Welcome to Dream.In.Code
Getting Help is Easy!

Join 86,240 Programmers. There are 2,287 online right now! Ask your question and get quick answers from Dream.In.Code experts. Join the #1 programming help community on the internet! Registration is fast and FREE... Join Now!

Chat LIVE With a Expert
Powered by LivePerson.com

Register to Make This Box Go Away!

Sad state of affairs...

2 Pages V  1 2 >  
Reply to this topicStart new topic

Sad state of affairs...

PsychoCoder
post 26 Apr, 2008 - 08:14 AM
Post #1


ToCode || !ToCode

Group Icon
Joined: 26 Jul, 2007
Posts: 5,857



This morning, simply because I was bored, I did a search on Google, using a certain query (I will not post it here as we will have every script kiddie/wannabe hacker doing it) to see how many sites out there are still putting their SQL queries in the querystring. Google returned 48,700 results, thats 48,700 chances to ruin someone's site, and the majority of them ended in .gov. Yes government sites that make SQL Injection even more simple to accomplish. Who do they contract to do their web development? I thought that more developers realized that this is probably one of the worst ideas when it comes to creating a site.

Please tell me that none of our members here are insane enough to develop and deploy sites in this manner. It's sad that our government would allow such security holes to be deployed, to be used in releasing their information to the general public. I don't know about you, but that goes a long way in removing any respect I have for our government (this is not a political discussion so please don't turn it into one).

This is one that it turned up, site name removed to protect the stupid


QUOTE

http://<removed>.gov/services/agreements.asp?p=20&ps=&q=SELECT+B.applicant_name%2C+B.trade_name%2C+B.bus_address_f_no
%2C+B.bus_street%2C+B.bus_quad%2C+A.id%2C+A.entity%2C+A.patrol_service_area%2C+A.expiration_status%2C+A.expiration_date
%2C+A.investigator%2C+A.pdf%2C+A.url+FROM+abra_rw.tblLicense_hold+AS+B%2C+abra_rw.agreements+AS+A+WHERE+B.id+%3D
+A.business_id+AND+applicant_name+LIKE+'%25%25'+ORDER+by+B.applicant_name%3B


Do they not realize how easy it would be to wipe all this data out?
User is online!Profile CardPM
Go to the top of the page
+Quote Post


Nykc
post 26 Apr, 2008 - 08:39 AM
Post #2


DIC == Huge!

Group Icon
Joined: 14 Sep, 2007
Posts: 2,293

Hey Psycho you should email them and let them know how stupid they are. You might get a medal.

You know tell them how to fix their flaw. It could be a minor contribution to making the internet a safer place.

This post has been edited by Nykc: 26 Apr, 2008 - 08:41 AM
User is offlineProfile CardPM
Go to the top of the page
+Quote Post

girasquid
post 26 Apr, 2008 - 10:13 AM
Post #3


Barbarbar

Group Icon
Joined: 3 Oct, 2006
Posts: 953

I think this showed up on dailywtf not too long ago, with a sex offender registry.

This post has been edited by girasquid: 26 Apr, 2008 - 10:13 AM
User is online!Profile CardPM
Go to the top of the page
+Quote Post

Martyr2
post 26 Apr, 2008 - 10:30 AM
Post #4


Programming Theoretician

Group Icon
Joined: 18 Apr, 2007
Posts: 3,561

QUOTE
Yes government sites that make SQL Injection even more simple to accomplish. Who do they contract to do their web development?


Shhhhhh.... They are hiring people like Skyhawk and sloth.
User is offlineProfile CardPM
Go to the top of the page
+Quote Post

PsychoCoder
post 26 Apr, 2008 - 11:57 AM
Post #5


ToCode || !ToCode

Group Icon
Joined: 26 Jul, 2007
Posts: 5,857

QUOTE(girasquid @ 26 Apr, 2008 - 10:13 AM) *

I think this showed up on dailywtf not too long ago, with a sex offender registry.


That is just one instance of this stupidity, I remember reading that as well.
User is online!Profile CardPM
Go to the top of the page
+Quote Post

supersloth
post 26 Apr, 2008 - 02:12 PM
Post #6


Pwnership is nine tenths of the LOL

Group Icon
Joined: 21 Mar, 2001
Posts: 18,486

QUOTE(Martyr2 @ 26 Apr, 2008 - 11:30 AM) *

QUOTE
Yes government sites that make SQL Injection even more simple to accomplish. Who do they contract to do their web development?


Shhhhhh.... They are hiring people like Skyhawk and sloth.

we don't do that smile.gif
User is offlineProfile CardPM
Go to the top of the page
+Quote Post

Martyr2
post 26 Apr, 2008 - 03:27 PM
Post #7


Programming Theoretician

Group Icon
Joined: 18 Apr, 2007
Posts: 3,561

Of course not, you are top of the top... but I just didn't want him to bash government contracted web developers. Who knows what he would have said and then retaliation. Make DIC bust out in a civil war or something.

Because you know, then I would be forced to take a side or something, put on some military uniform, drafted into a game of COD4 or something. It would just get all ugly and messy.

biggrin.gif
User is offlineProfile CardPM
Go to the top of the page
+Quote Post

girasquid
post 26 Apr, 2008 - 03:31 PM
Post #8


Barbarbar

Group Icon
Joined: 3 Oct, 2006
Posts: 953

Aren't you from Canada? All we'd do in the case of a war is apologize.
User is online!Profile CardPM
Go to the top of the page
+Quote Post

Martyr2
post 26 Apr, 2008 - 03:53 PM
Post #9


Programming Theoretician

Group Icon
Joined: 18 Apr, 2007
Posts: 3,561

I am talking about a DIC civil war. Which you know would be global. A virtual war.

As for real life, yeah we would apologize because lets face it, our canoe against the US fleet or our wooden plane is not going to take our their squadron of fighters. They throw bombs, we throw rocks or hockey pucks. Whichever we have more of.

biggrin.gif
User is offlineProfile CardPM
Go to the top of the page
+Quote Post

RodgerB
post 26 Apr, 2008 - 05:16 PM
Post #10


D.I.C Lover

Group Icon
Joined: 21 Sep, 2007
Posts: 1,458

@PsychoCoder: I found the full address for the one you censored... what the hell were they thinking?
User is online!Profile CardPM
Go to the top of the page
+Quote Post

KYA
post 26 Apr, 2008 - 11:43 PM
Post #11


DIC DIC DIC DIC DIC DIC DIC DIC DIC DIC DIC DIC DIC DIC DIC DIC

Group Icon
Joined: 14 Sep, 2007
Posts: 1,318

QUOTE(girasquid @ 26 Apr, 2008 - 04:31 PM) *

Aren't you from Canada? All we'd do in the case of a war is apologize.


Quality.

On topic: Wow. I can't fully appreciate your findings since I don't fully understand the working of SQL, but you would think that the contracted people would know better.
User is offlineProfile CardPM
Go to the top of the page
+Quote Post

no2pencil
post 26 Apr, 2008 - 11:53 PM
Post #12


DIC K-mart

Group Icon
Joined: 10 May, 2007
Posts: 3,321

ROFL... I don't even have anything smart ass'ed to say. I'm dumbfounded.

The 1st time I learned about the evils (& power if missused) of the Unix eval command in a CGI-BIN script was from .gov sites being overthrown. This is where the shadow file came into play. But still, it was as simply as requesting for information from the URL.
User is online!Profile CardPM
Go to the top of the page
+Quote Post

2 Pages V  1 2 >
Fast ReplyReply to this topicStart new topic
Time is now: 5/16/08 08:14AM

Live Help!

Tutorials

Programming

Web Development

Reference Sheets

Code Snippets

Bye Bye Ads

Free DIC T-Shirt

T-Shirt Example

Related Sites

Monthly Drawing

Thumb Drive

Partners

Top Contributors

Top 10 Kudos This Month