14:00:41 +0000</pubDate>
		<dc:creator>FireHost Evangelist</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Cross Site Scripting]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Prevent Hackers]]></category>
		<category><![CDATA[Secure Web Hosting]]></category>
		<category><![CDATA[SQL Injections]]></category>

		<guid isPermaLink="false">http://www.fireblog.com/?p=1943</guid>
		<description><![CDATA[Security experts believe social networks like Twitter and Facebook are targeted because of the sheer number of users. Defacement is the most common motivation for ego-driven hackers, and these high traffic, high involvement communities are a great way to disrupt many victims at once.]]></description>
			<content:encoded><![CDATA[<p>This year, social networking sites have become popular  targets for cyber crime according to a <a href="http://www.pcworld.com/businesscenter/article/170287/hackers_put_social_networks_such_as_twitter_in_crosshairs.html" target="_blank">study of hacking episodes</a> by Web Hacking Incidents Database (WHID). This is a shift from 2008 when government and law enforcement agencies were the most enticing targets.</p>
<p><img class="alignright size-full wp-image-1961" style="margin-left:22px;" title="socialTargets" src="http://www.fireblog.com/wp-content/uploads/2009/08/socialTargets.jpg" alt="socialTargets" width="169" height="104" /></p>
<p>Security experts believe social networks like Twitter and Facebook are targeted because of the sheer number of users. Defacement is the most common motivation for ego-driven hackers, and these high traffic, high involvement communities are a great way to disrupt many victims at once.</p>
<p>A <a href="http://www.pcworld.com/article/167511/beware_identity_thieves_harvest_social_networks.html?tk=rel_news" target="_blank">study by Webroot</a> sheds light on a few other reasons why social networks make a ripe targets for hackers.</p>
<ul>
<li>36% of social networkers admit they don&#8217;t hide personal information</li>
<li>33% admit to using the same password for all of their online accounts</li>
<li>28% accept &#8220;friend requests&#8221; from strangers</li>
</ul>
<p>With such a high percent of social networking users being unaware of the dangers, &#8220;hackers lure users into taking actions they shouldn&#8217;t by making it appear as if a friend within their social netowrk has sent them a message &#8211; only the message is from a hacker who has hijacked the friend&#8217;s account,&#8221; warns Mike Kronenberg CTO of Webroot&#8217;s Consumer Business division.</p>
<p><span id="more-1943"></span></p>
<p>The technique described by Mr. Kronenberg is known as <a href="http://security.firehost.com/terms/phishing" target="_blank">phishing</a>, and it&#8217;s one of the most preventable ways hackers obtain access to confidential information. <a href="http://security.firehost.com/terms/sql-injection" target="_blank">SQL injections</a>, Cross-site Scripting <a href="http://security.firehost.com/terms/cross-site-scripting" target="_blank">(XSS)</a>, and Cross-site Forgery Requests (CSFR) are more covert, technical methods that hackers use to get the infomation they need.</p>
<p>&#8220;As a web service or SaaS provider, you can help protect your users from these attacks by hosting your applications in a <a href="http://www.firehost.com/secure-hosting" target="_blank">secure environment</a>. Users need to be savvy, and when they can&#8217;t stay up to speed on all the risks, community users should be weary and overly cautious at all times,&#8221; suggests Chris Drake, CEO of FireHost.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.fireblog.com/social-networks-targeted-by-hackers-more-often-than-government-law-agencies-in-09/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Web 2.0 Enabled Sites Wear a Target for Cybercrime</title>
		<link>http://www.fireblog.com/web-2-0-sites-wear-a-target-for-cybercrime/</link>
		<comments>http://www.fireblog.com/web-2-0-sites-wear-a-target-for-cybercrime/#comments</comments>
		<pubDate>Fri, 24 Jul 2009 14:00:11 +0000</pubDate>
		<dc:creator>FireHost Evangelist</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[protect open source applications]]></category>
		<category><![CDATA[SQL Injections]]></category>
		<category><![CDATA[Website Security]]></category>
		<category><![CDATA[WordPress Plugins]]></category>

		<guid isPermaLink="false">http://www.fireblog.com/?p=1335</guid>
		<description><![CDATA[Businesses who incorporate Web 2.0 functionality like social networks, wikis, and blogs are the most popular targets for hackers. In fact, websites that incorporate these features accounted for 21% of hacking incidents reported in the first quarter of 2009.]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.fireblog.com/wp-content/uploads/2009/07/20Target.jpg" alt="20Target" title="20Target" width="146" height="139" class="alignright size-full wp-image-1784" />Data compiled by <a href="http://secure-enterprise20.org/node/2" target="_blank">Secure Enterprise 2.0</a> indicates that businesses who incorporate Web 2.0 functionality like social networks, wikis, and blogs are the most popular targets for hackers.</p>
<p>In fact, websites that incorporate these features accounted for 21% of hacking incidents reported in the first quarter of 2009. The top threats to &#8220;socially enabled&#8221; websites are <a href="http://security.firehost.com/terms/sql-injection" target="_self">SQL Injections</a> (21% of attacks), Authentication Abuse (18%), and Cross Site Request Forgery &#8211; CSRF (8%). You may download a full copy of Secure Enterprise&#8217;s report <a href="http://secure-enterprise20.org/node/39" target="_blank">here</a>.</p>
<p>&#8220;Businesses often use open source applications like <a href="http://www.firehost.com/secure-hosting/community-server" target="_self">Community Server</a>, <a href="http://www.firehost.com/secure-hosting/wordpress" target="_self">WordPress</a>, and <a href="http://www.firehost.com/secure-hosting/drupal" target="_self">Drupal</a> to integrate social features into their websites. Every enterprise deserves the ability to keep content fresh by using blogs and forums. It&#8217;s great for marketing and user retention. We help facilitate these mediums by addressing vulnerabilities in open source software all the way from module installation to hosting,&#8221; encourages FireHost CEO, Chris Drake.</p>
<p>FireHost CTO, Kevin Wall explains why a holistic approach to site development and hosting is important.<span id="more-1335"></span></p>
<p style="padding-left: 30px;">&#8220;Often the application itself isn&#8217;t unstable; it&#8217;s the add-ons and plug-ins site owners use to extend the installation that cause problems. Our engineers are well-versed in the nuances of open source platforms. We&#8217;re different because we can help you navigate thru the many open source options available and determine which will achieve your marketing goals. Finally, we install open source applications in a way that helps protect you from hackers.&#8221;</p>
<p>To learn more about how FireHost can help secure your favorite open source platform, visit our secure <a href="http://www.firehost.com/secure-hosting/platforms" target="_self">platform hosting</a> page.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.fireblog.com/web-2-0-sites-wear-a-target-for-cybercrime/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>USA Today: &#8220;SQL Injection Attacks Hit 450,000 a Day&#8221;</title>
		<link>http://www.fireblog.com/usa-today-sql-injection-attacks-hit-450000-a-day/</link>
		<comments>http://www.fireblog.com/usa-today-sql-injection-attacks-hit-450000-a-day/#comments</comments>
		<pubDate>Fri, 20 Mar 2009 14:00:11 +0000</pubDate>
		<dc:creator>FireHost Evangelist</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Application Protection]]></category>
		<category><![CDATA[Prevent Hackers]]></category>
		<category><![CDATA[Secure Web Hosting]]></category>
		<category><![CDATA[SQL Injections]]></category>
		<category><![CDATA[Website Vulnerabilities]]></category>

		<guid isPermaLink="false">http://www.fireblog.com/?p=312</guid>
		<description><![CDATA[SQL attacks are preventable when your website, email, databases, and other applications are hosted with a security-focused web hosting provider. FireHost has taken industry-leading measures to make enterprise-level security attainable for every business because we know that the last thing you need to do with your time is mitigate a high-profile website attack on customer information.]]></description>
			<content:encoded><![CDATA[<p>Modern cybercriminals are out to do harm. Simple as that. They penetrate vulnerable websites, steal private customer information, and commit identity theft every day. Hacker tools and methods of attack have become more sophisticated and wider in scope in recent months.</p>
<p><span class="inside-head"><span style="background-color: #ffffff;"><a href="http://www.usatoday.com/money/industries/technology/2009-03-16-sql-attacks-cyber-security_N.htm">USA Today reports</a>:</span></span></p>
<div style="margin-left: 40px;">SQL attacks take aim at the database layer of websites. They typically were manual attacks designed to pilfer customer data from merchant websites. But last June someone figured out how to automate the attacks, and use them to plant infections. By mid-June, daily attacks spiked to 25,000; by October they topped 450,000 a day.</div>
<div style="margin-left: 40px;">
<p>Holly Stewart, IBM ISS threat response manager, says the infections take advantage of security flaws in cool website features, such as online-delivered video, music, photos, documents and work files.</p></div>
<div style="margin-left: 40px;">
<p>Giant financial institutions and online merchants have put up strong defenses, says Phil Neray, vice president of security strategy at Guardium, a database security firm. &#8220;The same is not necessarily true of regional banks and credit unions, smaller online retailers and state government agencies.&#8221;</p></div>
<p>FireHost is in business to address website security needs of the &#8220;smaller guys&#8221; Mr. Neray mentions above. It&#8217;s imperative your company respond to the threat of cybercriminals swiftly and effectively because SQL attacks strike <a href="http://www.theregister.co.uk/2008/04/24/mass_web_attack/">governments</a> and <a href="http://www.usatoday.com/money/perfi/credit/2009-01-20-heartland-credit-card-security-breach_N.htm">credit card companies</a> every day. FireHost can help your company avoid the negative spotlight.</p>
<p>SQL attacks <strong>are</strong> <strong>preventable </strong>when your website, email, databases, and other applications are hosted with a security-focused web hosting provider. We&#8217;ve taken industry-leading measures to make <a title="Enterprise-level Security" href="http://www.firehost.com/secure-hosting" target="_blank">enterprise-level security</a> attainable for every business because we know that the last thing you need to do with your time is mitigate a high-profile website attack on customer information.</p>
<p>Most hosting providers don&#8217;t invest the resources required to maintain a prevention-focused, secure hosting environment. If your company does business online however, you owe it to your customers and employees to make sure their most important information is protected.</p>
<p>Here&#8217;s just a sample of what puts FireHost secure web hosting in a class of its own:</p>
<p><strong>Network Layer Security</strong><br />
FireHost runs dual Sonicwall internet security devices, providing firewall redundancy for every client. This layer safegaurds websites, emails, and databases from unauthorized intrusions, like SQL attacks.</p>
<p><strong>Application Protection</strong><br />
We also run a web application firewall to close the holes within your website&#8217;s applications, the entry-point for SQL attacks.</p>
<p><strong>Vulnerability Monitoring</strong><br />
FireHost partners with McAfee to provide you with web-based website vulnerability auditing and remediation mangement, completing scans every fifteen minutes.</p>
<p><strong>Register </strong><strong><a href="http://www.firehost.com/secure-hosting/vulnerability-audit">here</a> to have a FireHost Security Agent perform a </strong><strong>vulnerability report for your website. We will contact you shortly with the eye-opening results.<br />
</strong></p>
]]></content:encoded>
			<wfw:commentRss>http://www.fireblog.com/usa-today-sql-injection-attacks-hit-450000-a-day/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Why You Need SQL Injection Protection</title>
		<link>http://www.fireblog.com/why-you-need-sql-injection-protection/</link>
		<comments>http://www.fireblog.com/why-you-need-sql-injection-protection/#comments</comments>
		<pubDate>Mon, 03 Nov 2008 11:25:59 +0000</pubDate>
		<dc:creator>FireHost Evangelist</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Application Protection]]></category>
		<category><![CDATA[application security]]></category>
		<category><![CDATA[Hosting]]></category>
		<category><![CDATA[SQL Injections]]></category>
		<category><![CDATA[Vulnerabilities]]></category>
		<category><![CDATA[Website Hacking]]></category>
		<category><![CDATA[Website Security]]></category>

		<guid isPermaLink="false">http://www.fireblog.com/?p=58</guid>
		<description><![CDATA[SQL Injections have website owners and developers running scared. If you haven&#8217;t heard of a SQL Injection, then you better listen up and hit Google university. SQL Injections are the number one vulnerability exploited by hackers, by far. According to security vendor Sophos, 16,000 new websites are hit by the attacks every day. WordPress, Joomla, [...]]]></description>
			<content:encoded><![CDATA[<p>SQL Injections have website owners and developers running scared. If you haven&#8217;t heard of a SQL Injection, then you better listen up and hit Google university.</p>
<p>SQL Injections are the number one vulnerability exploited by hackers, by far. According to security vendor Sophos, 16,000 new websites are hit by the attacks every day. WordPress, Joomla, Drupal, .NET, classic ASP, PHPBB websites have all been hit with SQL Injections. Do NOT roll the dice on this one! Every web site big or small is vulnerable to injection by automated scripts attempting SQL-Injections through your webforms, dynamic URLs, etc.</p>
<p>This video from Graham Cluley of Sophos discusses the impact of a SQL Injection that hit BusinessWeek.</p>
<p><object id="viddler" classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="545" height="347" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="allowScriptAccess" value="always" /><param name="allowFullScreen" value="true" /><param name="wmode" value="transparent" /><param name="src" value="http://www.viddler.com/player/30f164a6/" /><param name="allowfullscreen" value="true" /><embed id="viddler" type="application/x-shockwave-flash" width="545" height="347" src="http://www.viddler.com/player/30f164a6/" wmode="transparent" allowfullscreen="true" allowscriptaccess="always"></embed></object></p>
<p style="text-align: left;">
<p style="text-align: left;"><strong>What can you do NOW to help secure your website?</strong></p>
<ol>
<li>Ensure all logins use strong passwords</li>
<li>Employ web form validation and/or <a href="http://en.wikipedia.org/wiki/Captcha" target="_blank">CAPTCHA</a></li>
<li>If you&#8217;re using a CMS or website platform, ensure it&#8217;s up-to-date (including all plug-ins)</li>
<li>Ensure all components are current (ASPupload, etc)</li>
<li>Use static URLs instead of dynamic URLs</li>
</ol>
<p><strong>FireHost takes SQL Injection protection to the next level by:<br />
</strong></p>
<ol>
<li><a href="http://www.firehost.com/secure-hosting/vulnerability-audit">Analyzing</a> your website and web applications to assess the potential for SQL Injections and other hacking vulnerabilities</li>
<li><a href="http://www.firehost.com/secure-hosting">Protecting</a> your website using our secure and transparent Web Application Firewall</li>
<li><a title="Vulnerability Monitoring" href="http://www.firehost.com/secure-hosting/vulnerability-monitoring">Monitoring</a> your website for new vulnerabilities</li>
</ol>
]]></content:encoded>
			<wfw:commentRss>http://www.fireblog.com/why-you-need-sql-injection-protection/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
