Think Information. Think Security.
According to secure cloud hosting company FireHost, its users were protected from a total of 17 million cyber attacks during the period of April to June 2012. It also claimed that there was a 69% increase in SQL Injection attacks between Q1 and Q2, rising from 277,770 blocked attacks to 469,983.

SQL Injection attacks are often automated, many website owners may be blissfully unaware that their data could actively be at risk, said Chris Hinkley ,  senior security engineer  at FireHost and Todd Gleason, director of technology at FireHost, said: “Some of the data theft incidents that are reported in the media are precisely targeted, but a more substantial risk to most comes from an abundance of automated, malicious bots that attack websites in a more random fashion.”

Recent research by White Hat Security found that while SQL injection is a prevalent website vulnerability, it only affects 11% of websites and flaws are fixed in an average of 53 days. It claimed that 5% of all websites it evaluated had at least one SQL injection vulnerability that was exploitable without first needing to login to the website.

The April 2012 'State of Software Security Report' from Veracode, said that SQL injection remains one of the two most frequently exploited vulnerability types (along with cross-site scripting), with a statistically flat incidence rate from the first quarter of 2010 to the fourth quarter of 2011.

Cross-posted from: SC Magazine

Leave a Reply.