54 Replies - 6897 Views - Last Post: 13 August 2012 - 10:11 AM
#16
Re: What was the cause of the redirects?
Posted 01 August 2012 - 02:39 PM
I was reading about an old IPBoard exploit that uses a SQL injection attack, but the attack only works in the setup mode of IPBoard. In IPBoard's shoes, that bug would probably be a lower priority since it's only the admin who should have access at setup time. The board should not be public yet at that time. But the mere fact that such an attack was possible means that not all the code uses prepared statements.
If a few months later somebody goes, "hey that code does exactly what I need, I'll just call it from the public facing part of IPBoard". Unless somebody does a code review of not only the new code the calls the function, and reviews the old function as well, the a public vulnerability has just been opened up. Some code reviewers don't bother looking at the old function because "It's been shipping for years. It must be okay to use it."
#17
Re: What was the cause of the redirects?
Posted 01 August 2012 - 02:39 PM
Duckington, on 01 August 2012 - 05:25 PM, said:
Dogstopper, on 01 August 2012 - 09:18 PM, said:
However, we lost most, if not all of today's posts.
I thought the whole point of prepared statements was that they seperated the instructions from the data, making it impossible to inject anything....
I know that's the point. But what I'm saying is that somehow it happened. Not sure on the details.
#18
Re: What was the cause of the redirects?
Posted 01 August 2012 - 02:39 PM
#19
Re: What was the cause of the redirects?
Posted 01 August 2012 - 02:53 PM
May be by advising visitors here not to use their tools!!!
#20
Re: What was the cause of the redirects?
Posted 01 August 2012 - 02:57 PM
#21
Re: What was the cause of the redirects?
Posted 01 August 2012 - 04:08 PM
atraub, on 01 August 2012 - 02:36 PM, said:
I personally find it funny, but I meant the exploit seemed like less of a prank and more of a targeted attack.
When I said "they know what they did" I really meant "I'm not sure how they did it" and "WTF, look at this crazy exploit"
Do you think DIC was a vulnerable blip on their radar, or do you think they targeted DIC?
#22
Re: What was the cause of the redirects?
Posted 01 August 2012 - 04:22 PM
#23
Re: What was the cause of the redirects?
Posted 01 August 2012 - 05:19 PM
Or are the server guys playing whack-a-mole and banning IP addresses as they see the attacks happen?
#24
Re: What was the cause of the redirects?
Posted 01 August 2012 - 05:43 PM
Skydiver, on 01 August 2012 - 04:39 PM, said:
I used to, until I realized that it's literally just as easy (often easier) to always use prepared statements, or an ORM that uses them for you. I haven't written a single SQL statement with string concatenated parameters in something like five years now.
#25
Re: What was the cause of the redirects?
Posted 01 August 2012 - 06:19 PM
I hope this doesn't happen anymore, who knows how much answered questions were lost due to this attack. Lots of stuff seemed to be lost, is there any way to bring them back, or are they deleted?
#26
Re: What was the cause of the redirects?
Posted 01 August 2012 - 06:24 PM
Quote
I am certain there is someone who knows..
#27
Re: What was the cause of the redirects?
Posted 01 August 2012 - 06:32 PM

POPULAR
#28
Re: What was the cause of the redirects?
Posted 01 August 2012 - 09:10 PM
#29
Re: What was the cause of the redirects?
Posted 01 August 2012 - 09:44 PM
Wow and also 20 posts!
This post has been edited by strawhat89: 01 August 2012 - 09:47 PM
#30
Re: What was the cause of the redirects?
Posted 01 August 2012 - 10:10 PM
|
|

New Topic/Question
This topic is locked



MultiQuote














|