ChromePlatedEquator
19872
414
12
Every security person at every company doing this sort of thing should start panicking right now, for real.
My company is doing something similar with AI (with similar goals) and I bet it's exploitable just like this company's AI 'helper' was.
https://codewall.ai/blog/how-we-hacked-mckinseys-ai-platform
MendoncycleSmith
Fuck AI.
justadude41123
If you’re writing code that is vulnerable to sql injection and it makes it to production, your company has no business being in business. Software developers are arrogant enough as it is, the consequences for such an amateur mistake are not harsh enough.
cytherians
If someone could do this, imagine what the FSB could do.
Putin's FSB must already have the entire database.
relsky
Heh. My company uses McKinsey, as does just about every other major corp. These idiots are going to destroy themselves and I have a front row seat.
relsky
And yeah, I know I'll burn too. That's okay. The world is already destroyed - we are the bacteria bloating the corpse of our already dead planet.
DerpyBestPrincess
Coding AIs are amazing TOOLS. Using them in 100% autonomous mode is absolute insanity.
nachosyndicate
Now imagine that McKinsey and Co. is running a war.
netharia
They've probably done work on it. They take a lot of military contracts.
Munchman347
in the past, companies have tried to impress investors and shareholders by adopting the latest 'trendy' action of the day. This ultimately ended in a cringe fest, causing the 'new thing' to be quietly dropped. AI is a cancer... once adopted, it takes over and eats away at all your protections and operating systems, eventually killing it's host while praising itself for a job well done...
slightlybrokenegg
God damn a literal 10 year old could pull of sql injection. How the hell is that still a vulnerability in your systems in 2026 ffs.
sadurdaynight
Why would your ai agent that has control over critical internal systems be able to get interacted with from external sources? That makes no sense. Sandbox and compartmentalize that shit.
baecaughtmewhackin
Bind variables. They aren't that fucking hard.
evilspock
I remember back in the ancient days when I was a scrub wondering why those existed when you could just pass a string. The reason they exist isn't super obvious. And when I was a CS major in college a VERY long time ago - bupkis. I'm not even sure I had a security-related class. I hope that's been addressed, or it would explain a lot...
relsky
Heh. My company uses McKinsey, as does just about every other major corp. These idiots are going to destroy themselves and I have a front row seat.
zordac
Bitdefender says:
Feature: Online Threat Prevention
The page https://codewall.ai/_/service_worker/63b0/sw_iframe.html?origin=https%3A%2F%2Fcodewall.ai&1p=1 has been detected with suspicious activity. It is not recommended to continue browsing this website.
RCSpotz
And then it started its own crypto mining service
Shaodyn
And its own internal scanners saw nothing wrong.
somebackup
Isn't McKinsey the company that caused the theme park deaths? Semi sure it was Disney world
PaperinoVB
Little Bobby Tables is married, with children, and probably is telling them a story like "When I was your age I destroyed an entire school database just existing! You see, my mom, your grandma..."
[deleted]
[deleted]
jakedafish
Do you know who Bobby Tables is?
RichardPotato
Oh now I wanna know what the comment was
1stDrunkJoe
Oh what a bubble we weave...
DarthAndy
zordac
Replying to your comment since it is at the top. Bitdefender says:
Feature: Online Threat Prevention
The page https://codewall.ai/_/service_worker/63b0/sw_iframe.html?origin=https%3A%2F%2Fcodewall.ai&1p=1 has been detected with suspicious activity. It is not recommended to continue browsing this website.
bittenicht39
For those wondering: https://xkcd.com/327/
cokebot9000
Also https://bobby-tables.com/
MrAcurite
> this company
McKinsey isn't just "a corporation". There is a solid argument to be made that they are the single most evil corporate entity on the planet. They've helped push opioids, greenwash oil companies, kill dissidents and journalists, and inflate income inequality.
scrumbles666
I was wondering the other day if some place like reddit had ever done like a sweet 16 bracket for evilest company. Do a pole, take the top entries and then have a weekly debate over who has done the most harm. How does McKinsey stack against the Chiquita or Phillip Morris?
textilelover
Or, "your water is not yours and you have no right to it" Hershey.
jintoabriel
The John Oliver episode on them, https://youtu.be/AiOUojVd6xQ
SMarkt
lol. i always get downvotes, when i tell people that i still use checks and no homebanking as a programmer. they cannot fake an underwritten piece of paper so easyly.
bittenicht39
Well, there was this guy they made that film with Tom Hanks about…. But he was lying about his fraud, so who knows.
SMarkt
yeah, but in this case, its the banks problem not mine. i can always say: check the writing. its not mine. also my bank account is way too small to fake checks. but if you got a collection of bank accounts that can be easyly hacked, even small accounts are interesting. and the bank will always say, it was your fault, giving away passwords or not enough security software running, to keep the loss small. good luck proving otherwise.
tinyfootprints
Validating input is one of the first computer programming lessons I ever got. Otherwise, you could be vulnerable to all manner of injection attacks.
dashers
And yet, I'm still here pointing out these sorts of issues to "senior" developers.
tinyfootprints
I'm amazed how some people can keep a job. I did a 6-month consulting gig at a major corporation. On my first day, a guy there was struggling to get the formatting right on a report he was printing. Over the next six months, I developed a real time reporting system that communicated with the transponders on every plane in the fleet and reported it in an intuitive way. On my last day, the same guy was still struggling to format a printed page properly.
dashers
In my experience, the majority aren't that motivated to become any good at things.
tinyfootprints
I enjoy exercising expertise in any field of endeavor. I get more joy from doing a few things really well that I do from a boatload of marginal jobs. That said, indolence has its appeal. I once spent a week at a Sandals resort and very quickly acclimatized to having no responsibilities at all. The first few days back in the real world were challenging.
TheOldSchoolisBack
A startup with threeengineers probably wouldn’t have been so vulnerable. This is bragging on how effective your lock picking tool is on an unlocked door.
dproz
This... Bigger companies are more susceptible because of "well, someone else will surely patch that before it goes to prod" mentality.
Sylventhe
I think the key here is expectations. A large company, with significant resources, is expected to have the resources to handle things like this.
OrkenMork
Come on now...SQL injection isn't even "hacking" anymore...It's the equivalent of leaving your door open...If you're an IT person and your system gets "hacked" via SQL injection, then quit and get out of the industry...do something else that won't cause harm...like basket weaving or Naval contemplating...I hear that's always good..
JohnSmithterms
I wonder if you know all the owasp flaws in sql injection besides escaping and sanitizing all data coming into the back end. So checking for special characters, converting to a string object, that sort of thing. I bet there's a hole in your knowledge.
ChazzK
I have a feeling it would be one of those "your password is actually just Password?" "Who's going to guess the IT head would be that dumb? I at least capitalized the P." moments.
Zamerine
The scary part is the autonomous stuff; it takes time and effort to hack but if you simply brute force every known vulnerabilities in every direction available you will find something.
No software is without mistake, be it the soft itself or the hundreds of librairies and such that everything uses. What saves (or saved) us before was that time and effort cost money so the likelihood of someone brute forcing was low... but now with a tool like that ...
CallMeCourierSix
*navel
Lynkfox
With vibe coding on the rise it's no surprise that this happens. If you don't specifically tell it to do things like sanitize the inputs then it won't, and if you don't know what to tell it (ie already have experience) then it will give you the minimum.
reddles
I blame the models for that. You should have to tell it not to do those things.
ElbowDeepInAPoliceState
You're assuming it'll even do that right
pgdave
I worked for the USPS for a few months - they had 12 year old code that was absolutely vulnerable to very simple SQL injection. It was behind reasonable authentication security, so it would have to have been an existing user, or a weak password combined with someone who got on the internal network, but it was just "select * from [table] where column = '" + user_input + "';". One of the first things I did was to parameterize every single query. My PM disliked that there was nothing to show.
LoopStricken
I suspect you meant navel, but what would I know.
OrkenMork
I blame autocorrect...I've never used that word before so my phone guessed wrong.
pt2016
I salute you, fellow nitpicker.

Madalchemist2018
Some people just want to watch the ships burn.
1stDrunkJoe
Long walk off a short pier whatever, 'nature finds a way'.
Chereazi
Still have to tell it to plenty of devs in code reviews...
"It's just an integer, nothing can happen there!" Technically correct, but bad practice and there's no guarantee that the type doesn't change later on.
"I'm checking here if that string could be used for an injection, it's safe!" No, there's no guarantee you thought of everything, it's additional needed maintenance, and it could break. Just use the proper tools ffs...
BananaForScaIe
"it works for now" isn't the same as "it's secure forever".
JohnnyPumpkinStar
If anyone can even consider manually checking or sanitizing anything for SQL, the codebase itself is the actual problem. You don't need tools, you don't need to think, every database and language in the world has SQL injection proof methods for 15+ years. You have to actively bypass the normal methods to make it vulnerable.
This company probably had some intern do some hacky 'proof of concept' integration in 2022, then pushed this shitbox demo live with no oversight or checks.
OrkenMork
In the perfect world, you're correct...but the 12 year old cousin to the CEO can't think of everything. And the real world is far messier. Many times I've found data on URLs that allows me to plumb the depths of the customer database. One time, I was filling out a questionnaire and at the end, they gave you the option of purchasing, using your credit card an item based off of the questionnaire. I did and got a customer number which I noticed matched the "id=#######" on the URL. So for
->2
OrkenMork
2) shits and giggles, I went up to the URL and iterated the "id" one number higher and got another person's information, including credit card, address and phone number. So I wrote a small script and dumped their entire customer database. I encrypted it, grabbed a few examples, sanitized the PII and sent it to the WHOIS contact with my information. The guy reached out and acted as if I performed magic. I explained what he needed to do and together we fixed his problem.