Welcome, Guest: Register On Nairaland / LOGIN! / Trending / Recent / New
Stats: 3,157,935 members, 7,835,117 topics. Date: Tuesday, 21 May 2024 at 04:57 AM

Pls: Security Is Very Important Just Like You Are Getting Paid - Webmasters - Nairaland

Nairaland Forum / Science/Technology / Webmasters / Pls: Security Is Very Important Just Like You Are Getting Paid (709 Views)

Join Our Team Of Freelance Webmasters And Start Getting Paid. / Need A Website Just Like 2go,eskimi / Advertising On Facebook And Other Social Networking Sites And Getting Paid (2) (3) (4)

(1) (Reply) (Go Down)

Pls: Security Is Very Important Just Like You Are Getting Paid by Cactus(m): 5:24pm On Feb 21, 2011
Have you ever seen websites that have pure sql statements in their url?
eg

http://www.samplesite.com/sql=Select+something+something+from+tablename+where+columnname=something

This I just saw on a major nigerian financial institution client login page. and basically if you change the statement to something like this


http://www.samplesite.com/sql=Select+something+something+from+tablename+where+columnname>1

You will get all the information of their customers.

I was wondering, a major financial institution is it that they are not aware of these simple details?   Someone please help me put my head around this.

I am not talking about a small financial organization o. I am talking major.

This is another one from my previous post. That has been fixed.
Re: Pls: Security Is Very Important Just Like You Are Getting Paid by proflynks1(m): 5:31pm On Feb 21, 2011
i think the question will be more appropriate to the database admin n not the coy,


@ur question: probably, it's not known
Re: Pls: Security Is Very Important Just Like You Are Getting Paid by Cactus(m): 3:47am On Feb 22, 2011
Well, this is a developer's issue that is if their dba and programmers are different. Architecture planning, all tlhese issues must have been addresses. The main pages are password protected, But pages loading via javascripts are not password protected. I dont knowif they were thinking that protecting the parent page will protect others and left the security for the children.

From what I have seen, do Nigerian companies go tru system reviews after initial deployment? The major companies I have seen so far, after the first deployment, no reviews are done just keep adding to it.
Re: Pls: Security Is Very Important Just Like You Are Getting Paid by Nobody: 9:39pm On Feb 24, 2011
dude, our banks are nothing to write about.
just email them, and do it wisely.

can i add u on FB @Cactus
Re: Pls: Security Is Very Important Just Like You Are Getting Paid by Slyr0x: 11:45pm On Feb 24, 2011
Cactus:

Have you ever seen websites that have pure sql statements in their url?
eg

http://www.samplesite.com/sql=Select+something+something+from+tablename+where+columnname=something

This I just saw on a major nigerian financial institution client login page. and basically if you change the statement to something like this


http://www.samplesite.com/sql=Select+something+something+from+tablename+where+columnname>1

You will get all the information of their customers.

I was wondering, a major financial institution is it that they are not aware of these simple details?   Someone please help me put my head around this.

I am not talking about a small financial organization o. I am talking major.

This is another one from my previous post. That has been fixed.

shocked shocked shocked shocked shocked shocked shocked

(1) (Reply)

Google+ Vs. Facebook: See How They Compare / Api Client V1.0 / Seun Treat This Bug

(Go Up)

Sections: politics (1) business autos (1) jobs (1) career education (1) romance computers phones travel sports fashion health
religion celebs tv-movies music-radio literature webmasters programming techmarket

Links: (1) (2) (3) (4) (5) (6) (7) (8) (9) (10)

Nairaland - Copyright © 2005 - 2024 Oluwaseun Osewa. All rights reserved. See How To Advertise. 10
Disclaimer: Every Nairaland member is solely responsible for anything that he/she posts or uploads on Nairaland.