Catch up on stories from the past week (and beyond) at the Slashdot story archive

 



Forgot your password?
typodupeerror
Security

Journal twitter's Journal: Direct Cash from SQL Injection. 3

"The Analyzer" has been arrested for $1.7 million of card fraud.

The alleged scheme involved the purchase of low-value cards, typically with balances of about $15. Tenenbaum would then exploit SQL injection vulnerabilities in Direct Cash's server to increase the value of the cards. The amount of a single card was inflated to more than $1m, Calgary officials told Wired.com.

What's that site running? IIS, of course. This is petty theft next to the current collapse but it's still no way to run a bank.

This discussion has been archived. No new comments can be posted.

Direct Cash from SQL Injection.

Comments Filter:

"If people are good only because they fear punishment, and hope for reward, then we are a sorry lot indeed." -- Albert Einstein

Working...