‘Everyday hackers’ are on the rise

8 April 2013
By Edd Gent
Mobile version
Share |
Every day hackers seem to be on the rise after research found a Google search for “SQL injection hack” provided 1.74 million results

Every day hackers seem to be on the rise after research found a Google search for “SQL injection hack” provided 1.74 million results

“Everyday hackers” will become more common due to the increasing availability of hacking advice, according to new research.

According to cyber-security firm Veracode’s annual State of Software Security Report (SoSS), released today a simple Google search for “SQL injection hack” provides 1.74 million results, including videos with explicit instructions on how to exploit SQL injection vulnerabilities.

The ready availability of this information is making it possible for less technically skilled hackers to take advantage of this common flaw and although SQL injection flaws are easy to identify and fix, Veracode found that 32 per cent of web applications are still affected by SQL injection vulnerabilities.

“Despite significant improvements in awareness of the importance of securing software, we are not seeing the dramatic decreases in exploitable coding flaws that should be expected,” says Chris Eng, vice president of research, Veracode.

“For each customer, development team or application that has become more secure, there are an equal number that have not.”

The research concluded that the leading cause of security breaches and data loss for organizations is insecure software and Veracode believes as many as 30 per cent of breaches in 2013 will be from SQL injection attacks.

“Veracode’s 2013 SoSS provides organizations with ways to reduce the success of potential attacks on company infrastructure by understanding the threat to the application layer and outlines the implications of these trends if organizations continue on their current paths,” says Eng.

The report, which includes the latest research on software vulnerability, also found that 70 per cent of software failed to comply with enterprise security policies on their first submission for security testing, indicating that the demand for rapid development means new vulnerabilities are constantly being introduced into organisation’s software portfolio.

“The amount of risk an organization accepts should be a strategic business decision, not the aftermath of a particular development project,” says Chris Wysopal, co-founder and CTO of Veracode.

“The time for organizations to act is now. My hope is that readers will use this research to estimate their current application risk, and then consider how they can act to improve the security posture of their organization by addressing the applications that are currently in development and/or production.”

Download the report here.

Latest Issue

E&T cover image 1604

"Should the UK's engineers be in or out of Europe? The IET sets out its official position on the EU referendum this week - will you agree?"

->

E&T jobs

  • SAP TEAM MANAGER GENERAL ENQUIRIES

    SSE
    • Melksham, Swindon or Oxford
    • £33,520 TO £44,269 + CAR (SSE7) DEPENDING ON SKILLS AND EXPERIENCE

    An exciting opportunity has arisen for an Overhead Tower Line Manager within Power Distribution covering Southern England.

    • Recruiter: SSE

    Apply for this job

  • Principal Engineer - Submarine Operability

    BAE Systems
    • Cumbria, England, Barrow-In-Furness
    • Competitive package

    As a Principal Engineer - Operability, you will be using your knowledge of submarine systems operation to influence the way the systems are designed, ensuring the Royal Navy personnel will be able to operate the system effectively

    • Recruiter: BAE Systems

    Apply for this job

  • OVERHEAD TOWER LINE MANAGER

    SSE
    • Southern England
    • SALARY £42,149 - £62,427 + CAR (SSE9/10) DEPENDANT ON SKILLS AND EXPERIENCE

    An exciting opportunity has arisen for an Overhead Tower Line Manager within Power Distribution covering Southern England.

    • Recruiter: SSE

    Apply for this job

  • Electrical Engineer - Water

    Premium job

    Mott MacDonald
    • Peterborough, Cambridgeshire

    Mott MacDonald's highly successful Water and Environment Unit is recruiting an electrical engineer....

    • Recruiter: Mott MacDonald

    Apply for this job

  • Electrical Design Engineer

    Premium job

    Mott MacDonald
    • Cambridge, Cambridgeshire

    Mott MacDonald's highly successful water business continues to win and deliver a fantastic amount of work....

    • Recruiter: Mott MacDonald

    Apply for this job

  • Senior Programme Manager

    Network Rail
    • England, London
    • £76800 - £86400 per annum

    Do you possess a track record of taking the lead on large projects?

    • Recruiter: Network Rail

    Apply for this job

  • Professor and Head of the Department of Electrical and Computer Systems Engineering

    Monash University
    • Australia (AU)

    Shape the future direction of a Department which is currently involved in ground breaking innovative research

    • Recruiter: Monash University

    Apply for this job

  • Rail Engineer

    Frazer-Nash Consultancy Ltd
    • Burton, Dorking, Glasgow
    • £ Competitive + Benefits

    Some of the most exciting infrastructure projects in the UK over the coming years are in rail.

    • Recruiter: Frazer-Nash Consultancy Ltd

    Apply for this job

  • Electrical Power & HV Engineers

    Frazer-Nash Consultancy Ltd
    • Bristol, Burton, Glasgow, Gloucester, Plymouth, Warrington
    • £ Competitive + Benefits

    Frazer-Nash is currently embarking on a period of significant growth of our electrical, electronics, control and instrumentation capability.

    • Recruiter: Frazer-Nash Consultancy Ltd

    Apply for this job

  • Control and Instrumentation Engineers

    Frazer-Nash Consultancy Ltd
    • Bristol, Burton, Dorchester, Glasgow, Gloucester, Plymouth, Warrington
    • £ Competitive + Benefits

    Frazer-Nash is currently embarking on a period of significant growth of our electrical, electronics, control and instrumentation capability.

    • Recruiter: Frazer-Nash Consultancy Ltd

    Apply for this job

More jobs ▶

Subscribe

Choose the way you would like to access the latest news and developments in your field.

Subscribe to E&T