Are manuul SQL injections still a big concern?
Yes. Manual, one-off SQL injection hackers are still out there making a living. Not only can these intruders clean out a customer database, they can get a foothold inside of the corporate network serving up the company’s website. “We’ve seen numerous instances in which attacks leveraged SQL vulnerabilities in order to get inside of corporate networks and gtet access to internal systems and information that was not supposed to be exposed to the Internet,” says Tom Cross, Manager, X-Force Advanced Research, at IBM ISS. “When we first started seeing this kind of attack occurring, it was pretty amazing how simple and straightforward it was, yet how deep the intruder could infiltrate the infrastructure and be relatively unseen. “The bad guys are getting in and are not being detected,” Cross continued. “They’re finding and taking what they want and leaving, not bothering to clean up.