Skip to main content
InfoSec aXioms
Ofer Shezaf contemplating the role & value of information security

You are here

Home

WHID 2003-8: SQL Injection in PetCo.com leads to FTC investigation

Share/Save

Additional information:

  • Petco settles charge it left customer data exposed [Infoeworld, Nov 17 2004]
  • Petco settles with FTC over cyber security gaffe [Security Focus, Nov 17 2004]
  • FTC investigates PetCo.com security hole [Security Focus, Dec 5 2003]
Attack Method: 
SQL Injection
Incident Outcome: 
Disclosure Only
  • Add new comment

Science or Religion?

  • Risk Management
  • Research Analysis
  • Solutions Accuracy
  • Open Source
  • Patents

Further Research

  • Defining a WAF
  • Detecting Credit Card Numbers in Network Traffic
  • Secure Development Life Cycle
  • Positive Security & Learning
  • Signatures & Negative Security

Presentations

  • Analysis Of The Web Hacking Incident Database (video)
  • Pen-testing RESTful Web Services
  • WAFs in the cloud
  • Wiki Security

  • About
  • Contact
  • Legal Stuff
Copyright © 2011 Ofer Shezaf.Theme by Kiwi Drupal Themes, based on Tarski project.