SQL injections top plenty of lists as the most prevalent means of attacking front-end Web applications and back-end databases to compromise data. According to recent published reports, analysis of the Web Hacking Incidents Database (WHID) shows SQL injections as the top attack vector, making up 19 percent of all security breaches examined by WHID. . Similarly, in the "Breach Report for 2010" (PDF) released by 7Safe earlier this month, a whopping 60 percent of all breach incidents examined involved SQL injections. "One of the reasons we're seeing such an increase in SQL injections is actually sort of what we've dubbed the 'industrialization' of hacking," says Brian Contos, chief security strategist for Imperva. "It's this notion of smart SQL injections leveraging things like Google searches, automation through bots, and various other technologies to carry out sophisticated, automated attacks." SQL injection attacks are generally carried out by typing malformed SQL commands into front-end Web application input boxes that are tied to database accounts in order to trick the database into offering more access to information than the developer intended. Part of the reason for such a huge rise in SQL injection during the past year to 18 months is the fact that criminals are increasingly using automated SQL injection attacks powered by botnets to hit vulnerable systems, Contos says. They use the attacks to both steal information from databases and to inject malicious code into these databases as a means to perpetrate further attacks. The link for this article located at Dark Reading is no longer available. . Similarly, in the 'Breach Report for 2010' (PDF) released by 7Safe earlier this month, a whopping 60. injections, plenty, lists, prevalent, means, attacking, front-end, applicatio. . LinuxSecurity.com Team
In a recent study spanning from February 2005 to March 2006, SecureWorks saw 67% more Internet attacks attempted against its credit union clients than its banking clients. SecureWorks' credit union clients range from large ($500 million to billions in assets) to smaller organizations (under $500 million in assets). On average, SecureWorks blocks 767 attacks per day per credit union client. SecureWorks CTO Jon Ramsey theorizes that their credit union clients are experiencing more Internet attacks than their banking clients because hackers assume that credit unions' networks are less protected than banks. . The link for this article located at https://ebcvg.com/ is no longer available. . The link for this article located at https://ebcvg.com/ is no longer available.. recent, study, spanning, february, march, secureworks, internet, attac. . LinuxSecurity.com Team
Linux developers said they had few problems with attacks and viruses overall, with 92 percent saying their Linux systems have never been infected with a virus, and 78 percent saying their systems have never been hacked. Less than seven percent claimed to have been hacked three or more times. . . .. Linux developers said they had few problems with attacks and viruses overall, with 92 percent saying their Linux systems have never been infected with a virus, and 78 percent saying their systems have never been hacked. Less than seven percent claimed to have been hacked three or more times. Two years ago, 94 percent were virus-free, while the attack figures were about the same. Despite the slight fall, however, the figures remain far below the average. In a survey of all types of North American developers this spring, Evans found that 60 percent of developers said they had been breached and 32 percent had been hit at least three times. The link for this article located at InfoWorld is no longer available. . Programmers working with Linux observe rare occurrences of malware and invasions, highlighting a strong defense against compromises.. Linux Developers, Attack Statistics, Virus Protection, System Security. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.