Advertisement
Promo

Become a member of the ZDNet UK community

(ISC)2

View blog's RSS Feed

Security Profession blog

Comment and discussion about the security industry of interest to the security professional. Blogs will be submitted by (ISC)2's management team and Advisory Board members.

Wednesday 26 August 2009, 6:39 PM

SQL injection attacks point to need for more secure software

Posted by (ISC)2

The most recent identity theft attack to hit the headlines (http://news.bbc.co.uk/1/hi/business/8206305.stm) was apparently the biggest case of identity theft in the USA. Like an increasing number of such attacks, it exploited weaknesses in web based applications by using the well known technique of ‘SQL injection’ to access and steal 130 million credit card numbers. Hackers understand that there have been significant investments made to protect network, database and server assets and have moved on to attack the application layer. Today they are less interested in causing corporate havoc, and more interested in stealing data. Their attacks therefore are designed to evade detection and move through the easiest door to get to the prize.

At a recent (ISC)2 Secure London seminar the keynote speaker from IBM Internet Security, James Rendell, said that IBM’s X-Force security labs had tracked a 30 x increase in ‘SQL injection’ attacks in the last six months. He suggested that cyber criminals liked them because it is easy to identify the targets, they are easy to implement and they deliver a high payoff—i.e. they don’t have to recognise the underlying operating system or even the database because they take advantage of the Web front ends that companies are applying to all of their applications.

Rendell also pointed out that more than half of all software vulnerabilities are web application based, however the issue here isn’t just about web application software, it’s a matter of the bad software architecture and design that is endemic in much software. Too often security holes are known vulnerabilities that just weren’t tracked properly in the development process. With patching becoming an increasing burden, wouldn’t the economics now warrant pushing the issues and costs back to the software vendors?
We know that software developers have yet to progress their profession with security in mind. They are driven by tight timescales, flexible and cost-effective development methodologies and an obsessive focus on usability. Security has been an afterthought, all too often introduced at the testing stage. But the time to change is now. Software teams need to establish more sound security standards and raise awareness among stakeholders across the software development lifecycle of the importance of addressing security concerns. While many argue that secure coding techniques have been developed, the approach is too limited. This is not an issue for software coding alone.

John Colley, managing director for EMEA of (ISC)2

Comments on this post

CA

This underlines the sheer stupidity in keeping copy's of customers details for any retailers, I mean the only organizations who should have these details should be the relevant banks to which your cards belong to and thats it.

The only thing the retailers need is a link back to the banking system to authenticate the card purchase, why the retailer's have being collating customer's details after transactions is beyond me.

Posted by CA on Aug 27, 2009 1:52 AM

(ISC)2
  • (ISC)2
  • n/a
  • Member since: February 2008

Site Activity Rating 3

Contacts

Number of Contacts: 1

Contacts' Latest Discussions

Number of Tracked Discussions: 123

Karen Friar Karen Friar

Comment quarantined

Tuesday 24 November 2009, 3:50 PM

8 comments
Karen Friar Karen Friar

Thanks for the catch

Monday 2 November 2009, 6:00 PM

2 comments
Karen Friar Karen Friar

Disappearing comments and blog posts

Tuesday 29 September 2009, 9:36 AM

5 comments
Karen Friar Karen Friar

Windows 7 versus Vista, XP

Thursday 6 August 2009, 11:40 AM

1 comment

Contacts' Latest Blogs

Number of Contacts Blogs: 1

Avatar Karen Friar

HP workers set dates for strikes

Thursday 3 December 2009, 7:57 PM

1 comment

Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters