lederhosen: (Default)
lederhosen ([personal profile] lederhosen) wrote2008-04-23 05:43 pm

Not such a good idea

Via RISKS:

The Oklahoma Department of Corrections published a web interface where the URL contained the SQL query executed to retrieve the data to be reported. Thus, any knowledgeable user could execute general SQL queries against a database containing large amounts of personal information -- including UPDATE statements (!) It was taken down only after management was shown that THEIR personal information was available.

[identity profile] lederhosen.livejournal.com 2008-04-23 10:47 pm (UTC)(link)
It was supposed to be the sex offenders' registry, but it achieved that by subselecting from a larger database - looks like if you substituted the right snippet of SQL you could access non-SO records, including not only prisoners but DOC staff.

Apparently the loophole existed for three years. I wonder what, if anything, they're going to do to verify that what they have now is accurate o.O