By George Norman - Software News Editor
Added on 12 Feb 2009(962 Views)




The Romanian hacker that made the news this week by blowing the whistle on an SQL injection affecting two of the best known security software developers, Kaspersky and BitDefender, is not resting on his laurels and is now putting the Finish experts from F-Secure to the test. According to Unu, the alias used by the hacker in question, the web page of F-secure is vulnerable to SQL injection and XSS (cross site scripting); the good thing is that no confidential or sensitive data has been leaked. The only info that Unu managed to access is related to past virus activity and some statistics.

“During the last few days a Romanian group has been doing SQL injection attacks on several security vendor's websites and early this morning they hit us,” replied F-Secure. “One of our servers used in gathering malware statistics had a page that didn't properly sanitize input and was therefore vulnerable to attack. Fortunately we utilize defense-in-depth strategies so the attack was only partly successful. Although the attackers were able to read information from the database they couldn't write or manipulate it. And they couldn't access any other data on that server because the SQL user only had access to its own database, which only contains public information that is shown on our statistics pages. So while the attack is something we must learn from and points at things we need to improve, it's not the end of the world.”


It may not be “the end of the world” but it is properly embarrassing when a company that specializes in security solutions is vulnerable to some sort of exploit or attack.

While Unu’s success may have been a limited, some other hacker has been successful in compromising the official web page of Germany’s Interior Minister, Wolfgang Schäuble. The attacker exploited a security vulnerability in the Typo3 content management system and placed the “Visit: Vorratsdatenspeicherung” message on the site. The attack seems to have been spurred by the minister’s support for biometric passports and logging all email, internet, landline and mobile phone communications.





Don't forget to:

RSS


Tags: F-Secure, Unu, Kaspersky, BitDefender, Germany, Interior Minister

Link to this article:



Add comment:
Name(Required)
Email(Required - Never shown)
Website(Optional)
Comment(Required):

Insert the following code:
Software News
Linux Mint 9 KDE Final Coming Soon, Linux Mint 9 Xfce RC Out Now
If you’re really delighted with the Linux Mint 9 KDE RC (Release Candidate) that was released about a month back, then I have some exciting news for you: the final version of the operating system is ...
22 Jul 2010
New Communication Tool for Advertisers: Click & Call Advertising with Skype
Skype boasts the fact that its goal is to facilitate meaningful connections either free of charge or at a very low cost. With that goal in mind, Skype has announced the release of a new tool that allows ...
22 Jul 2010
Adobe Announces Protected Mode for Reader
Adobe, the California-based company that specializes in creating multimedia and creativity software products, recently announced that, for the sake of all its customers, it plans to make Adobe Reader safer...
22 Jul 2010
Google Revamps Image Search
Mountain View-based search engine giant Google is on a revamp spree. The well-known company revamped its homepageGoogle.com, revamped the popular video sharing site YouTube...
22 Jul 2010
Apple Reports Record Revenues and Profit for Q3
Cupertino-based software developer Apple recently made public its financial results for Q3, the third fiscal quarter of 2010 which ended on the 26th of June. In Q3 Apple did even better than in Q2...
21 Jul 2010
True to Its Word, Yahoo! Opens the Yahoo! Messenger Platform
Yahoo! Messenger is used by millions of people all over the world on their desktop and mobile devices. Thanks to Yahoo! Messenger all these people can easily manage their social contacts, ...
21 Jul 2010
Recommended Tools
Top Downloads