Loading....
Loading....

    Posted by unu in English News | Romanian News

    Posted on February 7th, 2009

    untitledKaspersky is one of the leading companies in the security and antivirus market. It seems as though they are not able to secure their own data bases.

    Seems incredible but unfortunately, its true.

    Alter one of the parameters and you have access to EVERYTHING: users, activation codes, lists of bugs, admins, shop, etc.

    First, lets see the version, user and name of the database.

    User host & password for mysql.user

    This time I will not (for reasons that need no explanation) publish any screenshot with containing personal details or activation code.

    I will only make public the names of the tables.

    Though the list is long, the table are very interesting.

    codes
    users
    vouchers
    affectstable
    bugs_settings
    bugshistory
    bugstable
    builds
    categories
    commentstable
    computertable
    editions
    filestable
    frontpage
    grouptable
    ignoretable
    milestones
    paks
    pmtable
    priority
    repfielddetail
    repfields
    repfieldset
    repoptiondetail
    repoptions
    repquick
    severity
    statustable
    substable
    userstable
    admin_users
    best_buy
    cms
    cyberCrimeRegs
    email_list
    fr_link
    fr_link_import
    interview_request
    k_test_users
    kbfaq
    kbfaq_import
    kbrub
    kbrub_bu
    kbrub_import
    login_stats
    menu
    menu_relations
    menus
    node
    partners
    partners_bu
    portal_cms_prod_ann
    portal_cms_recent_articles
    portal_cms_whats_new
    portal_product_orders
    product_names
    retail_login_stats
    retail_partners
    retail_users
    se_login_stats
    se_partners
    se_users
    setup
    shopping_com_sales
    smnr_items
    smnr_items_bu
    trials
    trials_bu
    trials_downloaded_new
    trials_rpts
    users
    users_bu
    it_hardware
    activation_code_problem
    admin_users
    best_buy
    cms
    cyberCrimeRegs
    e5users
    email_list
    fr_link
    fr_link_bu
    fr_link_import
    interview_request
    k_test_users
    kbfaq
    kbfaq_bu
    kbfaq_import
    kbrub
    kbrub_bu
    kbrub_import
    kbtop_pop
    login_stats
    menu
    menu_relations
    menus
    ms_crm_files
    ms_crm_files_support
    ms_crm_intermediary
    ms_crm_intermediary_bu
    ms_crm_intermediary_support
    node
    opt_out
    partners
    partners_bu
    portal_cms_prod_ann
    portal_cms_recent_articles
    portal_cms_whats_new
    product_names
    retail_login_stats
    retail_partners
    retail_users
    se_login_stats
    se_partners
    se_users
    setup
    shopping_com_sales
    smnr_events
    smnr_items
    smnr_items_bu
    test_users
    test_users_new
    trials
    trials_bu
    trials_downloaded
    trials_downloaded_new
    trials_rpts
    users
    users_bu
    virus_watch
    columns_priv
    db
    func
    help_category
    help_keyword
    help_relation
    help_topic
    host
    proc
    procs_priv
    tables_priv
    time_zone
    time_zone_leap_second
    time_zone_name
    time_zone_transition
    time_zone_transition_type
    user
    codes
    stores
    stores_bu
    users

    And another picture with the colons name , and the name of userstable table.

    Don’t forget to check our new article about same problem in bitdefender portugal.
    —————————–

    RO version:

    Kaspersky ocupa un loc de frunte pe piata antivirusilor si a solutiilor de securitate pentru internet. Totusi nu este capabil sa-si securizeze propria baza de date. Incredibil,dar adevarat. Un parametru prost sanitizat si avem acces la tot: utilizatori, coduri de activare,lista de buguri, admini, shop, etc.

    Prima data sa vedem versiunea, userul si numele bazei de date.

    Acum user host si password pentru mysql.user

    De data asta voi omite , din motive usor de inteles, publicare vreunei poze cu datele personale ale userilor sau afisarea vreunui cod de activare. In schimb imi permit sa fac public denumirile tabelelor. Desi e o lista lunga, sunt tabele foarte interesante

    codes
    users
    vouchers
    affectstable
    bugs_settings
    bugshistory
    bugstable
    builds
    categories
    commentstable
    computertable
    editions
    filestable
    frontpage
    grouptable
    ignoretable
    milestones
    paks
    pmtable
    priority
    repfielddetail
    repfields
    repfieldset
    repoptiondetail
    repoptions
    repquick
    severity
    statustable
    substable
    userstable
    admin_users
    best_buy
    cms
    cyberCrimeRegs
    email_list
    fr_link
    fr_link_import
    interview_request
    k_test_users
    kbfaq
    kbfaq_import
    kbrub
    kbrub_bu
    kbrub_import
    login_stats
    menu
    menu_relations
    menus
    node
    partners
    partners_bu
    portal_cms_prod_ann
    portal_cms_recent_articles
    portal_cms_whats_new
    portal_product_orders
    product_names
    retail_login_stats
    retail_partners
    retail_users
    se_login_stats
    se_partners
    se_users
    setup
    shopping_com_sales
    smnr_items
    smnr_items_bu
    trials
    trials_bu
    trials_downloaded_new
    trials_rpts
    users
    users_bu
    it_hardware
    activation_code_problem
    admin_users
    best_buy
    cms
    cyberCrimeRegs
    e5users
    email_list
    fr_link
    fr_link_bu
    fr_link_import
    interview_request
    k_test_users
    kbfaq
    kbfaq_bu
    kbfaq_import
    kbrub
    kbrub_bu
    kbrub_import
    kbtop_pop
    login_stats
    menu
    menu_relations
    menus
    ms_crm_files
    ms_crm_files_support
    ms_crm_intermediary
    ms_crm_intermediary_bu
    ms_crm_intermediary_support
    node
    opt_out
    partners
    partners_bu
    portal_cms_prod_ann
    portal_cms_recent_articles
    portal_cms_whats_new
    product_names
    retail_login_stats
    retail_partners
    retail_users
    se_login_stats
    se_partners
    se_users
    setup
    shopping_com_sales
    smnr_events
    smnr_items
    smnr_items_bu
    test_users
    test_users_new
    trials
    trials_bu
    trials_downloaded
    trials_downloaded_new
    trials_rpts
    users
    users_bu
    virus_watch
    columns_priv
    db
    func
    help_category
    help_keyword
    help_relation
    help_topic
    host
    proc
    procs_priv
    tables_priv
    time_zone
    time_zone_leap_second
    time_zone_name
    time_zone_transition
    time_zone_transition_type
    user
    codes
    stores
    stores_bu
    users

    Si inca o poza cu denumirile coloanelor , a tabelului userstable.

    Related Posts

    181 Responses to “usa.kaspersky.com hacked … full database acces , sql injection”

    1. Iulyan Says:

      probabil ar merge sa pui si niste coduri de activare :D
      interesant bug gasit :)

    2. 2fingers Says:

      Nu promovam warez.

    3. Andrei Says:

      Daca ei au probleme de acest gen… ce pretentii sa mai avem de la site-urile romanesti ?

      Listau si cardurile pe acolo (in plain-text cumva), nu de alta da’ sa stiu la ce sa ma astept…

    4. Pyrro`s Blog » Cei de la HackersBlog o comit din nou Says:

      [...] de la Hackersblog o comit din nou. Dar tinta de data e situl http://usa.kaspersky.com/ si dupa cum spun ei “si [...]

    5. bl Says:

      urat … asta in cazul in care asta vara umblau cu user-ul mysql fara parola (serverul .fr) :) era innodb cu 5G extension fuck ! n`am avut rabdare sa o salvez, i-am anuntat si au inceput cu articole de lege si amenintari.Eu le-am transmis ca trimit toate serialele (158 de mii) moca la site`urile warez si deja imi facea oferta de munca. asta sa stiti la ce sa va asteptati :D
      activation_provision
      bugs_db
      faq_test
      internal
      kaspersky
      mysql
      retail_portal
      test

      cred ca a-ti omis si bazele de date la care exista accessssssssssss

      P.S. stiati ca : cei care folosesc kasp au ip-urile, detaliile pc-ului salvate + un fel de logger care inregistreaza cuvinte cheie ?

    6. Octav Says:

      mda… lasati ca nu e singurul site mare cu probleme. de ex: support.fujitsu-siemens.com are probleme de xss. Mai multe detalii la http://www.octav.name/2009/02/xss-in-siteul-fujitsu-siemens.html

    7. Tommy Says:

      nasol…pacat…chiar nu ma asteptam la asa ceva

    8. unu Says:

      bl..ai perfecta dreptate cu bazele de date http://img201.imageshack.us/img201/8343/schemact6.jpg
      si nu ne-ai zis finalul..te-ai angajat la ei, pana la urma?

    9. Raizen Says:

      Good job. :) ) omfg, you rock =]

    10. bl Says:

      mai am si eu cunostinte sa ma angajez la ei … ?! o gainarie nu inseamna neaparat cunostinte avansate in domeniu

    11. bl Says:

      Octav: fujitsu-siemens … de ce nu te iei de altceva mult mai periculos, care intredevar ar putea provoca pagube … ? iti dau eu un pont ? 70% din asociatiile de credit americane sunt vulnerabile XSS, ~20% blind injection, ~5% full injection (returneaza la o interogare toate campurile).
      o cautare in google, primu gasit primu servit! urmeaza avertizarea si lipsa replay-ului :) )

    12. 2fingers Says:

      “mai am si eu cunostinte sa ma angajez la ei … ?! o gainarie nu inseamna neaparat cunostinte avansate in domeniu”

      True. Tocmai de aia trebuie sa inteleaga lumea ca daca spargi un server/site mare nu inseamna ca sar toti sa te angajeze. Faza asta era la moda prin anii 90 dar s-au schimbat multe de atunci.

    13. Sicherheitsspezialist unsicher … Says:

      [...] Heise, Fefe und die Hauptquelle hackersblog.com berichten, ist die Webseite von Kaspersky mit einer eigenen massiven Sicherheitslücke betroffen, [...]

    14. Claudel Says:

      2fingers, nu uita sa-ti faci about/faq/terms in engleza, daca citesti articolul de pe theregister esti citat drept “the hacker” asa ca ai grija sa nu calci in alte strachini :)

    15. Shocker Says:

      Tocmai la asta m-am gandit adineauri, o sa modificam pagina About

    16. Kapersky ¿hacked? | CyberHades Says:

      [...] aparece en hackersblog.org alguien que se hace llamar Unu, dice haber accedido a la base de datos de unas de las compañías [...]

    17. Kaspersky-Website angeblich undicht - www.computerschutz.net - Strategie statt Lethargie Says:

      [...] der Website hackersblog.org berichtet ein Teilnehmer mit dem K

    18. Rook Says:

      This is trully open up my mind to what’s going on in Ebay

    19. usa.kaspersky.com hacked - Untangle Forums Says:

      [...] has not heard yet so they can look into see if UT users/customers have anything to worry about. HackersBlog

    20. usa.kaspersky.com被黑 SQL注入数据库全部暴露 - 【多图】 Says:

      [...] 今天usa.kaspersky.com被黑了。黑客还写了个blog:usa.kaspersky.com hacked … full database acces , sql injection [...]

    21. wtf Says:

      bl
      Poti sa-mi spui mai exact ce ai vrut sa spui legat de IP.ce anume din calc meu au la ei pe site?

    22. Internets Says:

      Why the hell do Romanians always used mixed case letters? It’s annoying. If they’re going to attempt to use English, they might as well do it right.

      It’s ON, ALL and SELECT, not On, aLL and SelECT.

      Idiots.

    23. Kaspersky-Website angeblich undicht « Computerhilfe u. Info Blog Says:

      [...] Veröffentlicht in Februar 8, 2009 von Klaus Alrutz Auf der Website hackersblog.org berichtet ein Teilnehmer mit dem Kürzel “unu” von seinen Erkenntnissen, wie man durch einfache [...]

    24. Shocker Says:

      @Internets, stop being such a smartass. Some websites have case-sensitive input filtering, thus blocking URLs that contain possible malicious keywords like UNION, SELECT.

    25. Kaspersky-Seite eventuell mit Sicherheitsleck « Netzwelten Says:

      [...] Kaspersky gehackt. So berichten Heise, Mitternachtshacking.de und Fefes Blog über die Berichte von Hackersblog.org, in deren Beitrag das ganze mit Screenshots untermauert [...]

    26. Security Cadets » BREAKING: Kaspersky Site Breach Exposes Data Says:

      [...] You can read the full run down from the hacker at HackersBlog.Org. [...]

    27. [WTF] usa.kaspersky.com Hacked! - SQL Injection Says:

      [...] got this information from here that show us usa.kaspersky.com hacked.. here some [...]

    28. HackersBlog » Blog Archive » usa.kaspersky.com hacked - Zoidbot Says:

      [...] HackersBlog » Blog Archive » usa.kaspersky.com hacked ¦ full database acces , sql injection. Share and [...]

    29. Keith Says:

      Bound to happen as the product gets more notice

    30. Kaspersky may have been hacked with SQL Injection « TTC Shelbyville - Technical Blog Says:

      [...] HackersBlog [...]

    31. Klantendatabase Kaspersky door hacker gestolen « DeVosDesign Blog Says:

      [...] informatie of activatie codes publiceren.” Wel heeft hij de lijst met database tabellen online gezet en dat is een behoorlijke lijst. Unu, zoals de hacker zich noemt, is niet over de beveiliging van [...]

    32. Jest Staffel Says:

      now i know it wasn`t my wife who cleaned out my cc -… alone..she had help:-

    33. Kaspersky Lab hacked: another sign of the losing war against hackers? » VentureBeat Says:

      [...] Oh great. This is all we need. Kaspersky Lab, a big antivirus software company, has been hacked, according to the Register. That seems to be the conclusion based on evidence posted on a blog yesterday. [...]

    34. Kaspersky Lab hacked: another sign of the losing war against hackers? | All about MICROSOFT Says:

      [...] by admin on Feb.09, 2009, under Microsoft Oh great. This is all we need. Kaspersky Lab, a big antivirus software company, has been hacked, according to the Register. That seems to be the conclusion based on evidence posted on a blog yesterday. [...]

    35. Kaspersky hacked…=O | I suck at spellings | Politically Motivated (dotnet) Says:

      [...] You can read the full story at The Register. If you are interested, you can view the original post by the hacker at HackersBlog. [...]

    36. REPORT: Kaspersky’s Web Site Open To SQL Injection Attacks « Data Security Podcast Says:

      [...] You can read more about this attack at The Hacker’s Blog. [...]

    37. Kaspersky Lab hacked: another sign of the losing war against hackers? | HoverOver.Us | Blogs, News & Latest Web 3.0 Trends Says:

      [...] Oh great. This is all we need. Kaspersky Lab, a big antivirus software company, has been hacked, according to the Register. That seems to be the conclusion based on evidence posted on a blog yesterday. [...]

    38. Kaspersky Lab hacked: another sign of the losing war against hackers? | WinSoftNews - Daily IT & Software News Says:

      [...] a posting made Saturday, the hacker claimed a simple SQL injection gave access to a database containing [...]

    39. SecuriTeam Blogs » Kaspersky Injected Says:

      [...] Grab more details about the incident here. [...]

    40. IT-понедельник : Посольство Саисё Кебати Says:

      [...] вроде подломали пост [...]

    41. Il sito di Kaspersky è stato violato » Italia SW Says:

      [...] cosa ha scritto il presento hacker su http://hackersblog.org Kaspersky is one of the leading companies in the security and antivirus market. It seems as though [...]

    42. t-bag Says:

      oh yeah
      amazing

    43. Auch das noch: Anti-Viren Hersteller Kaspersky gehackt | freshzweinull +++ Says:

      [...] Kundendatenbank von Kaspersky ein und veröffentlichte Tabellenzeilen daraus in einem glaubwürdig erscheinenden Protokoll. Glück im Unglück: Es war offenbar ein “freundlicher” Hacker, der nur auf eine [...]

    44. Tim Anderson’s ITWriting - Tech writing blog » Kaspersky site hacked through SQL injection Says:

      [...] apparently one of them (at least until yesterday) was kaspersky.com. A hacker codenamed unu posted details – not all the details, but enough to show that the vulnerability was real. The hack exposed [...]

    45. Wicked Says:

      You funny people, which fucking language are you writing?

    46. 2fingers Says:

      @Wicked – romanian

    47. » Hackato il sito web usa.kaspersky.com Says:

      [...] post su HackersBlog ha riportato le prove di un attacco ai danni del sito web usa.kaspersky.com andato a “buon [...]

    48. TTDDOO Says:

      bravo baieti… si cate traceback-uri =)) nice.

    49. usa.kaspersky.com Pwned | www.pwnage.ro Says:

      [...] http://hackersblog.org/2009/02/07/usakasperskycom-hacked-full-database-acces-sql-injection/ [...]

    50. Romanian Hackers Expose Kaspersky USA Site Open to SQL Injection | productsreviewed.net Says:

      [...] ”Kaspersky is one of the heading companies in the confidence and antivirus market. It seems as yet they have been not means to secure their own interpretation bases. Seems implausible but unfortunately, it’s true. Alter one of the parameters and you have entrance to everything,” says Unu. [...]

    51. blog test via un flux rss google reader » Archives du Blog » Kaspersky Lab piraté ?! Says:

      [...] en tout cas ce que laisse penser l’article publié par des membres de HackersBlog qui affirment être parvenus à accéder à une base de donnée contenant un grand nombre [...]

    52. Kaspersky breach exposes sensitive database, says hacker | Kay Enn's Cafe ! Says:

      [...] a posting made Saturday, the hacker claimed a simple SQL injection gave access to a database containing [...]

    53. computer__crazy Says:

      I wish to get 5 years kaspersky lincense from him. please donate me….
      :D :D

    54. KasperSky atacada por Hackers |  MercadoTiBrasil Says:

      [...] Será o fim dos tempos, a empresa de segurança da informação que “fabrica” o famoso antivírus de mesmo foi atacada por hackers segundo evidência no blog HackerBlog: http://hackersblog.org/2009/02/07/usakasperskycom-hacked-full-database-acces-sql-injection/ [...]

    55. Les sites de Kaspersky et Bitdefender hackés ! | Presse-Citron Says:

      [...] ce que l’on pourrait penser à la lecture – inquiétante – de cette histoire, publiée par un hacker roumain sur HackersBlog : le pirate (ou appelez ça comme vous voulez) [...]

    56. Claudel Says:

      hahahaha 2fingers ce ti-am zis eu de about ala… uite ce zic francezii aia :) ))

      par un hacker roumain sur HackersBlog : le pirate

    57. نوشته های رضا در دنیای زیبای وب » Blog Archive » حکایت Kaspersky در عرصه ی امنیت Says:

      [...] منبع خبر: hackersblog [...]

    58. La base de datos de kaspersky al descubierto por un agujero en su web » SoftwareZone : Blog sobre Software con tutoriales de ayuda y noticias Says:

      [...] hacker contó su hito en este post y para logar poner al descubierto la base de datos de los servidores de kaspersky usó una técnica [...]

    59. Shocker Says:

      Claudel, stii cum e cu presa si “infrumusetatul” situatiei :)
      A modificat 2fingers disclaimer-ul

    60. Trau, schau, wem - DXBLOG Says:

      [...] Da verkaufe ich meinen Kunden eine der verbreitetsten Internet Secutity Software, und dann das! [...]

    61. Rob Says:

      I have tried installed Kaps into my laptop but display saying remove old kaps 8. I did tried remove but itself cannoy emove so stuck there. Could you help me to do it.
      Thanks

    62. Shocker Says:

      Rob, try their official support center: http://www.kaspersky.com/support/

    63. Claudel Says:

      LOOOL! tocsixu sa cereti banii pe support ;) ) ca vin astia si va cer ajutor ptr antiv :) )) lmao

    64. سایت کاسپرسکی هک شد !!!!!!!!!!!!!!!!!!!! - صفحه 2 - Sat98 Professional Forums Says:

      [...] was hacked at the weekend, exposing a database containing customer details A hacker claimed in a blog posting that he was able to access Kasperky’s databases containing a customer details including users, [...]

    65. Security Vendor susceptible to SQL Injection | N-Stalker Web Security Community Says:

      [...] to Hacker’s Blog article on 07-Feb-2009, Russian’s desktop security vendor “Kaspersky” was target of a [...]

    66. Kaspersky.com database hacked! Says:

      [...] you have access to EVERYTHING: users, activation codes, lists of bugs, admins, shop, etc. Source: HackersBlog Blog Archive usa.kaspersky.com hacked … full database acces , sql injection __________________ -Jason / WTF Admin Little girl, this seems to say, Never stop upon the [...]

    67. Major Anti-Virus Sites Pull-Down | The Blog Pirate Says:

      [...] an attack on the site“. Howell The Kaspersky hacker, who published their finding on the Hackersblog.org website, has since said that confidential data would not be released. “[The] Kaspersky team [...]

    68. Kaspersky breach exposes sensitive database, says hacker • The Register « InfoSec Musings Says:

      [...] original post appeared on Hackersblog with follow on discussion [...]

    69. JWD Says:

      I there an email address for you guys so I can give you some contact info?
      Thanks

    70. 2fingers Says:

      hackersblog.org at gmail.com

    71. P2P ZONE Says:

      [...] Kaspersky noto e famosissimo per la sua qualità come antivirus è stato violato da un attacco in SQL Injection . Hackersblog ha fornito in dettaglio tutta la procedura dell’attacco con tanto di screenshot di chi di mestiere dovrebbe sapersi difendere dagli “attacchi”. Ecco le dichiarazioni: “Sabato 7 febbraio, una vulnerabilità è stata rilevata in una sottosezione del nostro dominio usa.kaspersky.com, dove un hacker ha portato un attacco sul sito. Il sito è stato vulnerabile solamente per un breve periodo e a subito dopo la rilevazione del bug abbiamo preso le misure necessarie per sostituire la sottosezione del sito e la vulnerabilità è stata eliminata entro 30 minuti. La vulnerabilità non era critica e nessun dato è stato compromesso”. Ecco il sito documentato sull’attacco: KasperskyHacked [...]

    72. La web de Kasperksy USA hackeada - Foro de Informatica - Foro de Windows 7, Windows Vista y Noticias de informatica Says:

      [...] web de Kasperksy USA hackeada Aqui teneis el enlace de la noticia: HackersBlog

    73. Dev Blog AF83 » Blog Archive » Veille technologique : Internet, Liberté, Vie privée, Agilité, Javascript, Git, Outils, Sécurité, User experience Says:

      [...] http://hackersblog.org/2009/02/07/usakasperskycom-hacked-full-database-acces-sql-injection/ : encore site connu piraté à cause d’une injection SQL [...]

    74. LIQ Says:

      Haha, nice one guys :) ) tot romanii ma, tot noi :) )

    75. Japonezu.com - Kaspersky hacuit?!?! Says:

      [...] fi fost rusii??? , conform hachersblog.org site-ul din state a celor de la Kaspersky Labs a fost spart de un hacker care sustine ca a accesat [...]

    76. Plausible Deniability » Kaspersky hack highlights reputation risk Says:

      [...] line is that its defenses were strong enough to repel all but the most sophisticated hackers. The hacker’s line, no surprise, is that he’s grey hat, not black hat, and had no interest in probing around and [...]

    77. Minä Says:

      ostaakaa prk parempia FIIIIIrus systeemejä,äläkää tänne tulko itkeen jos on koneen tiedot maailmalla,tai ÄLKÄÄ OSTAKO TÄTÄ

    78. » Feedmastering #62 Says:

      [...] Wow! Qualcuno ha bucato la sicurezza del sito di Kaspersky Usa, il famoso antivirus. Il tutto a fin di [...]

    79. Blog Porta 80 - Liberdade para Todos! Says:

      [...] informações foram postadas no blog “Hackers Blog” que não apresentou maiores [...]

    80. Antivirus firm confirms hackers breached site | Ramblings Says:

      [...] hackers, who are presumed to be Romanian, went public early Saturday in a blog post where they claimed that after launching a SQL injection attack on Kaspersky’s [...]

    81. Kaspersky-Website nicht ausreichend vor SQL Injection geschützt - elexpress.de Says:

      [...] auf der Webseite hackersblog.org zu lesen ist konnte man mittels SQL Injection Daten abrufen, die normalerweise nicht für die [...]

    82. Como Tu Quieras Production C.A. » La base de datos de kaspersky al descubierto por un agujero en su web Says:

      [...] hacker contó su hito en este post y para lograr poner al descubierto la base de datos de los servidores de kaspersky usó una [...]

    83. Security Company Infiltrated | Bill Hely's "Computer & Online Security" Says:

      [...] The post by the hacker who cracked the Kaspersky website can be found here: Kaspersky Website Hacked [...]

    84. Website của Kaspersky bị hack? - AMTECH Says:

      [...] cắp thông tin khách hàng. Theo tuyên bố của nhóm hacker được đăng trên trang HackersBlog, chúng đã đột nhập được vào cơ sở dữ liệu của trang web thuộc chi nhánh [...]

    85. Claudel Says:

      The hackers, who are presumed to be Romanian, went public early Saturday in a blog post where they claimed that after launching a SQL injection attack on Kaspersky’s U.S. support site, they were
      able to access a customer database that included e-mail addresses and software activation codes

      LOL!

    86. vv Says:

      Ia uite ce parere are Kaspersky despre voi :D :D
      “A more advanced hacker could have potentially accessed about 2,500 e-mail addresses of customers and about 25,000 product activation codes that were on the compromised server, but that did not happen, Schouwenberg said.”
      http://news.cnet.com/8301-1009_3-10159640-83.html?part=rss&subj=news&tag=2547-1_3-0-20

    87. 2fingers Says:

      E momentul sa inceapa sa isi refaca si ei imaginea. E de inteles.

    88. [CWS]Kaspersky confirms breach - Overclock.net - Overclocking.net Says:

      [...] and no data was revealed," he said. The hackers, who are presumed to be Romanian, went public early Saturday in a blog post. There, they claimed that after launching a SQL injection attack on Kaspersky’s U.S. [...]

    89. TiC Says:

      Bravo! Inca un articol despre voi:
      http://www.tomsguide.com/us/Kaspersky-Hacker-Internet-Security,news-3456.html

      “The attack was unsuccessful and, despite their attempts, the hackers were unable to gain access to restricted information stored on the website,” said the company in a press release. :) :) :)

    90. TTDDOO Says:

      ce distrusi… “The attack was unsuccessful and, despite their attempts, the hackers were unable to gain access to restricted information stored on the website” … vai de pula lor, noroc ca ati gasit voi treaba asta si nu altul care ar fi facut pagube. Full disclosure FTW si multumim ca aveti grija de imformatiile noastre confidentiale prin a expune niste GAURI in site-urile in care ar trebui ‘cica’ sa avem incredere.

    91. Andi Says:

      Does anyone know how to register on this site?

    92. Al4mbic Says:

      Just incredible !!! It’s funny to see that one of the leading companies in the security and antivirus market is not able to secure their own data bases. SQL Injections is still alive !

    93. PhpBB Died at » piticu .ro Says:

      [...] alte stiri hackersblog au devenit faimosi dupa ce au descoperit o vulnerabilitate in kaspersky.com pe care au exploatat-o. [...]

    94. Un român a spart site-ul Kaspersky « bataiosu.ro Says:

      [...] un e-mail către Kaspersky. Ne-au oferit exact o oră să răspundem, după care au postat totul pe blogul lor  fără să aştepte un răspuns din partea noastră. Suntem norocoşi că atacatorii şi-au [...]

    95. Al4mbic Says:

      Just Incredible ! It’s funny to see that one of the leading companies in the security and antivirus market is not secured. SQL Injections is still alive !

    96. Sitio de Kaspersky hackeado, base de datos de expuesta por 11 días - Cybernauta Says:

      [...] Una entrada en el sitio Hackersblog.org incluye capturas del hacker inyectando código SQL para acceder a la base de datos de la compañía a través del sitio de soporte técnico de la división norteamericana, presuntamente creado por terceros y nunca evaluado apropiadamente en términos de seguridad. De acuerdo a los datos de Kaspersky, el sitio se puso en-línea el pasado día 28 de enero, haciéndose público apenas un día después de eso. [...]

    97. Lyon Says:

      It only proves that no company no technology is secure, next time could be symantec or microsoft or even mcafee, who know right!?

    98. 2fingers Says:

      We need to make a difference between websites and av products. Yes the website was hacked but still kaspersky av is one of the best security products, right next to symantec, eset, mcafee, bitdefender & others.

      This is just my opinion of course.

    99. Un hacker roman a spart site-ul producatorului de programe antivirus Kaspersky si pagina unui partener BitDefender din Portugalia  | CTNEWS Says:

      [...] angajat roman al Kaspersky a dat alarma dupa ce a vazut o informatie publicata pe site-ul romanesc Hackers Blog, Angajatul a alertat Kaspersky USA si intr-o jumatate de ora sectiunea cu probleme a fost inlocuita [...]

    100. Adrian Says:

      daca McAfee va avea situl vulnerabil e nasol pentru ei, avand in vedere ca un produs pentru testarea problemelor de genu

    101. Kaspersky official website gets Hacked Says:

      [...] hacker, who officially publicized the hack on Hackersblog, informs that he only planned to hack the website after he got no response from the Kaspersky Labs [...]

    102. Blindagem Digital» Arquivo do Blog » Site de fabricante de antivírus é invadido nos EUA Says:

      [...] site Hackers Blog notificou que o site da empresa de antivírus Kaspersky foi invadido nos EUA. Os Hackers [...]

    103. victorblog Says:

      Ai de capu’ meu şi eu care credeam că e cel mai bun antivirus, implicit că se pricep la securitate.
      Oricum, când am văzut că scrie în limba română, parcă eram mândru că ne pricepem şi noi la ceva.
      Ar trebui să vă răsplătească într-un fel că le-aţi arătat cât de prost stau cu securitatea.

    104. Giany Says:

      This is embarrassing..such a big site..and still such a easy attack.I bet that more than 80% of website are vulnerable to some kind of attack..It only requires a lot of patiance..

    105. Gaura lui Kaspersky a fost sparta de un hacker roman Says:

      [...] Site-ul care dezbate problema si explica ce si cum. Nu va speriati, puteti vizita fara probleme. E un site un site onorabil care se ocupa cu probleme de securitate informatica. Ii salutam cordial cu ocazia asta (ne guduram si noi putin acum, ca doar nu vrem sa ne imprietenim cu Kaspersky gauritul). [...]

    106. un fan Says:

      Deja au inceput si parodiile pe teme asta

      http://www.martianul.ro/gaura-lui-kaspersky-a-fost-sparta-de-un-hacker-roman-10-02-2009/

    107. Anti-Virus Software Site Gets Hacked | The Keutech Says:

      [...] The hacker himself told that a small modification could have gained him access to activation codes, users, admins, lists of bugs, shop etc. He also said that he informed kaspersky about the vulnerability, and leaked it to public right after 1 hour. [...]

    108. chessh Says:

      Felicitarile mele echipei de aici! Sa mai auzim astfel de lucruri, chiar si mai mari!

    109. Kaspersky Hack'lendi | blogdar.org - bugünlük değil her günlük Says:

      [...] Şuradaki linkte ise olayın teknik boyutu ele alınmış. Veri tabanına full erişimin sağlandığından ve veri tabanındaki tablo yapısından açıkça söz ediliyor. Büyük ihtimalle bütün veriler ele geçirildi. Kaspersky bi’ şekilde bunu yapanı çok ağır bir şekilde cezalandıracak gibi duruyor. [...]

    110. Le site de Kaspersky hacké | The Tech Guy Says:

      [...] The Hacker’s Blog nous montre comment ils ont réussi, avec une faille plus que basique d’injection SQL, a pirater leur site et acceder à toutes les informations les plus critiques de leur base. [...]

    111. XO Says:

      well i think you won a job in kaspersky labs dude

    112. HeroTurko.Net » Blog Archive » Kaspersky official website gets Hacked Says:

      [...] hacker, who officially publicized the hack on Hackersblog, informs that he only planned to hack the website after he got no response from the Kaspersky Labs [...]

    113. Halil ÖZTÜRKCİ Güvenlik Günlüğü » Blog Archive » Asıl Korkulan Olursa! Says:

      [...] hacklendiği ve bütün müşteri bilgilerinin dışarı sızdığı iddia edildi. İlgili yazıya buradan ulaşabilirsiniz. Her ne kadar Kaspersky bu olayı yalanlasa da görünen o ki bir SQL injection [...]

    114. Kaspersky official website gets Hacked | YoungEngineers.co.in::For The Students By The Students Says:

      [...] hacker, who officially publicized the hack on Hackersblog, informs that he only planned to hack the website after he got no response from the Kaspersky Labs [...]

    115. Kaspersky vittima di un hacker - m-bay.org il Punto di Ritrovo Per tutti Gli appassionati dell’informatica Says:

      [...] portare a segno: “Basta alterare uno dei parametri” da passare all’URL composito, scrive unu su HackersBlog, “per avere accesso a TUTTO: utenti, attivazioni, codici, lista dei bug, [...]

    116. IT News » Blog Archive » Kaspersky’s website hacked Says:

      [...] hacker claimed in a blog posting that he was able to access Kasperky’s databases containing a customer details including [...]

    117. Genx Says:

      Congrats dude.

    118. Ali Kapucu Says:

      Vooooo :)

    119. De ce target firmelor de securitate? « Aspects of computer security Says:

      [...] Tags: Razboiul Ideilor trackback La cafea citeam astazi o stire in Hotnews despre o noua “reusita” a hackerilor romani. Victima Kaspersky LAB. Dupa mine devine plictisitor cum chiar firmele [...]

    120. Kaspersky’s support website hacked! | Hacked Info Says:

      [...] http://hackersblog.org/2009/02/07/usakasperskycom-hacked-full-database-acces-sql-injection/ [...]

    121. Kaspersky y BitDefender Hackeadas « Says:

      [...] que ha comprometido la seguridad del sitio web de karpersky de los EE.UU. En un post puesto en HackersBlog, unu ha publicado capturas de pantalla, así como una lista de las tablas de la base de datos [...]

    122. usa.kaspersky.com hacked … full database acces , sql injection | IT Blog on toata.info Says:

      [...] (Articolul in continuare) [...]

    123. Acunetix Web Application Security Blog » SQL injection sneaks into Kaspersky’s support website Says:

      [...] (the Antivirus vendor) support database left the company with a bit of explaining to do. The hacker published a blog post on hackersblog detailing stunts with Kaspersky’s USA support website. Kaspersky also [...]

    124. John Average » Blog Archive » Un hacker roman a spart site-ul Kaspersky! Says:

      [...] Cei de la Kaspersky au fost anuntati printr-un e-mail vinerea trecuta despre o vulnerabilitate a site-ului. O ora mai tarziu le-a fost spart site-ul. “unu” – asa isi spune hackerul, a reusit sa afle parola de la baza de date a site-ului si, a afisat structura tabelelor si cateva screen-sht-uri pe site-ul romanesc Hackers Blog. [...]

    125. xel Says:

      omg cate trackbackuri. sunteti vedete !! :D

      apropo, scriu si dajtebtii astia de la libertatea de voi http://libertatea.ro/stire/un-hacker-roman-a-spart-site-urile-kaspersky-si-bitdefender-229681.html

    126. Koliko smo sigurni na Internetu? / plagosus / blog Says:

      [...] ste pratili vesti na Internetu, verovatno ste već pročitali da je uhakovan američki sajt ruske anti-virus kompanije Kaspersky. Tom prilikom, neimenovani haker imao je pristup kompletnoj listi klijenta, sa svim njihovim [...]

    127. HackersBlog » Blog Archive » F-Secure.com - SQL + Cross Site Scripting vulnerabilities Says:

      [...] serverului portal.edu.ro prin LFI in Bugs (142 Visits)AsociatiaBrokerilor.ro in Bugs (43 Visits)usa.kaspersky.com hacked … full database acces , sql injection in Local File Inclusion (461 Visits)RedTube.com … The Free Sex Video Community in Local File [...]

    128. ClaudiuCC Says:

      foarte tare … bravo! mai paypal trebuie hackuit

    129. Kaspersky USA e BitDefender PT Hacked | TECNOSH Says:

      [...] Post Hack BitDefender PT Post Hack Kaspersky USA [...]

    130. hazed Says:

      Congratulations on the hack. There is nothing worse than false security, and these guys definitely gave that. Good work guys.

    131. dblackshell Says:

      mda, subiectul acesta imi tot apare prin reader… era momentul sa dau si eu un comment, ca de nu cred ca ma urmarea in continuare…

    132. PowerDream Says:

      most large systems is the cost of even minuscule holes so that the end of

    133. Kaspersky Bullsh!t PR | Grump’s Corner Says:

      [...] oameni hăcuiesc kaspersky.com la nivel demonstrativ, fără intenţii criminale. Ca să arate că există [...]

    134. Kaspersky Lab ofiarą SQL Injection. Wyciekły poufne dane Says:

      [...] taką opublikował 7 lutego 2009 roku jeden z redaktorów witryny hackersblog.org. W artykule stwierdzono, że w stronę tego [...]

    135. Παραβίαση βάσης δεδομένων της Kaspersky Says:

      [...] εδώ » και εδώ [...]

    136. Next please! | IT Blog on toata.info Says:

      [...] please! iodus 12 Feb, 2009 Securitate Dupa Kaspersky si BitDefender, a venit timpul si celor de la F-Secure.com… vulnerabil la SQL Injection si la [...]

    137. Chris Saddler Says:

      cat m-am bucurat cand am auzit stirea asta, sincer. in schimb m-am intristat ca in continuare, olandezii cel putin (locuiesc prin zona lor de ceva timp), nu au zis nimic in niciun ziar sau la vreun tv de asta ca deh, sunteti romani, de ce sa zica ca ati descoperit ceva bun… neah, tot pe tiganii care fura ii promoveaza in continuare. niste jegosi. stiu ca suntem mai buni decat multi altii pe IT.
      bravo inca o data!
      diseara ma duc sa mai bag un acces de 777 pe o olandeza, numai asa de ciuda.

    138. Paxs Says:

      Now, a lot of associates who always chidded me for NOT using Kaspersky products in my servers and other machines will shut up. I hope the rest of the so-called antivirus companies will immediately take appropriate measures so this kind of thing does not occur in their own backyards. Kaspersky’s reputation certainly got very compromised. Sorry.

    139. Kill Me Says:

      Internet related…

      1. hackersblog.org anunta ca e o vulnerabilitate in site-ul celor de la kaspersky in us. Se dau screenshot-uri, liste cu tabele si explicatii. Kaspersky USA recunoaste o parte a atacului pe 10 februarie, adica la 3 zile !!! de la postarea anuntului cu …

    140. PC Fires • Blog » Kaspersky official website gets Hacked Says:

      [...] hacker, who officially publicized the hack on Hackersblog, informs that he only planned to hack the website after he got no response from the Kaspersky Labs [...]

    141. Catalin Bocanu Says:

      The Kaspersky Lab official response: no data was stolen or compromized. Read the entire article http://www.downloadtube.com/blog/

    142. xetech Says:

      Huhu, I thought that Kaspersky the best antivirus solutions, but it hacked now, since Kaspersky Malaysia hacked before this…

      From,
      http://www.xetech.info

    143. Kaspersky contra-ataca Says:

      [...] ce un blog romanesc de securitate a descoperit o vulnerabilitate in site-ul usa.kaspersky.com s-a pornit un mare scandal. Imaginea [...]

    144. Update la Hackersblog | IT Blog on toata.info Says:

      [...] Am scris nu demult despre white – hacking-ul celor de la http://hackersblog.org asupra kaspersky (usa.kaspersky.com hacked … full database acces , sql injection ), am scris aici. Si apoi urmeaza replica celor de la [...]

    145. Zeus - knowledge database » Weekend wrap up Says:

      [...] 3. usa.kaspersky.com hacked … full database acces , sql injection [...]

    146. Kaspersky.com, BitDefender.com and F-secure hacked - klumea.net Says:

      [...] hacking Saturday, February 14, 2009, 20:09 Posted in hacking and has 0 Comments so far. After Kaspersky and BitDefender, it’s now time for F-Secure.com … vulnerable to SQL Injection plus Cross Site [...]

    147. » Kaspersky Labs chybu přiznává, data prý ale odcizena nebyla » Blog počítačového nadšence | Píše Jiří Macich ml. Says:

      [...] několika dny se jistý člověk vystupující pod přezdívkou Unu na blogu Hackersblog.org pochlubil tím, že se mu díky SQL Injection údajně podařilo hacknout webové stránky ruské [...]

    148. » Kaspersky Hack edildi » Haber 7 x 24 Son Dakika Hızlı Haber Turu Says:

      [...] firması Kaspersky Lab müşteri veritabanının hack edildiğini 11 gün sonra hacker’s blog sitesindeki yazılardan [...]

    149. Syber News » Security Firm Kaspersky Labs: No Customer Data Leaked in Site Hack Says:

      [...] injection and cross-site scripting to gain access to a database on the Kaspersky support site, he advertised his accomplishment, and that’s when the company learned of the attack.The company, which many (arguably) say produces [...]

    150. Kaspersky was Hacked using SQL Injection attack Says:

      [...] (read more) [...]

    151. Hacker claims SQL bug on Symantec site; vendor disputes « BREAKING IT NEWS FOR BUSINESS Says:

      [...] over a week ago, Unu found a similar problem in Kaspersky Lab’s site, as well as in a partner site for security vendor BitDefender and in the F-Secure Web [...]

    152. Hacker Claims SQL Bug on Symantec Site | TechnoBlog Says:

      [...] over a week ago, Unu found a similar problem in Kaspersky Lab’s site, as well as in a partner site for security vendor BitDefender, and in the F-Secure Web [...]

    153. Atualize-se | Não fique parado » Blog Archive » Site da Kaspersky Invadido Says:

      [...] De fato que a invasão houve e o próprio hacker publicou no Hackersblog ? * Clique aqui e veja o link da invasão [...]

    154. Была найдена дыра в сайте Касперского | Dr.TRO Blog :) Says:

      [...] : http://hackersblog.org/2009/02/07/usakasperskycom-hacked-full-database-acces-sql-injection/ [...]

    155. Official Kaspersky Website Hacked! | Talk to Gadgets.CoM Says:

      [...] The hacker, Officially favored them by reporting them about the vulnerability through email.Check Hackersblog, For more [...]

    156. Should I Trust You? Says:

      [...] “hacking series” against major antivirus companies. After the recent SQL injections in Kaspersky, BitDefender (here and here) and F-Secure the regular user might wonder in which company should [...]

    157. Хакеры взломали американский сайт “Лаборатории Касперского” | inf4u.org.ua Says:

      [...] американском сайте “Лаборатории Касперского” и опубликовали список таблиц баз данных ресурса, якобы содержащих [...]

    158. Kaspersky Lab: Hacked | Blippitt Says:

      [...] Kaspersky Lab, a huge antivirus software company (of all things), has been hacked according to the Register.  That seems to be the conclusion based on evidence posted on a blog yesterday. [...]

    159. HyG Says:

      if u hack http://www.rising.com.cn
      U r so stronger

    160. Wow - WHT Hacked! - HostV Community - VPS Hosting Forums Says:

      [...] BTW….Kaspersky (USA) was also hit with a SQL injection back in February exposing everything. HackersBlog Blog Archive usa.kaspersky.com hacked … full database acces , sql injection __________________ For HELP, summon support with the Bat-Signal: http://support.hostv.com/ [...]

    161. SQL Tutorials Says:

      Does anyone know if there is another language or set of commands beside SQL for talking with databases?

      I’m working on a project and am doing some research thanks

    162. tex Says:

      HyG:

      Get lost with your IIS/6.0

      :D

    163. Hirosima Says:

      din cate am observat au reusit sa repare vulnerabilitatea, e adevarat?

    164. Kaspersky’s support website hacked! | Says:

      [...] http://hackersblog.org/2009/02/07/usakasperskycom-hacked-full-database-acces-sql-injection/ Share and Enjoy: [...]

    165. Asıl Korkulan Olursa! | Açıkkod.org Says:

      [...] hacklendiği ve bütün müşteri bilgilerinin dışarı sızdığı iddia edildi. İlgili yazıya buradan ulaşabilirsiniz. Her ne kadar Kaspersky bu olayı yalanlasa da görünen o ki bir SQL injection [...]

    166. Zone-H got owned | Static in the Ether Says:

      [...] Details on this as yet. Hackers blog has more on the Kaspersky hack which seems to be good old SQL [...]

    167. FanX Says:

      :D fain …brava

    168. Gorev Says:

      Good job

    169. dully Says:

      good … very good

    170. Pulpish Says:

      Wow this gave me a good laugh lol

    171. HackersBlog » Blog Archive » Another security problem in usa.kaspersky.com? Says:

      [...] Those two(?) vulnerabilities  are NOT confirmed. Read more about usa.kaspersky.com vulnerabilities here. [...]

    172. Symantec hacked, full disk and databse access? » CounterMeasures Says:

      [...] in February of this year, the Romanian hacker Unu found a SQL injection vulnerability in a Kaspersky tech support portal server based in the USA. That vulnerability when exploited allowed full access [...]

    173. Niebezpiecznik.pl » Rumun włamał się na do Symanteca Says:

      [...] Szczegółowy opis ataku znajduje się na blogu Unu: http://unu123456.baywords.com/2009/11/23/symantec-exposed-passwordsserials-sql-injection-full-database-access/ Dla przypomnienia, opis ataku na stronę Kaspersky’ego: http://www.hackersblog.org/2009/02/07/usakasperskycom-hacked-full-database-acces-sql-injection/ [...]

    174. Setelah Kaspersky, Giliran Symantec Kena Hack « Teknologi [tidak] harus canggih Says:

      [...] sulit dibobol dengan cara mengumumkan nama tabel yang mestinya tidak diketahui umum. Menariknya, Kapersky dengan jantan telah membenarkan bahwa situsnya memang kebobolan data [...]

    175. Често задавани въпроси » Blog Archive » Сайт на Symantec хакнат Says:

      [...] информация, с която разполага. Същият хакер беше счупил сайта на Kaspersky в началото на [...]

    176. Symantec Hacked? Full Disk And Database Access? | Business Computing World Says:

      [...] 2009 | by Rik Ferguson | 1 views Back in February of this year, the Romanian hacker Unu found a SQL injection vulnerability in a Kaspersky tech support portal server based in the U.S. That vulnerability when exploited [...]

    177. Kaspersky gets hacked Ouch, there’s nev… « WASRC Says:

      [...] http://www.security-watchdog.co.uk/2009/02/kaspersky-gets.html http://hackersblog.org/2009/02/07/usakasperskycom-hacked-full-database-acces-sql-injection/ [...]

    178. raynor009 Says:

      Kaspersky este unul din cel mai de rahat antivirus pe care lai putea avea eu prefer sami fac proprii antivirusi si firewalluri dar eu va recomand AVG si va garantez ca nu va va lasa la greu.

    179. HackersBlog » Blog Archive » Kaspersky.com.pt hacked Says:

      [...] the big scandal regarding usa.kaspersky.com data breach posted for the first time here on hackersblog by our former member “unu”, [...]

    180. Ansamblu Says:

      Ce vremuri… hehe

    181. Baza de date Kaspersky a fost sparta Says:

      [...] postarii unui blogger printr-un atac simplu de tip “SQL injection” asupra site-ului Kaspersky USA a putut avea [...]

    Leave a Reply

    Studio videochat bucuresti Studio videochat Bucuresti
    Download Muzica Filme
    Studio videochat Iasi videochat Iasi