Slashdot Log In
SQL Injection Turns BusinessWeek Into Viral Replicator
Posted by
CmdrTaco
on Monday September 15, @09:33AM
from the glad-it's-not-us dept.
from the glad-it's-not-us dept.
martins writes "The website of popular magazine BusinessWeek has been attacked via SQL injection in an attempt to infect its readership with malware. Hundreds of pages in a section of BusinessWeek's website which offers information about where MBA students might find future employers have been affected."
Related Stories
[+]
Adobe Flash Ads Launching Clipboard Hijack Attacks 353 comments
bullyBEEF writes "Malicious hackers are using booby-trapped Flash banner ads to hijack clipboards for use in rogue security software attacks. In the Web attacks, which affect Mac, Windows, and Linux users running Firefox, IE, and Safari, bad guys are seizing control of the machine's clipboard (probably using the Flash command setClipboard) and inserting a hard-to-delete URL that points to a fake anti-virus program. A number of legitimate sites have been seen to host ads carrying the attack — including Newsweek, Digg, and MSNBC.com. Researcher Aviv Raff offers a harmless demo of how it's done."
Firehose:BusinessWeek site hacked to host malware by Anonymous Coward
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
Full
Abbreviated
Hidden
Loading... please wait.

Malic or incompetence? (Score:5, Insightful)
Sophos informed BusinessWeek of the infection last week, although at the time of writing the hackers' scripts are still present and active on their site.
It's bad enough to have an insecure site, but to ignore the break-in for a week or more is just unconscionable.
Reply to This
Re: (Score:3, Interesting)
Re:Malic or incompetence? (Score:5, Interesting)
They just don't teach anything about security in schools. We interviewed an intern candidate this spring and asked her how one would avoid a SQL injection attack.
Her response: "Don't use Microsoft products."
Swing and a miss!
The candidate's sample code had a big 'ol SQL injection vulnerability. Yet the instructor raved over his project.
Reply to This
Parent
Hmm (Score:5, Funny)
Reply to This
Re:Hmm (Score:5, Funny)
So no great loss to society then.
Reply to This
Parent
Pity on the future MBAs (Score:4, Funny)
Ah-well, only kidding ;)
Reply to This
That's frightening (Score:4, Funny)
A replicant virus. Is it a virus or a replicant? Will it need retiring? If the website hosted a picture of a turtle on its back, will it rotate the picture 180 degrees? Will we know if it's a replicant virus or a real virus by the end of the article?
Reply to This
ATTENTION WEB DEVELOPERS (Score:5, Insightful)
HAI!
Just a friendly reminder - your Database Admin will be more than happy to set up multiple users for you with different permissions. For instance, a user with "write" privileges that can be used by the website backend page that the editors use, and a user with "read only" permissions that the public facing web server(s) will use when presenting the page to the public.
That is all.
Reply to This
Re:ATTENTION WEB DEVELOPERS (Score:5, Informative)
This is a very good point. Except that phpMyAdmin makes it really easy to set up a new database with a single user who has all rights, and the same name as the DB.
So what I tend to do (and I do admit that I am a lazy SOB), is just create a new DB and user for every app.
However, your idea is much better, and it would be nice if phpMyAdmin had such a feature... (Not that I'm about to code it in, on account of my being busy with other things, and never having even looked at the phpMyAdmin code beyond what is needed to install it.)
However, an even better thing to do (then just create a read-only user), is to escape shit before you query the DB... PHP and MySQL have this nifty function mysql_real_escape_string [php.net] which will do that for you. It is better then using the general escape functions in PHP, for reasons that I read just recently. Basically, it takes into account the character encoding for the DB... http://shiflett.org/blog/2006/jan/addslashes-versus-mysql-real-escape-string [shiflett.org]
Reply to This
Parent
Re: (Score:3, Insightful)
Multiple DB users, proper escaping, you know it's not actually an either-or situation. If the only way you know to set up a database is through phpMyAdmin, then you need help reading the manual.
Bobby Tables is at it again... (Score:5, Funny)
Bobby Tables is at it again...
Reply to This
Re:Bobby Tables is at it again (obligatory link) (Score:5, Informative)
http://xkcd.com/327/ [xkcd.com]
Reply to This
Parent
' UNION UPDATE `users` SET karma='godlike';-- (Score:4, Interesting)
Seriously? Why is it that these people always point to their site? wouldn't you figure that, with a bit of injection, they could put the damn thing in the database? It's never made any sense to me. Anyone have any insights?
Also, they always waste these opportunities to give replace real headlines with those from the Onion... if they're going to do something malicious, they should at least do it with style...
Reply to This
more economic woes (Score:5, Funny)
I suppose McDonald's is going to have to rely on employing just the liberal arts majors for now.
Reply to This
Re: (Score:3, Insightful)
Re:MBA students, appropriate. (Score:4, Interesting)
You haven't seen the modern MBA have you. Almost half of the MBA students have Computer Science Degrees and have been working professional for at least 5 years. Many of them while good at what they do, wants to further their career so go for an MBA so they be considered qualified for promotion. Not every one wants to be a basic programmer for the rest of their life, they much rather have influence in the process and the design and less time doing the drudge work.
Reply to This
Parent
Re:MBA students, appropriate. (Score:4, Interesting)
Many of them while good at what they do
Not every one wants to be a basic programmer for the rest of their life
Pretty much all of the *GOOD* programmers *DO* want to program for the rest of their lives (while I wouldn't say "basic programmer"....most want to be Dev Lead / Architect type of coders, but coders none the less). And being Dev Lead / Architect is not the type of position that goes to the MBA grads.....MBAs are for people who want to go into Management / Project Management.
I've been in the industry since 1994 and am one of the top database developers in my company. And I don't see myself as being a manager any time soon. I enjoy programming too much. [This is in a large corporation where a manager is not a technical manager; small companies where "Dev Lead" equates to manager might be a different situation.]
Layne
Reply to This
Parent
Re:MBA students, appropriate. (Score:5, Insightful)
To be a good Architect you often need a strong business knowledge. Yea Yea You know how to program you so smart (being that I learned to program at 6 years old) it doesn't take a genius to program. But in reality being able to be a good programmer doesn't mean you can design or create solutions that solve real business problems. I have been in the industry for a long time too. Working as a consulting I was actually the top database developer for multiple companies, including many fortune 500 companies. However I found that creating the code is a piece of cake, however the hard part is trying to understand the business process, then filtering out what is needed and not for the code to run successfully without having to run extra work, as well understand what is happening so in a case the software fails (or hardware) you can come up with a quick workaround solution for the employees until you can get a working version. Business knowledge is a key area. If you are working in a business environment getting Masters in computer science wouldn't be as useful as getting an MBA.
Reply to This
Parent
Re: (Score:3, Funny)
You sound like "The Most Interesting Man in the World": http://www.brentter.com/dos-equis-most-interesting-man/ [brentter.com]
Do you drink Dos Equis???
Layne
Re:MBA students, appropriate. (Score:5, Informative)
Depends. Alan Cox is a top-class programmer who got an MBA because there was this whole other world that intersected with what he did that he didn't understand.
Reply to This
Parent
Re:MBA students, appropriate. (Score:4, Interesting)
I'd be really curious to know what he thought of it afterwards, and whether having an MBA really helped him understand this other world. I get the distinct impression that an MBA is the business-world equivalent of an MSCE: it gives you some basic knowledge and impresses the clueless but isn't really very useful.
Reply to This
Parent
Nit pick time. (Score:5, Informative)
Many of them while good at what they do, wants to further their career so go for an MBA so they be considered qualified for promotion.
To nitpick:
That depends on your company and their policies. Therefore ask HR. I did once to see what they'd do for me. The answer was that I'd get a $3,000 raise for having a graduate degree. I asked for clarification regarding why she put that way; "You mean, I would get the raise regardless of what masters degree I received?"
"Yes. Of course your manager has to approve it."
Another thing to clarify, and I've found this out the hard expensive way: getting an MBA does NOT automatically give you a ticket into management. Here's what I was told by several folks: You need management experience for an MBA to mean something. Without the experience, the MBA is worthless. So now, I'm a coder with an MBA - it's not doing me any good. And like a stupid SOB, I paid for it with student loans. I did it when I was out of work thinking that it would get me a management job. Schools are so quick to tell you that their MBA will further your career. BS! Experience matters more than the degree - and networking (i.e. It's who you know.)
So here's what I would do differently, get into management, see if my company requires an MBA for my position, get them to pay for it, bust my ass in night school, some profit! But if they don't require it, I don't see the point in getting one.
And there's going to be a HUGE glut of MBAs. With this down economy, MBA enrollments have gone through the roof. Which means, in two years, the already huge glut of MBAs is going to get bigger.
Reply to This
Parent
AND I don't mean ... (Score:5, Insightful)
I'm just ... look at my user name...
Reply to This
Parent
Re:Nit pick time. (Score:4, Funny)
Look on the bright side; it was only 2 years of student loans, I had to do 3 years of law school to be in the same situation.
Reply to This
Parent
Re:MBA students, appropriate. (Score:4, Funny)
No, I just have to spend time around them occasionally since my field happens to be very useful in finance and business. You can tell, because when you enter the business-popular classes (time series; baby stochastic analysis; &c.) the first thing that hits you is a wave of cheap cologne covering the stench of desperation.
Reply to This
Parent