On MovieTome: Patrick Dempsey is a MADE OF HONOR

Search:
Go!


Security Bites podcast: SQL-injections hit the Web

By CNET News.com Staff
Published: May 2, 2008 4:11 PM PDT

Listen Now

Robert Vamosi talks with Jeremiah Grossman, CTO of WhiteHat Security.

Download mp3

Listen to more episodes of this podcast at the Security Bites podcast archive.

Subscribe to this podcast

Subscribe to the podcast rss feed, or subscribe with iTunes.

The last few weeks have seen a surge in SQL attacks. Some, most likely using an automated tool, has involved adding malicious code to legitimate Web sites. For the end user, there's no way to tell that you are visiting a comprised site. Silently, your browser downloads the malicious content onto your PC.

This week Robert talked with Jeremiah Grossman, CTO for WhiteHat Security. Grossman said that what's different about these latest attacks is that someone has found a generic way to compromise Microsoft-SQL sites, which number in the thousands. Before, SQL-injection attacks were niche, targeting travel sites or sports sites, but these recent attacks have affected commercial, educational and even government sites.

advertisement
advertisement

Top picks from News.com readers

Readers who read Security Bites podcast: SQL-injections hit the Web also read...

More Info



Copyright ©2008 CNET Networks, Inc. All rights reserved. Privacy policy|Terms of use