16
submitted 2 months ago by radix@lemmy.world to c/nottheonion@lemmy.world

"One coder added at least two database entries that are visible on the live site and say “this is a joke of a .gov site” and “THESE ‘EXPERTS’ LEFT THEIR DATABASE OPEN -roro.” "

you are viewing a single comment's thread
view the rest of the comments

Here's an archived version of the article to get past the paywall. The hackers went to the network tab of their browser's developer console and noticed that the API calls to write to the database weren't password protected.

[-] driving_crooner@lemmy.eco.br 0 points 2 months ago

Compared with an SQL injection, how sophisticated is this method?

[-] Yoddel_Hickory@lemmy.ca 3 points 2 months ago

If SQL injection is picking a lock, this is entering through an unlocked door.

Not sophisticated at all, authentication on API routes is way earlier on the security checklist than SQL query sanitisation. This site is amateur work.

[-] fiestorra@discuss.tchncs.de 2 points 2 months ago

Much much simpler, with a SQL injection at least you have to bypass the filters set, this is just submitting the changes through an API and the DB just eats it up.

[-] kautau@lemmy.world 2 points 2 months ago

Not to worry, they don’t use SQL

this post was submitted on 14 Feb 2025
16 points (100.0% liked)

Not The Onion

16048 readers
1034 users here now

Welcome

We're not The Onion! Not affiliated with them in any way! Not operated by them in any way! All the news here is real!

The Rules

Posts must be:

  1. Links to news stories from...
  2. ...credible sources, with...
  3. ...their original headlines, that...
  4. ...would make people who see the headline think, “That has got to be a story from The Onion, America’s Finest News Source.”

Please also avoid duplicates.

Comments and post content must abide by the server rules for Lemmy.world and generally abstain from trollish, bigoted, or otherwise disruptive behavior that makes this community less fun for everyone.

And that’s basically it!

founded 2 years ago
MODERATORS