Leakage of Information

WHID 2009-43: Web Mail Company to Pay Prize After CEO Hacked

Updated: 
5 June 2009

What does a challenge to break an web mail system and get $10,000, broken within minutes prove? Is it a lesson in vanity? Or about the state of web security? Or about security in general. Probably all.

The most obvious observatoins is that offering $10,000 for anyone who can break your site and being broken within an hour shows that you don't know what you taking about. Maybe it would be a lesson to all security vendors to not believe their own marketing verbiage. A quick browse of the bugtraq vulnerability archives will show how insecure and easy to evade security products can be.

However, judging from the number and seriousness of the incidents reported on the web hacking incidents database, StrongWebmail is not alone and far stronger companies suffers severe incidents, making web applications the weakest link in an organizations information security.

Lastly, we should always remember that there is never perfect security. By making systems more secure we are just raising the price required to attack them and lowering the damage of such an attack, but never. As the old joke goes: the only secure system is one without users.

 

WHID 2009-39: Uno is back: 245,000 records stolen from Orange France using SQL injection

Updated: 
26 May 2009

After focusing earlier this year on Anti-Virus vendors, Uno, the Romanian Hacker is now back and reports in his blog that an Orange France web site dedicated to photo management is vulnerable to SQL injection and that he was able to access 245,000 records from the web site.

WHID 2009-36: Hackers steal Austalian and NZ Shell customer info (Updated)

Updated: 
19 April 2009

Update (Apr 19th 2009) - (Presumably) the hacker posted a comment to this story with some details. He says that the number of records leaking was much higher: 17,000 Aussies and 7,000 Kiwis. The rest we did not understand and hope that either he or any of you can clarify.

Read more...


Leakage of information from an energy company is usually associated with gas stations fraud such as installing a stealth credit card reader at the pump. However, a report suggests that an incident in which information about 4500 Australian and 1400 Kiwis leaked was a result of a glitch in a web based application for applying for a Shell fuel card. The information obtained included company names, address details, email addresses and some bank account details.

WHID 2009-35: Former US Senator Donors Information Leaks

Updated: 
17 March 2009

Norm Coleman, a former senator from Minnesota, is going through a legal battle to try to win back his seat in the senate. If the way he manages his web site security and the crises it created are an indicator, I am not sure that he has a place there.

read more...

WHID 2009-34: Romanian Hacker Moves On To The Telegraph

Updated: 
10 March 2009

Another week, another hack by the HackerBlog, and when it targets an important web site and the impact is severe it is worthy of WHID. This time the Romanian hacker used blind SQL injection to penetrate to the web site of the Telegraph, a leading English daily paper.

Among his findings is a table including 700,000 e-mails, which would be a gold mine for spammers.

The Telegraph response was published on their official blog.

WHID 2008-60: Miley Cyrus Pictures Leaked Due to a Web Hack (Updated)

Updated: 
19 April 2009

Update (April 19th 2009) - E!News provides additional interesting details about Josh Holly, the hacker who carried out the attack providing an interesting insight into the celebs hacking phenomena.

Read more...


Celebs are fast becoming a prime hacking target. Miley Cyrus already made her debut at WHID when her Twitter account was raided. But it seems that this was not her first cyber incident for her. As reported by Wired, late last year a hacker named Josh Holly published private photos of Ms. Cyrus stolen from her G-mail account.

WHID 2009-29: FBI & Secret Service warn of a sophisticated HSM attack

Updated: 
25 February 2009

The FBI and US Secret Service issue an alert on attack using SQL injection to penetrate banks secret key vaults: the enigmatic HSMs. Yet, nobody hears about it. Sounds like a movie plot, can it really be?

read more...

WHID 2009-28: Serious Leakage on Mac clone Maker's site

Updated: 
25 February 2009

The Register reports that the online shop of Psystar, a maker of Mac compatible equipment is heavily leaking technical information that can  be expoited to hack the site.

WHID 2009-26: F-Secure Joins The Breached AV Vendors Club

Tagged:  
Updated: 
19 February 2009

It wasn't surprising that after attacking a Kaspereski and a BitDefender web sites,another anti-virus vendor would follow

Read more...

 

WHID 2009-23: Miley Cyrus Twitter Account Hit By Sex-Obsessed Hacker

Tagged:  
Updated: 
19 February 2009

It is Twitter again, it is a celebrity again.

Read more...

 

Syndicate content