Buy the Whitehouse, get an SQL injection attack

| 1 Comment
The Internet casino and poker house GoldenPalace.com bought up the only known deed for The White House as reported by The Inquirer.

Except that the link that the inq uses to get to the page telling the story at casinocitytimes.com revealed a little more information than they should have.   Because the URL on the inq was mistyped - they tried to make two links but only made one broken one.

When I clicked on the link: http://www.casinocitytimes.com/news/article.cfm?contentID=153470%5D %20and%20here%20[http://realtytimes.com/rtcpages/20050831_titleinsurance.htm I received an error page that was obviously the result of an unchecked contentID being passed right from the url into the SQL.



This is a classic case of unchecked user supplied data being trusted which leads to a compromise in security and some very red faces when some naughty people get hold of it.

I hope they fix it soon.
Bookmark and Share

1 Comment

Even worse, they have ColdFusion configured to show anyone tracebacks by the looks of it.

Leave a comment

About this Entry

This page contains a single entry by Paul Gregg published on September 18, 2005 9:13 PM.

PHP: HTTP Authentication via PHP was the previous entry in this blog.

Compiling PHP, OCI8 on Sparc64 Solaris 10 with Oracle10g is the next entry in this blog.

Find recent content on the main index or look in the archives to find all content.