Send to a friend Print

Risk Management

Oklahoma Department of Corrections leaks personal data from website

Author:
Posted:
16:00 18 Apr 2008

Thousands of residents of Oklahoma state in the US have found their personal details have been freely available on the web for three years.

The data includes their names, social security numbers and other personal information.

The source of the leak is Oklahoma's Department of Corrections website.

Anyone with a basic knowledge of SQL programming could interpret the URL and other data returned by Oklahoma's Department of Corrections (DoC) website.

Amending the long URLs returned by the site, a hacker could retrieve tens of thousands of social security numbers and allied data from the site.

Fredrick Lee, a software security researcher at Fortify Software, said the origin of the problem was poor coding on the state's DoC website.

ADVERTISEMENT

"This is a classic SQL injection vulnerability," he said, adding that the security lapse could easily have been caught with a simple code review.

According to Lee, had some form of automated analysis been used on the site, the incident could have been avoided.

"The sad thing is that vulnerabilities like these indicate to attackers that other related applications and organisations are probably vulnerable as well," he said.

Essential guide to security policy>>





Send to a friend Print
ADVERTISEMENT

Featured Blog

Who's in your network? Having a good network is a key asset of a CIO. Not that network - I mean your personal contacts. I'm...More All blogs
ADVERTISEMENT
SPONSORED LINKS
Advertisements