Feed aggregator
Reporter Suggests Half-Life 3 Will Be a Steam Machine Launch Title
Read more of this story at Slashdot.
Volkswagen To End Production At German Plant, a First In Company History
Read more of this story at Slashdot.
Utah Leaders Hinder Efforts To Develop Solar Energy Supply
Read more of this story at Slashdot.
MI6 Chief: We'll Be as Fluent in Python As We Are in Russian
Read more of this story at Slashdot.
Racks of AI Chips Are Too Damn Heavy
Read more of this story at Slashdot.
US Threatens Penalties Against European Tech Firms Amid Regulatory Fight
Read more of this story at Slashdot.
Texas Sues TV Makers For Taking Screenshots of What People Watch
Read more of this story at Slashdot.
McKinsey Plots Thousands of Job Cuts in Slowdown for Consulting Industry
Read more of this story at Slashdot.
High-Speed Traders Are Feuding Over a Way To Save 3.2 Billionths of a Second
Read more of this story at Slashdot.
Tech Giants Can't Agree On What To Call Their AI-Powered Glasses
Read more of this story at Slashdot.
The Entry-Level Hiring Process Is Breaking Down
Read more of this story at Slashdot.
Mozilla's New CEO Bets Firefox's Future on AI
Read more of this story at Slashdot.
Google's Real Estate Listings 'Experiment' Sends Zillow Shares Down More Than 8%
Read more of this story at Slashdot.
SoundCloud Confirms Breach After Member Data Stolen, VPN Access Disrupted
Read more of this story at Slashdot.
PayPal Applies To Become a Bank As US Loosens Regulatory Reins
Read more of this story at Slashdot.
Glaciers To Reach Peak Rate of Extinction In the Alps In Eight Years
Read more of this story at Slashdot.
Underwhelmed
Our anonymous submitter was looking for a Microsoft partner to manage his firm's MSDN subscriptions; the pile of licenses and seats and allowed uses was complex enough to want specialists. In hopes of quickly zeroing in on a known and reputable firm, he tracked down the website of a tech consultancy that'd been used by one of his previous employers.
When he browsed to their Contact Us page, filled out the contact form, and clicked Submit, the webpage simply refreshed with no signs of actually doing anything. After staring at the screen for a moment, wondering what had gone wrong, Subby noticed the single quotes used within his message were now escaped. Clicking Submit a few more times kept adding escape characters, with no submission ever occurring. So he amended his message to remove every it's, we're, and other such contraction.
Without single quotes, the next submission was successful. It's impossible to say what was going on behind the scenes, but this seemed to suggest a SQL injection vulnerability in their form submission code. They were escaping "'" characters because they were building their query through string concatenation. But in addition to escaping the single quotes, it seemed to be rejecting any string which contained them.
A stellar first impression, to be sure. In fairness, this firm hadn't designed their own website. The name of the designer they'd contracted with, displayed in the webpage footer, looked more embarrassing than proud in light of his trouble.
An email address was listed beside the contact form. Subby sent a separate email alerting them of the bug he'd found. Hopefully, someone would acknowledge and channel it to the proper support contact.
A week passed. Subby never received a response or any confirmation that any of his messages had been received. Had that mailbox been abandoned after most, if not all, attempted contacts had mysteriously failed?
"I guess no SQL injection if it's never submitted!" Subby joked to himself.
He moved on to other prospects.
[Advertisement] Plan Your .NET 9 Migration with ConfidenceYour journey to .NET 9 is more than just one decision.Avoid migration migraines with the advice in this free guide. Download Free Guide Now!
Microsoft Will Finally Kill Obsolete Cipher That Has Wreaked Decades of Havoc
Read more of this story at Slashdot.
Microsoft Will Finally Kill Obsolete Cipher That Has Wrecked Decades of Havoc
Read more of this story at Slashdot.
Lidar-Maker Luminar Files For Bankruptcy
Read more of this story at Slashdot.
