David Litchfield Asked Me

(Posted by adam)
At Blue Hat, David Litchfield of NGS asked me 'how many of the issues we see are related to SQL injection?' I did a review of the breach archive here, and found less than half a dozen that seemed decent candidates: Its not clear if all of these are SQL injection. Some I'm interpreting the lack of understanding or words like "sophisticated hacker." That's poor analysis technique, but the best I can do right now. We need to do better to help answer questions of where security resources are best allocated.

Posted by adam on March 15, 2006 at 9:24 AM in breach analysis . You can: comment, view comments (3), see trackbacks (0) or search Technorati.

Bookmark this post:

Comments

In a few weeks, there will be a fairly comprehensive list available of breaches of commercial entities. Stay tuned...

Posted by: Allan Friedman | March 15, 2006 5:34 PM


Is the conclusion here to be drawn that there are far fewer SQL injection attacks than we thought, and therefore the threat is overplayed?

Posted by: Iang | March 19, 2006 2:47 PM


I'd bet on observational bias before I'd bet that there are that few SQL injection attacks going on.

Posted by: Adam | March 19, 2006 2:59 PM