The InformationWeek -- Blogs
Security

Topics:   Security

  • Email this page E-mail this page
  • Print this page Print this page
  • Bookmark and Share
  • icon

RIAA Attacked: The SQL


Posted by George Hulme, Jan 21, 2008 12:24 PM

The Recording Industry of America's (RIAA) Web site was attacked -- again -- over the weekend. According to numerous breaking news stories, it seems a lack of proper security controls enabled some to take parts of the site down, and tweak its pages. Get serious.


It looks like a plain vanilla SQL injection vulnerability was publicized on the social news network site Reddit, and the attacking escalated from there.

The RIAA.org Web site appears fully functioning now, but that probably won't last too long if history is any indication. During the past five years the site has reportedly been defaced and has undergone several denial-of-service attacks. Things got really sticky a few years ago when Sen. Orin Hatch proposed to give the entertainment industry the right to attack systems used by illegal file swappers.

How about a search warrant?

Other than a laugh, these more recent hacks aren't going to push their argument against the RIAA, its lawsuits, or the demise of DRM any further.

Energy would be better placed by hounding Congress to improve the Digital Millennium Copyright Act (DMCA) and boycotting the purchase of DRM-enabled music files and CDs. Speaking of DRMed music files, they’re already starting their fade into oblivion.

Nearly every, if not every, major record label already is starting to release DRM-free files. In fact, defacing Web sites is about as petty as trying to sue your customer-base to save a dying business model.

Speaking of petty: Why won't the RIAA spring for the occasional server assessment?

« AT&T Makes The Enterprise iPhone Official | Main | Windows Server 2008: Less Is More »



Sign Up Now
For InformationWeek News Alerts




This is a public forum. United Business Media and its affiliates are not responsible for and do not control what is posted herein. United Business Media makes no warranties or guarantees concerning any advice dispensed by its staff members or readers.

Community standards in this comment area do not permit hate language, excessive profanity, or other patently offensive language. Please be aware that all information posted to this comment area becomes the property of United Business Media LLC and may be edited and republished in print or electronic format as outlined in United Business Media's Terms of Service.

Important Note: This comment area is NOT intended for commercial messages or solicitations of business.




 
 

  1. Sequential Programming: Like Eating Peas with a Straw.
  2. Biomolecular device using self-assembled DNA nanostructures?
  3. Coreinfo v2.0: A Simple Utility to Understand the Manycore Complexity in Windows


Join The InformationWeek Group On LinkedIn


                           


  1. More Reasons Why Linux Misses The Desktop
  2. Too Much Netbook For Too Litl?
  3. Motorola Explains Why Droid Doesn't Have Multi-Touch
  4. Sprint And T-Mobile Headed The Wrong Direction


  1. Review: Motorola Cliq Smartphone
  2. Florida Hospital Dials Up iPhones For Nurses
  3. Full Nelson: A Web Presence Needs Sizzle, My Nizzle
  4. Is Antivirus Software Dead?
  5. Practical Analysis: The Fastest-Growing Security Threat
  6. InformationWeek Analytics Research: Federated Search

 

  Ars Technica
Boing Boing
Channel 9 Forums
CRN Blogs
Dr.Dobb's Portal: Blogs
Engadget
Gizmodo
GrokLaw
  Lifehacker
Schneier on Security
Slashdot
TechCrunch
Techdirt
Techmeme
Valleywag

  DECEMBER 2008
NOVEMBER 2008
OCTOBER 2008
SEPTEMBER 2008
AUGUST 2008
JULY 2008
JUNE 2008
MAY 2008
  APRIL 2008
MARCH 2008
FEBRUARY 2008
JANUARY 2008
DECEMBER 2007
NOVEMBER 2007
OCTOBER 2007
SEPTEMBER 2007