Jump to content
florin_darck

How Was SQL Injection Discovered?

Recommended Posts

Posted

The researcher once known as Rain Forrest Puppy explains how he discovered the first SQL injection more than 15 years ago.

SQL injection has become the scourge of the Internet era. Year after year, it is cited as one of the top security vulnerabilities on the Internet, responsible for countless data breaches.

Jeff Forristal, also known by the alias Rain Forrest Puppy, was one of the first people to ever document SQL injection. Forristal, now the CTO of mobile security vendor Bluebox Security, wrote the first public discussion about it, back in 1998.

In a video interview with eSecurity Planet, Forristal discusses how he chose his alias and how he first came across SQL injection.

Back in December of 1998, Forristal was writing about how to hack a Windows NT server and found something out of the ordinary. At that time in the late 1990s, few websites were using full Microsoft SQL server databases, he said. Instead many used simple Microsoft Access-based databases.

"I can completely change the way SQL works," Forristal said. "At that point, there were no real security properties fronting a database."

Even after all these years, Forristal is not surprised that SQL injection remains a large security concern.

"Certainly [sql injection] is still there," Forristal said. "From the perspective that it's still prolific, yeah it's an interesting problem, but core vulnerability classes are prolific in many places anyway."

Watch the full video interview with Jeff Forristal below:

http://c.brightcove.com/services/viewer/federated_f9?width=425&height=344&flashID=myExperience2866308721001&bgcolor=#FFFFFF&playerID=2387428403001&playerKey=AQ~~,AAAAE9-JbIE~,kp-fJ_AakbJwhLDQD27rR7clAKeyf6c-&isVid=true&dynamicStreaming=true&@videoPlayer=2866308721001&autoStart=&debuggerID=&startTime=1385482527330

Source : http://esecurityplanet.com

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.



×
×
  • Create New...