Select Website 

Article Search Engine

Key Word(s): Search By:  


Articles tagged with SQL INJECTION

OWASP Top 10 and your Recruitment Website - Part 1
8:30am Monday 09 August 2010
Tags: dmitry kulshitsky security recruitment website job board owasp sql injection xss cross-site scripting broken authentication session management login form design hacking website security user authentication

OWASP has recently updated their list of the top 10 most prevalent security vulnerabilities. Since this list covers all major aspects of computer security it is interesting to check what are the issues that are relevant to a typical recruitment website or job board and (exercising the 80/20 rule) what are the key questions we should ask ourselves (or our IT/security staff) to be sure that we don't miss anything critical. read more...


Is your Job Site redirecting Candidates to insecure websites?
5:30pm Wednesday 07 October 2009
Tags: api hacking google safe browsing api job board recruitment website safety security php script md5 hash malware blacklist phishing database email encryption exploit mysql privacy sql injection vulnerability identity theft

Have you ever clicked on what you thought was a safe website URL and then all of a sudden your browser/antivirus software blocks the webpage? Every day, I am alerted to yet another recruitment website falling victim to some sort of security incident. If you own or manage a website, YOU are responsible for your website’s security and have an implied "duty of care" to provide safe 3rd party links. read more...


How secure is your Recruitment website? Part 4 - SQL Injection
11:17am Wednesday 19 August 2009
Tags: hacking security job board recruitment websites malicious code sql injection insecure job search form testing apostrophe hack database security identity theft

Database security is a huge issue at the moment - imaging having your whole database stolen and distributed to your competitors or being used for identity theft? SQL Injection attacks present a serious threat to the security of a recruitment website and it is essential that adequate countermeasures are taken to prevent such an attack from being successful. read more...