Security Management
Published on Security Management (http://www.securitymanagement.com)
Third IT Security Vendor Breached in a Week
By Matthew Harwood
Created 02/12/2009 - 10:52



    
Wrap-Up?: 
No
Weight: 
0
Lead Headline?: 
No
Date: 
02/12/2009
By Line: 
By Matthew Harwood
Teaser: 

Hackers that visit a Romanian Web site, Hackersblog, have claimed the third straight breach of a security vendor's Web site using SQL injection in a week.

Hackers that visit a Romanian Web site, Hackersblog, have claimed the third straight breach of a security vendor's Web site using SQL injection in a week.

This time, it's F-Secure [1], a Finnish antivirus vendor.

SearchSecurity.com reports [2]:

A Romanian hacker has detailed the latest SQL injection attack in a posting on the hackersblog.org forum. [3] The anonymous hacker said he viewed some statistics regarding past virus activity after exploiting coding errors on the Helsinki, Finland-based antivirus vendor's website. The hacker said the website was vulnerable to both SQL injection and cross-site scripting attacks.

The hacker posted screenshots of the SQL Server information and database table names.

"It was not even part of our critical infrastructure, nonetheless we're considerably embarrassed," David Frazer, director of technology services for F-Secure's North American division, told the IT news site. "As a security company it's still something that we should make sure is patched and up to date."

An SQL injection takes a small malicious bit of code and inserts it into a database. When done properly an attacker can gain access to the breached database.

Also this week, two other hackers on the same site posted news that they successfully breached two other security Web sites using SQL injections.

A hacker known as Unu breached the Kaspersky's U.S. Labs Web site on Saturday, reports eFluxMedia [4].

"Kaspersky is one of the leading companies in the security and antivirus market. It seems as though they are not able to secure their own databases," Unu posted on Hackersblog. "Alter one of the parameters and you have access to EVERYTHING: users, activation codes, lists of bugs, admins, shop, etc.," he added.

Kaspersky officials said no sensitive information, such as credit card numbers, had been breached and that a specialist would conduct an audit of its systems.

Two days later, the Portugal Web site for BitDefender was breached.

Related Resources: 

"Corporations are Biggest IT Security Threat to Customers, IBM Says [5]," by Matthew Harwood, Daily Headlines, Feb. 4, 2009

"New Hacking Tool Uses Google to Find Web Site Vulnerabilities [6]," by Matthew Harwood, Daily Headlines, Feb. 25, 2008

"Oh What a Tangled Web [7]," by Matthew Harwood, Security Management, Sept. 2004

Comments


Security Management is the award-winning publication of ASIS International, the preeminent international
organization for security professionals, with more than 38,000 members worldwide.

ASIS International, Inc. Worldwide Headquarters, 1625 Prince Street, Alexandria, Virginia 22314-2818 U.S.A.
703.519.6200 | fax 703.519.6299 | www.asisonline.org

ASIS

© 2013 Security Management
This site is protected by copyright and trade mark laws under U.S. and International law.
No part of this work may be reproduced without the written permission of Security Management.

Powered by: Phase2 Technology

Source URL: http://www.securitymanagement.com/news/third-it-security-vendor-breached-week-005205

Links:
[1] http://www.f-secure.com/f-secure/
[2] http://searchsecurity.techtarget.com/news/article/0,289142,sid14_gci1347639,00.html?track=sy160
[3] http://hackersblog.org/2009/02/11/f-securecom-sql-injection-cross-site-scripting/
[4] http://www.efluxmedia.com/news_Even_Kaspersky_Labs_Web_Site_Is_Vulnerable_To_Hacker_Attacks_34709.html
[5] http://www.securitymanagement.com/../../../../../../news/corporations-are-biggest-it-security-threat-customers-ibm-says-005189
[6] http://www.securitymanagement.com/../../../../../../news/new-hacking-tool-uses-google-find-web-site-vulnerabilities
[7] http://www.securitymanagement.com/../../../../../../article/oh-what-tangled-web