Is this a security risk?

From: Shark Bait (SharkBait_at_discussions.microsoft.com)
Date: 04/27/05


Date: Wed, 27 Apr 2005 05:28:02 -0700

I'm doing some testing on a vendor’s web site and ran into the error below. I
told the vendor that displaying this kind of error could give a hacker the
information needed to hack the db or attempt SQL injection attacks etc. (btw
this is a bank). The vendor is telling me that there is no danger in
releasing this information on the web site. I thold them they need to display
something else.

Assuming you or a hacker had this information, company information and the
URL where this error occurred; do you think these pose a security risk?

*** This is the error with the table database and field names changed ****
Insert statement conflicted with COLUMN CHECK constraint
'AColumnCheckConstraint'.
The conflict occurred in database 'ADatabaseName', table 'ATableName',
column 'PaymentAmount'..,
PaymentXML: 10056AWEBWEB01-4858538-14 ... WEBSERVERNAME ...



Relevant Pages

  • Re: Is this a security risk?
    ... If I was a hacker, I now have a good load of information to ... The toughest part of hacking is getting enough information so that you can ... > told the vendor that displaying this kind of error could give a hacker the ...
    (microsoft.public.sqlserver.security)
  • Re: FP 2003 + interactive buttons + search
    ... Your MLS search sounds like you will need to use a database ... | displaying the interactive buttons we're using for navigation. ... | I've also been asked to add a search feature for within a web site to enable ...
    (microsoft.public.frontpage.programming)
  • Re: Refurb Dell servers: deal or no deal
    ... they list no address or business policies on their web site. ... why would you recommend such a vendor ... It's one thing to decide you don't like the way a business does business, ... I'd never heard of uogold until this thread. ...
    (alt.sys.pc-clone.dell)
  • Re: Internet Explorer and .htaccess directory protection
    ... >I have protected a directory on a web site using .htaccess. ... > displaying the 401 error message? ... can this Internet Explorer setting ... > a limit on the number of times the pop-up window shows up.) ...
    (microsoft.public.windows.inetexplorer.ie6.browser)
  • Re: "Page cannot be displayed" banner
    ... Go to Microsoft Product Support Services and perform a title search for the ... topics titled Web Site Setup, Common Administrative Tasks, and About Custom ... > You should also get a copy of WINSOCKXPFIX available at: ... >> Has anyone else experienced this banner displaying within opened webpages ...
    (microsoft.public.windows.inetexplorer.ie6.browser)