Ah.  You're from the "blame the victim" school.

Unfortunately, when I wrote the first 1,000 ColdFusion templates using Ben
Forta's CF 4.0 book, there was no CFQueryParam.  So going back and rewriting
all those programs (now well into several thousand) has been a bitch.  And
all it took was one missed spot.

So I shouldn't be mad at the poor little hackers, because they were doing us
all favor by pointing out our faults.  That is your school of thought,

Dave Morris

> > Anyway, I propose the dot-com millionaires who left us stuck
> > with the current mess in the spam and virus arena be
> > personally required to fund an international Goon Squad with
> > kneecap breaking instructions to go after these vandals.
> And who exactly would that be?
> > If someone did this crap to your house, you'd have the police
> > and/or FBI out there in a heartbeat tracking down the
> > criminals.  This is criminal mischief on a global scale.
> If you left your front door open, so that anyone could just walk in,
> you'd
> have no one but yourself to blame. If you're looking for an analogy,
> that's
> the one that fits. The reason this particular attack has been so
> successful
> is the arguably criminal negligence of so many web developers, coupled
> with
> the typical improper usage of administrator rights on untrained users'
> desktops.
> People have been harping on these two issues for years - I know I have.
> As a
> web developer, one of these issues is within your direct control. If
> you've
> failed to do anything about unparameterized queries until something bad
> happens to you, you've failed to meet the minimal due diligence for
> being a
> web application developer.
> > And if Interpol won't do anything about it, and if the powers
> > that be refuse to attach any form of responsibility or
> > traceability to the ownership of an IP address, then we may
> > just have to implement vigilante measures and go after the
> > crooks ourselves.
> Well, uh, good luck with that. Let me know how it goes with you against
> the
> Russian mafia. This stuff is no longer just maladjusted kids in their
> parents' basement - there's money to be had here, and there are people
> going
> after that money. I suggest your efforts are better directed at
> ensuring the
> adequacy of your own sites' protection instead.
