32mil passwords compromised, SQL injection attack on RockYou
guardian.co.uk
guardian.co.uk
Normally I'm not so hasty to call for head-chopping and head-rolling family fun, but I would think this is entirely called for.
My final project in class gets and instant 0/100 (40% of the grade) if SQL injection was possible...
(So is not using a modern database abstraction library. Even PHP has them these days!)
The average web service has a complexity far greater than any college course project. SQL injections can be mitigated using the correct tools and methodology, but things like this (and buffer overflows) will continue to exist. Such is the nature of things.
There's "oh man, this one variable isn't sanitized", which is a bad, but understandable mistake.
Then there's "oh man, we don't encrypt our passwords AT ALL", which really belongs in the realm of mistakes made by 15 year-olds.
No seriously, the last time I made that mistake was when I was 15.
SQL Injection is very very common. I've worked on sites that never sanitize anything.
Totally guessing I'm thinking $0.50/1000 to $5/1000 for: $16,000 - $160,000. But I don't even know if I'm in the right ballpark.
I also assume you can resell these many times, so it could conceivably be worth hundreds of thousands.
You just opened the door to everything about these users.