3 ms·
shall we all assume it was an sql injection? does anyone know what the actual vulnerability was?
by securitywiz 14y ago
shall we all assume it was an sql injection? does anyone know what the actual vulnerability was?
- tantalor 14y agoAlmost certainly a query parameter, since he was reverse engineering their API it would be obvious. For it to be a SQL injection, he'd have to have been looking for vulnerabilities.
- nwh 14y agoWhile it's probable he found some issue with permissions in the queries, stumbling on SQL injection is easier than you'd think. For a very short period I used a completely random (any ASCII character) password generator for websites, but I quickly realised that the ' and " characters were breaking the vast majority of sites I logged in to. Plaintext passwords in a database without escaping; about the worst password storage you can get.
- namank 14y agoWho knows but I'm bound to look the way of GET URLs given that they discovered it trying to make an app around an existing system. API not validating correctly. If this is true, it will take a long time to fix.
- hn-miw-i 14y agoIt's likely to be an application logic authorization bug; the application doesn't check the context to see if it should return that info. Being web it's something silly like the student-id stored in the user cookie is used to to build the (parameterized) SQL statement. It's not arbitrary injection per say.