All the latest UK technology news, reviews and analysis

Yahoo site flaw uncovered

by Phil Muncaster

16 Nov 2009

Be the first to comment

  • Tweet this
hacker
SQL injection attacks are a common way for hackers to compromise web sites

Data security firm Imperva today disclosed a new vulnerability in a Yahoo site that could lead to a large-scale data breach.

The SQL injection flaw - known as a Blind SQLi problem – was found on the Yahoo jobs site by researchers after they listened in on conversations between hackers on an illegal forum site, according to Imperva CTO Amichai Shulman.

Although it doesn't appear that the hackers got past the planning stage, the incident is a timely reminder of the need for web companies to vet code thoroughly, and to be alert and ready to respond quickly when vulnerabilities are disclosed, as Yahoo appears to have done.

"I think all the large web companies are quite experienced now in protecting their sites and Yahoo were very quick to respond in this case," said Shulman.

"I reported the incident, caught a flight to the US and by the time I landed I had a reply from them saying they had identified and fixed it."

The particular SQL injection flaw found here allows hackers to export data at a slower rate than regular SQL attacks, but it could still have lead to the personal information of large numbers of people being compromised, he added.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

36%

0%

10%

54%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Symanteccloud

Social networking: a guide for IT managers

Social networking is almost ubiquitous. This white paper examines the benefits and risks and it looks at the different ways companies can reconcile them

Riverbed

Mitigating the risks of IT change

The importance of understanding your infrastructure

C# Developer - Leamington Spa

C# Developer - .Net Developer ( C#/ASP.Net ) - Warwick...

ITIL Service Desk Manager / Incident Manager. Lancashire

ITIL Service Desk Manager / Incident Manager required...

Project Manager IP, MPLS Networks, London EC1

Client Facing Project Manager, Project Management, Managed...

Project Manager, IPT, VoIP - North West or Midlands

Client Facing Project Manager, Project Management, IPT...

To send to more than one email address, simply separate each address with a comma.