WHID 2007-70: Tucson, Arizona police web site defaced using SQL injection
Just like WHID 2007-60, this hack is probably a representative of many other incidents. The Indonesian hacker Hmei7 has left the message "Hmei7 has touched your soul" on the Web site of the police department in Tucson, Arizona. Only unlike regular defacement, this time it is not the front page but rather the news section that was modified.
As many you know, the news section is one of the few database driven parts in many mostly static sites, as it allows the site owner to add news without requiring a web designer. Therefore it came as no surprise that the attack was identified by a public source as an SQL injection attack.
Additional information:
- Indonesian hacker touches souls by bringing down police web site [The Register, Dec 20 2007]
Attack Method:
Incident Outcome: