Worst Security I Have Seen in a Long Time

  • Post author:
  • Post category:Uncategorized

When the clueless are on the internet this is what happens.

I came across a site that had the most spectacularly bad security I have seen in a very long time. Where do I even start? SQL injection on the login page. Passwords stored in plaintext. Admin interface accessible without authentication on a different port. Directory listing enabled everywhere.

And the best part – when they found out someone had accessed their data, their response was to post an angry message on their homepage threatening legal action against the “hacker.”

You cannot make this stuff up.

The lesson here is simple. If you are going to put something on the internet, at minimum:

  • Use parameterized queries
  • Hash your passwords
  • Restrict access to admin interfaces
  • Disable directory listing
  • Do not threaten people who point out your incompetence

Basic stuff. Yet here we are.