• Data Management
  • Social Networking
  • Broadband
  • Digital Economy Bill
  • Copyright
  • UK / United Kingdom
  • File Sharers
  • Microsoft
  • Cybercrime
  • P2P
  • Oklahoma State leaks tens of thousands of social security numbers


    18 April, 2008, by Desire Athow
    Residents of Oklahoma State have reportedly been hit this week with the bad news that tens of thousands of their names, social security numbers and allied data were effectively available on the Web for around three years.

    The source of the problem, says Fredrick Lee, a software security researcher with Fortify Software, the application vulnerability specialists is poor coding on the state's Department of Corrections Web site.

    "This is a classic SQL injection vulnerability," he said, adding that, in this case, the security lapse could easily have been caught with a simple code review.

    According to Lee, had some form of automated analysis been part of the release procedure for this Web site, the incident could have been avoided.

    "The sad thing is that vulnerabilities like these indicate to attackers that other related applications and organizations are probably vulnerable as well," he said.

    According to newswire reports, anyone with a basic knowledge of SQL programming could interpret the URL and other data returned by the Oklahoma DoC Web site.

    Article continues after advert
    Then, by the simple process of amending the long URLs returned by the site, they could retrieve tens of thousands of social security numbers and their allied data from the site. Tags: Government, ID Management, ID cards, ID theft, Legal rights/wrongs
    Desire Athow
    Posted by
    Desire Athow
    on 18 April, 2008

    Désiré Athow is the Content Editor of ITProPortal.com and has been reporting on technology and telecommunication since 1999. You can follow him on Twitter.
    ITProPortal.com - Sponsored Section

    Featured Content

    1. The New Voice of the CIO. 158 CIOs in midsized businesses across 31 countries reveal their insights and vision for enhancing competitiveness over the next five years.

      Download Document

    Customer Case Studies

    1. How a wine wholesaler improved the flow of information
      Download full case study
    2. The server that made an entire university smarter
      Download full case study

    Videos

    Connecting in a smarter planet:

    Latest Tweets





     





    News Now Logo




    Forgot your password?