Results 1 to 4 of 4

Thread: The U.S. site Kaspersky hacked by SQL injection

  1. #1
    Join Date
    Oct 2008
    Posts
    102

    The U.S. site Kaspersky hacked by SQL injection

    This is the story of the sprinklers watered the Kapsersky company, which provides antivirus solution for millions of consumers around the world and itself as a solid company in the field of security appeared to have difficulty managing that of its website. The latter has suffered from piracy in good and due form, exposing the web of sensitive information that have quite embarrassed the publisher. At least, what a site dedicated to hacking.

    It is on the site Hackersblog.org that the pirate has published screenshots to demonstrate its piracy, explaining that he had used a SQL injection technique, which actually uses the introduction a SQL query not covered by the system. Thus, the attacker can provide a user name and password shadow to change the process of identification required.

    This type of critical security flaw is being used to purchase online by usurping the identity of a third or reach the bases kept confidential on a server. Similarly, in the context that interests us, it would have been able to steal personal information by a user comes to renew its product, says an expert from IBM Internet Security Systems

    The hacker was very correct, explaining that his team will retain or store personal data, "we just finger Pointon large websites with security problems," he said.

    Kaspersky immediately reacted by saying that the flaw was not critical, and limiting the damage, explained that yes, on the field usa.kaspersky.com, an attack was attempted by an attacker. However, the site has been vulnerable for a short period, and since the fault was detected and reported, the teams did what it took to fill the gap. Which was effective 30 minutes after the detection of piracy.

    This is not a first for the publisher who in July had seen the site cleared by a Malaysian Turkish hacker who had used the same technique SQL injection.

  2. #2
    Join Date
    Oct 2008
    Posts
    102

    Re: The U.S. site Kaspersky hacked by SQL injection




  3. #3
    Join Date
    May 2008
    Posts
    181

    Re: The U.S. site Kaspersky hacked by SQL injection

    Things happen, what. It is nice from the hacker to have just found the flaw without really enjoy. What is interesting to remember in the article, is the speed of the reaction Kaspersky and not the fault of the website. A site 100% uncrackable does not exist.

  4. #4
    Join Date
    Feb 2008
    Posts
    2,635

    Re: The U.S. site Kaspersky hacked by SQL injection

    Quote Originally Posted by Marco-D View Post
    Things happen, what. It is nice from the hacker to have just found the flaw without really enjoy. What is interesting to remember in the article, is the speed of the reaction Kaspersky and not the fault of the website. A site 100% uncrackable does not exist.
    But a team of developers to rapidly repair a fault in less than a month.

Similar Threads

  1. How to do DLL injection logic
    By Thenral in forum Software Development
    Replies: 5
    Last Post: 27-06-2011, 10:30 AM
  2. Replies: 5
    Last Post: 27-06-2011, 06:34 AM
  3. SQL Injection
    By ramsun in forum Software Development
    Replies: 3
    Last Post: 07-12-2009, 09:18 AM
  4. XML injection in a SOAP request
    By Logan.M in forum Software Development
    Replies: 4
    Last Post: 30-04-2009, 11:30 PM
  5. How to protect SQL injection attack
    By Projectkmo in forum Software Development
    Replies: 0
    Last Post: 04-12-2008, 01:48 PM

Tags for this Thread

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
Page generated in 1,714,132,212.79186 seconds with 17 queries