Oklahoma Leaks 10,000 Social Security Numbers
DrJokepu writes "Apparently the folks at the Department of Corrections of Oklahoma just forgot to use common sense when they created the state's Sexual and Violent Offender Registry. By putting SQL queries in the URLs, they not only leaked the personal data of tens of thousands of people, but enabled literally anyone with basic SQL knowledge to put his neighbor/boss/enemies on the sexual offender list. Fortunately, after the author of the blog The Daily WTF notified the department about the issue, the site went down for 'routine maintenance' on April 13 2008."
(1)Hack the registry
(2)Put your own name in the registry
(3)Sue the state
(4)Profit!!!
(5) (remember to have your name removed from the registry!)
ObXKCDComic
It's scary how lazy some of the web developers are. For years Yahoo used a system where their login system had the URL to go to once login succeeded urlencoded in the URL. It would have been exceedingly easy to duplicate the login page with a "Username/Password was typed incorrectly. Please try again." Then send people to the authentication page with your page as the follow-on one.
URLs should only be able to contain sanitized field values to search on that the server composes into actual SQL, URLs, etc.
E pluribus unum
What someone needs to do is register a certain G. Oatse as a sex offender in Oklahoma.
Who would tag this "humor"? Given the deeply-ingrained social stigma attached to being put on one of these lists, I don't really see how it's funny that one was so horribly misimplemented. Even when something is _obviously_ wrong, as in this case, it can be hard to iron out the impression that actual people get from reading these lists. What if the problem weren't as obvious as this one supposedly is? Would it still be funny?
Generally, no retraction is ever as effective as the original statement. That's probably one of the reasons why libel is such a big deal for some people--just saying "sorry, we were wrong" may not be good enough.
In Oklahoma, the age of the earth is 6000 years. Nuff said.
So I said to my girlfriend, "I am not a pedophile! But that is a pretty big word for a 10 year old."
Did you by chance hear a WHOOSH before you posted?
>>--[joke]--->
__0__ <- your head
|
Kevin Smith on Prince
im in ur sex offender database,
injectin sql.
Wow, an on topic post for my all time favorite XKCD! :)
http://xkcd.com/327/
WWJD?
JWRTFM!
Actually, take a look at ok.state.gov/registry/access&sql=TABLE%20DROP%20ALL