Settings

Theme

What to do after discovering SQL Injection vulnerability in random websites?

3 points by mariocarvalho 12 years ago · 4 comments · 1 min read


After playing a little with Vega - I'm newbie in web auditions, just trying to learning something new - and auditing some websites I can see that 8/10 websites have SQL Injection vulnerabilities classified by Vega as High. What should I do here? Email the website owner?

pktgen 12 years ago

I would be very, very, very careful here. Not sure what country you're in, but you're setting yourself up for possible legal action, even though your intentions are good.

gk1 12 years ago

You can email the owner with a few tips to fix the issue. You can even offer to do a deeper inspection for some fee.

  • INIT_6 12 years ago

    That might be interpreted as extortion. OP read up on responsible disclosure.

    • gk1 12 years ago

      That's why I was careful to say that you should offer tips to fix the issue, not ask for money to do so. As for the second part (offering to do a security audit), I don't see how that's any different from cold-emailing someone with a proposal to redesign their site.

Keyboard Shortcuts

j
Next item
k
Previous item
o / Enter
Open selected item
?
Show this help
Esc
Close modal / clear selection