the idea that NASDAQ might've been hacked using an SQL injection is pretty scary, as it's a pretty trivial attack to protect against in most cases (mysql_real_escape_string?) - is security in stock exchanges really so lax?
“NASDAQ is owned.” Five men charged in largest financial hack ever
91–100 of 143 posts
Re: “NASDAQ is owned.” Five men charged in largest financial hack ever
#92How would one even go about doing this? Do you just keep trying difference ssh key values? I never understood how people can just magically "gain access" to servers.
Re: “NASDAQ is owned.” Five men charged in largest financial hack ever
#93You would think that a way to stop these kinds of attacks for pennies on the dollar would be to have the security companies, banks, retail stores and others involved on the receiving side of these attacks fund hackathons or startup accelerators in every country, like a startup weekend, to give these "kids" a chance at legal startups and to get paid for finding bugs.
We spend how many hundreds of billions on the NSA so they can slurp all the worlds data? Why not force them to secure all networks?
Re: “NASDAQ is owned.” Five men charged in largest financial hack ever
#94Earlier quoted context omitted.
HA the jokes on you! We already HAVE the result of that. In all serious though, just be thankful you're still alive you unappreciative uppity citizen; at least you haven't been killed by a terrorist yet .
People don't often die from terrorism. He is much more likley to die from diabities, heart disease, cars or a gun shot. More toddlers with guns have killed Americans this year than terrorist have. If we are trying to save lives, worrying about terrorism is a waste of money.
That's a ridiculous argument. The Beltway sniper killed 10 people in 2002, a fraction of the number who died in car accidents that year. But tens of thousands of people had their lives disrupted as they ducked down while filling up at gas stations.
Re: “NASDAQ is owned.” Five men charged in largest financial hack ever
#95Earlier quoted context omitted.
That's exactly what defines SQLi. Incorrect filtering of user data is precisely the reason why SQLi is a vulnerability.
The better way to defend against SQLi would be to use proper quoting/prepared statements, instead of trying to play whack-a-mole by filtering and limiting the content of the input strings.
Re: “NASDAQ is owned.” Five men charged in largest financial hack ever
#96/facepalm
Re: “NASDAQ is owned.” Five men charged in largest financial hack ever
#97Earlier quoted context omitted.
We spend how many hundreds of billions on the NSA so they can slurp all the worlds data? Why not force them to secure all networks?
Our whole DOD budget is only 600-700 billion, so its unlikely we spend "hundreds of billions" on the NSA. Estimates are 8-10 billion: http://money.cnn.com/2013/06/07/news/economy/nsa-surveillanc... .
Re: “NASDAQ is owned.” Five men charged in largest financial hack ever
#98I honestly believe eastern Europe and possibly Israel are years ahead of the United States when it comes to the Internet - not with regard to adaptivity, but with regard to raw hacking ability. I have yet to understand why and I only have anecdotal evidence (including living in Ukraine), but there's something to those places that make them breed hackers.
They can't easily get jobs that pay them well, the way most programmers in the West can. People really good at security in the US just get a job making a great salary.
Re: “NASDAQ is owned.” Five men charged in largest financial hack ever
#99> According to one indictment, European credit card numbers sold for as much as $50, while US ones fetched about $10. This is truly dumbfounding to me. They had normalized, searchable access to millions of credit cards. They presumably had systematic ways of siphoning off money on high balance cards in a way that no one would've ever noticed. And yet, their grand scheme was to hock the numbers piecemeal for 50 a pop?…
Re: “NASDAQ is owned.” Five men charged in largest financial hack ever
#100I honestly believe eastern Europe and possibly Israel are years ahead of the United States when it comes to the Internet - not with regard to adaptivity, but with regard to raw hacking ability. I have yet to understand why and I only have anecdotal evidence (including living in Ukraine), but there's something to those places that make them breed hackers.
It feels like it's been that way for at least a couple of decades. In the early years of PC viruses it seemed like all the innovation was coming out of eastern Europe.