16 Nov 2009
Data security firm Imperva today disclosed a new vulnerability in a Yahoo site that could lead to a large-scale data breach.
The SQL injection flaw - known as a Blind SQLi problem – was found on the Yahoo jobs site by researchers after they listened in on conversations between hackers on an illegal forum site, according to Imperva CTO Amichai Shulman.
Although it doesn't appear that the hackers got past the planning stage, the incident is a timely reminder of the need for web companies to vet code thoroughly, and to be alert and ready to respond quickly when vulnerabilities are disclosed, as Yahoo appears to have done.
"I think all the large web companies are quite experienced now in protecting their sites and Yahoo were very quick to respond in this case," said Shulman.
"I reported the incident, caught a flight to the US and by the time I landed I had a reply from them saying they had identified and fixed it."
The particular SQL injection flaw found here allows hackers to export data at a slower rate than regular SQL attacks, but it could still have lead to the personal information of large numbers of people being compromised, he added.
Latest stories from Security
Related articles
Related jobs
Poll
What is the most important IT priority for your company this year?
Connect with V3.co.uk
This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes
Why good data management at all levels is essential in the modern business (video, 6mins)
VB.Net Developer - Winforms / ASP.Net / VB6 - Wolverhampton...
Java Developer, Online betting/Gaming, e-commerce, London...
C# Developer - Winforms / SQL - Cannock - My client is...
Middleware Consultant - Java / J2EE/ JBoss / Weblogic...
Keep up to date with the latest products, services and technologies from the world's leading IT companies. IThound.com brings you over 2,000 white papers, case studies and analyst reports.
Do you agree?