Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I went to a presentation once by a guy who does pen testing for banks. He showed us how a script can run google searches for potentially vulnerable sites, and attempt sql injection attacks against them. When vulnerable sites are found, the trick is to query system tables to get the names of all tables in the database, and then just suck everything down for analysis later. He claimed the Russian mob is doing it.


Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: