Discussion started by CardJoe, 3 Jun 2011.

    And now the apps side of Sony was also hacked supposedly by a SQL injection again... Anyone seeing a pattern here, like all these sites have the same validation.
    I am a website developer; the most newbie mistake to make is to use inline SQL with params from the query string/form post without validating them/quoting them. It is very easy to modify query string params or fake your own posts, you can even get an addon for Firefox to do it. This is not sophsticated hacking, it is Sony's website developers who have no clue on security
