All the latest UK technology news, reviews and analysis

US security blunder exposes residents' data

by Clement James

22 Apr 2008

Be the first to comment

  • Tweet this
Data security
The latest data scandal involved sensitive details on residents in Oklahoma

The names, addresses and social security numbers of tens of thousands of Oklahoma residents were exposed to the general public for a period of at least three years.

The information was made available via a badly coded page linked to Oklahoma's Department of Corrections Sexual and Violent Offender Registry.

Anyone with a basic knowledge of SQL could view the list of sexual offenders, and query the database to bring up a host of other information on the residents.

Fredrick Lee, a software security researcher at Fortify Software, said that the problem was down to poor coding.

"This is a classic SQL injection vulnerability," he said, adding that the security lapse could easily have been caught with a simple code review.

The incident could have been avoided, according to Lee, by using some form of automated analysis during the release procedure for the website.

"The sad thing is that vulnerabilities like these indicate to attackers that other related applications and organisations are probably vulnerable as well," he said.

In this case, anyone with a basic knowledge of SQL programming could interpret the URL and other data returned by the Oklahoma site.

By the simple process of amending the long URLs returned by the site, they could retrieve tens of thousands of social security numbers and allied data.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

30%

1%

12%

57%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Symanteccloud

Social networking: a guide for IT managers

Social networking is almost ubiquitous. This white paper examines the benefits and risks and it looks at the different ways companies can reconcile them

Riverbed

Mitigating the risks of IT change

The importance of understanding your infrastructure

Project Manager - Credit Risk - Finance IT - Investment Bank

Project Manager - Credit Risk - Finance IT - Investment...

Infrastructure Configuration Manager/Analyst/Data Modeler/IB

Infrastructure Configuration Manager/Analyst/Data Modeler...

Lead Perl Developer, Apache, SQL, Unix/Linux, INVESMENT BANK

Lead Perl Developer, Apache, SQL, Unix/Linux, Shell Scripting...

Perl Developer, Web and JEE App Servers, INVESTMENT BANK

**Perl /Java Developer, Web/ JEE application servers...

To send to more than one email address, simply separate each address with a comma.