The Core

Why We Are Here => Water Cooler => Topic started by: Adam C on January 06, 2017, 10:17:15 AM

Title: An SQL injection attack is a legal company name in the UK
Post by: Adam C on January 06, 2017, 10:17:15 AM
https://www.schneier.com/blog/archives/2017/01/an_sql_injectio.html

QuoteSomeone just registered their company name as ; DROP TABLE "COMPANIES";-- LTD.
Title: Re: An SQL injection attack is a legal company name in the UK
Post by: Rooftop on January 06, 2017, 02:12:00 PM
That is just beautiful.  Badly written sites using companies house data will start crashing all over the place
Title: Re: An SQL injection attack is a legal company name in the UK
Post by: ergophobe on January 06, 2017, 04:16:19 PM
I am guessing this is inspired by the XKCD cartoon

https://xkcd.com/327/

Title: Re: An SQL injection attack is a legal company name in the UK
Post by: ukgimp on January 06, 2017, 04:25:39 PM
https://i.kinja-img.com/gawker-media/image/upload/s--vekHtjBE--/c_scale,fl_progressive,q_80,w_800/18mpenleoksq8jpg.jpg
Title: Re: An SQL injection attack is a legal company name in the UK
Post by: rcjordan on January 06, 2017, 04:32:40 PM
BWAAAAaaahhhaa!

Both images just sent to a high-end math class smartboard. We'll see if that second one works.