A SQL faux pas for the state.
Oklahoma Leaks Tens of Thousands of Social Security Numbers, Other Sensitive Data - The Daily WTF
A SQL faux pas for the state.
Oklahoma Leaks Tens of Thousands of Social Security Numbers, Other Sensitive Data - The Daily WTF
after reading the article, let me just say that the method of coding the searches was way past 'faux pas' territory and was downright stupid on the part of the 'programmer' involved. if this person is a state employee, i sincerely hope they are no longer gainfully employed.
Agreed. Apparently the work was contracted out a long time ago to a company that no longer exists.However, if you read the state review of the DOC IT department from some time ago that one of the article commenters points out, DOC knew about serious problems with the system and didn't do anything to correct it.
Well if there's anybody's identity that I'd want to be stealing....
the worst of it is that any person with a smidge of sql knowledge could add that co-worker he didn't like or delete himself.
Seems like anyone who was added to the list could make a pretty good case for public slander. That would be a very costly joke / revenge attack.
I noticed that this incident is already listed on wikipedia under SQL injection --- Oklahoma's little claim to infamy.
Looks like the DOC IT dept wants to clear the air...moderately interesting
WTF Comment 190574
There are currently 1 users browsing this thread. (0 members and 1 guests)