> SQL-injection > NASDAQ
Sigh.
21–30 of 143 posts
> SQL-injection > NASDAQ
Sigh.
I honestly believe eastern Europe and possibly Israel are years ahead of the United States when it comes to the Internet - not with regard to adaptivity, but with regard to raw hacking ability. I have yet to understand why and I only have anecdotal evidence (including living in Ukraine), but there's something to those places that make them breed hackers.
I honestly believe eastern Europe and possibly Israel are years ahead of the United States when it comes to the Internet - not with regard to adaptivity, but with regard to raw hacking ability. I have yet to understand why and I only have anecdotal evidence (including living in Ukraine), but there's something to those places that make them breed hackers.
They can't easily get jobs that pay them well, the way most programmers in the West can. People really good at security in the US just get a job making a great salary.
I honestly believe eastern Europe and possibly Israel are years ahead of the United States when it comes to the Internet - not with regard to adaptivity, but with regard to raw hacking ability. I have yet to understand why and I only have anecdotal evidence (including living in Ukraine), but there's something to those places that make them breed hackers.
I've always figured (at least for former soviet states) that it's a combination of: + a rigorous STEM curriculum + limited conventional job prospects + a social/business environment in which exploit-selling is a respectable profession
Sites are susceptible when user input is ... incorrectly filtered for characters used in database commands ...
If you're trying to protect yourself from SQLi by filtering & then running user input, you're doing it wrong. If a supposedly tech-literate site like Ars can't get that right, what hope do we have? (Let alone the banks themselves...)This is truly dumbfounding to me. They had normalized, searchable access to millions of credit cards. They presumably had systematic ways of siphoning off money on high balance cards in a way that no one would've ever noticed. And yet, their grand scheme was to hock the numbers piecemeal for 50 a pop?
How are such smart people so bad at business.
> According to one indictment, European credit card numbers sold for as much as $50, while US ones fetched about $10. This is truly dumbfounding to me. They had normalized, searchable access to millions of credit cards. They presumably had systematic ways of siphoning off money on high balance cards in a way that no one would've ever noticed. And yet, their grand scheme was to hock the numbers piecemeal for 50 a pop?…
That's like saying anyone who runs a SaaS that helps other businesses make money for $50/m is bad at business.
> According to one indictment, European credit card numbers sold for as much as $50, while US ones fetched about $10. This is truly dumbfounding to me. They had normalized, searchable access to millions of credit cards. They presumably had systematic ways of siphoning off money on high balance cards in a way that no one would've ever noticed. And yet, their grand scheme was to hock the numbers piecemeal for 50 a pop?…
Where are they getting their numbers from? Last I heard (a year or two ago), carders charged about 10 cent for foreign cards and a dollar per US card. Any actual carding researchers care to weigh in?