How to be a "black hat": Hacktivismo

Hacktivismo has a very interesting article on exactly how to find SQL injection exploits and how to find sites that are vulnerable. How to be a "black hat" as they say.

Some may argue that this type information is irresponsible but I think its the opposite. The more we know about vulnerabilites and issues the stronger security is.

I have from time to time used search engines for years just to see whats out there and vulnerable. There are a few simple search engine queries that can get you all sorts of information that should never be public without making any "attack". The fact is many people are so sloppy that they have DAT files or even text files, full of customer and credit information, right in the webroot. They dont link to it so they think its "secret" or something. If you dont know what you are doing then get a qualified security person to help you, its not rocket surgery.

For more see the linked Hacktivismo article.   SQL Injection Attacks For Dummies: Hacktivismo