Hackers pants antivirus database

By Angela Gunn | Published February 9, 2009, 5:53 AM

kaspersky logoA good cook can burn a dish, a good outfielder can drop a can o' corn, and a good antivirus company can apparently have a big gap in their database defenses, as poster "unu" makes abundantly clear at HackersBlog at the moment.

The compromised site is kaspersky.com, and though unu was kind enough to blot out some of the crucial details of the vulnerability in his/her post, it appears that simply changing a few parameters breaches a SQL database containing users, activation codes... well, unu provides quite the list of tables. Can't have been much of a fun weekend over at Kaspersky with that flapping in the breeze.

Comments

View comments by with a score of at least

Kaspersky signs in with their take on events. (Same link as given by BadIronTree, but with perhaps a less inscrutable comment preceding it.)

http://www.kaspersky.com/news?id=207575747

Score: 0

|

Score: 0

|

How can we trust Kaspersky when they can not even protect there OWN assets!! ALL THIS COMPANY DOES IS PROVIDE SOFTWARE TO PREVENT ATTACKS.. Now they fall to a script kiddie? SQL attacks are very old..

Score: 0

|

I think they call that "a schoolboy error"...

Score: 0

|

I never did understand hacking and the deliberate destruction of other peoples property. I hope they catch the little critter and even though most of them think they cannot be caught, they will be. It is indeed a sad world we live in when people think these things are funny.

Score: -2

|

I agree ... they should institute judical caning for stuff like this.

Score: -1

|

People will never stop trying to break something for various selfish reasons (revenge, money, etc). And these people will not advertise the fact that they broke something. Instead they will try to make it look perfectly normal, while they siphon sensitive data out of the system they cracked.
This will never stop.
So, when someone cracks something for fun, it's not really a problem. It prompts system maintainers to fix the breach, which in turn will prevent the system from being compromised in the future. And if some data is lost...well, ever heard about 'backups'?

Score: 0

|

Which would you rather: Your system hacked by someone out for their own gain, or someone who's doing it just to prove a point?

Thought so.

Score: 0

|

You are right, anyone pointing to engineering errors should rot in prison. This will make us all safer, or at least it will make us feel safer, and that's all that matters, right?

Score: 1

|

So your stating that everytime you've had an issue with a device or product and you've called tech support, by you calling tech support and pointing out an engineering flaw, that you should rot in prison? Every web site has security flaws its a nature of coding. No one can make an absolute secure program or site because there will always be user intervention. The only way to make something secure is to remove human interaction. I think its good that "unu" pointed out the fact that company senstive data could be exposed and clearly by looking at the URL in the screen shots he was in fact using a SQL injection. The fact that he was nice enough to post and let the developers know that there was a bug. I know as a site developer I would like to be notified when an exploit was found. This only makes the developers at Kaspersky better developers by showing them this type of attack is possible.

Score: 0

|

You might try reading more than the first line of a post, genius.

Score: -1

|

Hacking and "deliberate destruction of other peoples property" are not necessarily the same thing. It's *malicious* hacking that I'm concerned about.

Score: 0

|

Define "malicious".

It's going to cost them. Time spent fixing it, covering their PR nightmares, and so on.

Had this hacker let them know privately things might be different.

Now they have suffered a PR meltdown and have to allocate funds immediately (in these times), instead of planning and strategically fixing it.

This was malicious.

Score: 0

|

PC_Tool, I was referring to LakotaElf's implication that all hackers are into doing destructive and malicious things. To me, that shows an ignorance of the various meanings of the term "hacker". Probably never heard of a white hat hacker, let alone a jedi hacker. Tiger term or samurai? Maybe a tiger team. Probably thinks crackers are a food item.

Score: 0

|

Careful.. Polly's getting hungry.

Score: 0

|

Microsoft's Ray Ozzie: 'Nobody's going to be 100% open'

The mobile apps ecosystems of the world may converge over time, led by apps being ported over across platforms, according to the Chief Software Architect.

Will Firefox beat IE9 to Direct2D rendering?

Just days after Microsoft executives gave conference attendees a peek at a new rendering technology, a Mozilla contributor revealed he's working on the same thing.

Where there's smoke: Apple warranty stance raises troubling questions

Carmi Levy | Wide Angle Zoom: Smoking can be dangerous not only for your lungs, it appears, but for your Apple hardware warranty.

The fallacy of Facebook privacy

Carmi Levy | Wide Angle Zoom: If an insurance company learns something interesting about its client through the Internet, is that snooping?

Microsoft 'worked with Apple' for Silverlight on iPhone, says Goldfarb

By not making such a big deal out of trying to stream video to the iPhone, Microsoft got a big deal out of it, revealed the Silverlight product manager.

Clicker.com cuts through the Web video chaos

In a world where homemade video and Hollywood movies travel the same pipeline, it's good to have a real search engine to cut through the clutter.

A case study in improving software: What Office 2010 can learn from Notion 3

A music composition product gambles with a complete overhaul, in an effort to make headway against two well-known competitors in a tough market.

Kindle 2 update adds battery life, native PDF reader

Amazon has pushed out an update to the Kindle 2 e-reader that lengthens battery life and adds a native PDF viewer.

Safari on iPhone gets competition from a $1 browser app

Apple likes to say it gives iPhone users a full browsing experience, but a new competitor tries to incorporate more desktop browser features.

Action Replay maker sues Microsoft for Xbox 360 'predatory technological barriers'

Third-party video game accessory maker Datel has filed an antitrust lawsuit against Microsoft over the Xbox 360's recent Dashboard update.