- Hacker Uses XSS and Google Street View Data to Determine Physical Location
- CAnCAn te iubim, CA CA tine nu gasim. Superfete.cancan.ro e de rahat
- Deface (?!?) pe Cotidianul.ro
- Virusi in clipuri video [how to]
- Cyber-Bullying – palma parinteasca a noului mileniu
- Christopher “moot” Poole: The case for anonymity online
- Wtf Avira?
- Some old story about tagged.com
- Pwning cam girls for fun
- Tabloshit
- Yahoo! again - XSS in Uncategorized (357 Visits)
- Yahoo! again - bad settings? in Uncategorized (252 Visits)
- Fanii nostri in Uncategorized (183 Visits)
- Frustrant in Uncategorized (146 Visits)
- La multi ani România, la multi ani românilor in Uncategorized (137 Visits)
- Weblog.ro - Shell via Local File Inclusion in Uncategorized (119 Visits)
- Yahoo! epic fail - permanent xss unleashed in Uncategorized (50 Visits)
- ... in Uncategorized (38 Visits)
- XSS Ownage - hi5 vs. Yahoo! + video in Uncategorized (2 Visits)
- Ce nu se invata la scoala - Tipuri si tehnici spam/Hi5 (4) in Uncategorized (2 Visits)
- Hackersblog.org is now blog.rstcenter.com in (1770 Visits)
- O mica dar importanta precizare in (1371 Visits)
- Twitter in (805 Visits)
- This is the end in (776 Visits)
- Ce servicii de mail folositi? in (773 Visits)
- Un nou membru in (730 Visits)
- La multi ani România, la multi ani românilor in (717 Visits)
- Inca o pierdere de timp in (674 Visits)
- De reţinut in (634 Visits)
- Azi este ziua userilor hackersblog.org in (610 Visits)
- SMS scam (1) in (564 Visits)
- Dezinformare sau proasta informare? in (563 Visits)
- Hi5.com coders read this in (553 Visits)
- Phishing Raiffeisen cu atasament html in (516 Visits)
- Phishing Bancpost in (486 Visits)
- Si tentativele de phishing pot fi amuzante in (422 Visits)
- Ce nu se invata la scoala - Tipuri si tehnici spam/mail (2) in (2707 Visits)
- Ce nu se invata la scoala - Tipuri si tehnici spam/Hi5 (4) in (2601 Visits)
- Despre CSRF, hi5.com, cum sa trisezi la concursuri s.a.m.d. in (1143 Visits)
- [Utilitare] Suna gratis de pe internet sau de pe iPhone in (1107 Visits)
- Ce nu se invata la scoala - (D)DOS (5) in (950 Visits)
- Virusi in clipuri video [how to] in (838 Visits)
- Ce nu se invata la scoala - Tipuri si tehnici spam (1) in (725 Visits)
- Yahoo! redirects - a big issue (with video) in (570 Visits)
- Internet vs. privacy (1) in (468 Visits)
- Ca musca in... in (435 Visits)
- RedTube.com ... The Free Sex Video Community in (12972 Visits)
- usa.kaspersky.com hacked ... full database acces , sql injection in (4919 Visits)
- libertatea.ro vulnerabil la (blind) sql injection in (2950 Visits)
- Pwning cam girls for fun in (2586 Visits)
- Telegraph.co.uk hacked, sql injection in (2546 Visits)
- Facebook hacked - sql injection in (2424 Visits)
- Simpatie.ro, matrimoniale3x.ro, apetisant.ro, deliciu.ro , etc Sql injection in (2406 Visits)
- F-Secure.com - SQL Injection + Cross Site Scripting in (1774 Visits)
- [Hacked]Bitdefender (Portugal) exposes sensitive customer data in (1743 Visits)
- Wtf Avira? in (1723 Visits)
- Christopher "moot" Poole: The case for anonymity online in (1495 Visits)
- Digital Photocopiers Loaded With Secrets in (1458 Visits)
- Wannabe Hackers [2] - cum sa faci un virus by sppy_hacker in (592 Visits)
- Wannabe Hackers [1] - Cum sa hack-uiesti RapidShare-ul in (590 Visits)
- Hope 2603 – Kevin Mitnick - Life a Computer Hacker – Revealed in (462 Visits)
- PRIVACY IS DEAD - GET OVER IT, Pt 01-34 (Recommended by Hackersblog ) in (396 Visits)
- Oldies but goodies - Freedom Downtime - The Story of Kevin Mitnick in (379 Visits)
- [Video] The History Of Hacking in (373 Visits)
- Email Security - Why You Should Encrypt Your Email - Part One in (368 Visits)
- The Story of DEFCON in (343 Visits)
- Deface - tuttoaffari.lastampa.it si citymusiclab.city.corriere.it in (3493 Visits)
- RNS vs. RAI - citizenreport.rai.it hacked. in (3300 Visits)
- Hi5 email finder si sfarsitul a tot ceea ce inseamna privacy in social networking in (2995 Visits)
- Se poate sparge parola de Yahoo? in (2572 Visits)
- Free SMS time, TrimiteSMS.ro in (2492 Visits)
- Planete-plus-intelligente.lemonde.fr defaced by R.N.S. in (2464 Visits)
- Gmail uber hacking in (2256 Visits)
- Camera de supraveghere a universitatii Alexandru Ioan Cuza din Iasi in (2255 Visits)
- Cancan.ro spart pentru a doua oara intr-o zi in (2251 Visits)
- Stiri cu antena3 in (2208 Visits)
Posted on February 7th, 2009
Kaspersky is one of the leading companies in the security and antivirus market. It seems as though they are not able to secure their own data bases.
Seems incredible but unfortunately, its true.
Alter one of the parameters and you have access to EVERYTHING: users, activation codes, lists of bugs, admins, shop, etc.
First, lets see the version, user and name of the database.
User host & password for mysql.user
This time I will not (for reasons that need no explanation) publish any screenshot with containing personal details or activation code.
I will only make public the names of the tables.
Though the list is long, the table are very interesting.
codes
users
vouchers
affectstable
bugs_settings
bugshistory
bugstable
builds
categories
commentstable
computertable
editions
filestable
frontpage
grouptable
ignoretable
milestones
paks
pmtable
priority
repfielddetail
repfields
repfieldset
repoptiondetail
repoptions
repquick
severity
statustable
substable
userstable
admin_users
best_buy
cms
cyberCrimeRegs
email_list
fr_link
fr_link_import
interview_request
k_test_users
kbfaq
kbfaq_import
kbrub
kbrub_bu
kbrub_import
login_stats
menu
menu_relations
menus
node
partners
partners_bu
portal_cms_prod_ann
portal_cms_recent_articles
portal_cms_whats_new
portal_product_orders
product_names
retail_login_stats
retail_partners
retail_users
se_login_stats
se_partners
se_users
setup
shopping_com_sales
smnr_items
smnr_items_bu
trials
trials_bu
trials_downloaded_new
trials_rpts
users
users_bu
it_hardware
activation_code_problem
admin_users
best_buy
cms
cyberCrimeRegs
e5users
email_list
fr_link
fr_link_bu
fr_link_import
interview_request
k_test_users
kbfaq
kbfaq_bu
kbfaq_import
kbrub
kbrub_bu
kbrub_import
kbtop_pop
login_stats
menu
menu_relations
menus
ms_crm_files
ms_crm_files_support
ms_crm_intermediary
ms_crm_intermediary_bu
ms_crm_intermediary_support
node
opt_out
partners
partners_bu
portal_cms_prod_ann
portal_cms_recent_articles
portal_cms_whats_new
product_names
retail_login_stats
retail_partners
retail_users
se_login_stats
se_partners
se_users
setup
shopping_com_sales
smnr_events
smnr_items
smnr_items_bu
test_users
test_users_new
trials
trials_bu
trials_downloaded
trials_downloaded_new
trials_rpts
users
users_bu
virus_watch
columns_priv
db
func
help_category
help_keyword
help_relation
help_topic
host
proc
procs_priv
tables_priv
time_zone
time_zone_leap_second
time_zone_name
time_zone_transition
time_zone_transition_type
user
codes
stores
stores_bu
users
And another picture with the colons name , and the name of userstable table.
Don’t forget to check our new article about same problem in bitdefender portugal.
—————————–
RO version:
Kaspersky ocupa un loc de frunte pe piata antivirusilor si a solutiilor de securitate pentru internet. Totusi nu este capabil sa-si securizeze propria baza de date. Incredibil,dar adevarat. Un parametru prost sanitizat si avem acces la tot: utilizatori, coduri de activare,lista de buguri, admini, shop, etc.
Prima data sa vedem versiunea, userul si numele bazei de date.
Acum user host si password pentru mysql.user
De data asta voi omite , din motive usor de inteles, publicare vreunei poze cu datele personale ale userilor sau afisarea vreunui cod de activare. In schimb imi permit sa fac public denumirile tabelelor. Desi e o lista lunga, sunt tabele foarte interesante
codes
users
vouchers
affectstable
bugs_settings
bugshistory
bugstable
builds
categories
commentstable
computertable
editions
filestable
frontpage
grouptable
ignoretable
milestones
paks
pmtable
priority
repfielddetail
repfields
repfieldset
repoptiondetail
repoptions
repquick
severity
statustable
substable
userstable
admin_users
best_buy
cms
cyberCrimeRegs
email_list
fr_link
fr_link_import
interview_request
k_test_users
kbfaq
kbfaq_import
kbrub
kbrub_bu
kbrub_import
login_stats
menu
menu_relations
menus
node
partners
partners_bu
portal_cms_prod_ann
portal_cms_recent_articles
portal_cms_whats_new
portal_product_orders
product_names
retail_login_stats
retail_partners
retail_users
se_login_stats
se_partners
se_users
setup
shopping_com_sales
smnr_items
smnr_items_bu
trials
trials_bu
trials_downloaded_new
trials_rpts
users
users_bu
it_hardware
activation_code_problem
admin_users
best_buy
cms
cyberCrimeRegs
e5users
email_list
fr_link
fr_link_bu
fr_link_import
interview_request
k_test_users
kbfaq
kbfaq_bu
kbfaq_import
kbrub
kbrub_bu
kbrub_import
kbtop_pop
login_stats
menu
menu_relations
menus
ms_crm_files
ms_crm_files_support
ms_crm_intermediary
ms_crm_intermediary_bu
ms_crm_intermediary_support
node
opt_out
partners
partners_bu
portal_cms_prod_ann
portal_cms_recent_articles
portal_cms_whats_new
product_names
retail_login_stats
retail_partners
retail_users
se_login_stats
se_partners
se_users
setup
shopping_com_sales
smnr_events
smnr_items
smnr_items_bu
test_users
test_users_new
trials
trials_bu
trials_downloaded
trials_downloaded_new
trials_rpts
users
users_bu
virus_watch
columns_priv
db
func
help_category
help_keyword
help_relation
help_topic
host
proc
procs_priv
tables_priv
time_zone
time_zone_leap_second
time_zone_name
time_zone_transition
time_zone_transition_type
user
codes
stores
stores_bu
users
Si inca o poza cu denumirile coloanelor , a tabelului userstable.




February 7th, 2009 at 2:45 pm
probabil ar merge sa pui si niste coduri de activare
interesant bug gasit
February 7th, 2009 at 3:01 pm
Nu promovam warez.
February 7th, 2009 at 3:16 pm
Daca ei au probleme de acest gen… ce pretentii sa mai avem de la site-urile romanesti ?
Listau si cardurile pe acolo (in plain-text cumva), nu de alta da’ sa stiu la ce sa ma astept…
February 7th, 2009 at 3:57 pm
[...] de la Hackersblog o comit din nou. Dar tinta de data e situl http://usa.kaspersky.com/ si dupa cum spun ei “si [...]
February 7th, 2009 at 4:15 pm
urat … asta in cazul in care asta vara umblau cu user-ul mysql fara parola (serverul .fr)
era innodb cu 5G extension fuck ! n`am avut rabdare sa o salvez, i-am anuntat si au inceput cu articole de lege si amenintari.Eu le-am transmis ca trimit toate serialele (158 de mii) moca la site`urile warez si deja imi facea oferta de munca. asta sa stiti la ce sa va asteptati 
activation_provision
bugs_db
faq_test
internal
kaspersky
mysql
retail_portal
test
cred ca a-ti omis si bazele de date la care exista accessssssssssss
P.S. stiati ca : cei care folosesc kasp au ip-urile, detaliile pc-ului salvate + un fel de logger care inregistreaza cuvinte cheie ?
February 7th, 2009 at 7:24 pm
mda… lasati ca nu e singurul site mare cu probleme. de ex: support.fujitsu-siemens.com are probleme de xss. Mai multe detalii la http://www.octav.name/2009/02/xss-in-siteul-fujitsu-siemens.html
February 7th, 2009 at 8:53 pm
nasol…pacat…chiar nu ma asteptam la asa ceva
February 7th, 2009 at 9:00 pm
bl..ai perfecta dreptate cu bazele de date http://img201.imageshack.us/img201/8343/schemact6.jpg
si nu ne-ai zis finalul..te-ai angajat la ei, pana la urma?
February 7th, 2009 at 10:35 pm
Good job.
) omfg, you rock =]
February 8th, 2009 at 9:21 am
mai am si eu cunostinte sa ma angajez la ei … ?! o gainarie nu inseamna neaparat cunostinte avansate in domeniu
February 8th, 2009 at 9:29 am
Octav: fujitsu-siemens … de ce nu te iei de altceva mult mai periculos, care intredevar ar putea provoca pagube … ? iti dau eu un pont ? 70% din asociatiile de credit americane sunt vulnerabile XSS, ~20% blind injection, ~5% full injection (returneaza la o interogare toate campurile).
)
o cautare in google, primu gasit primu servit! urmeaza avertizarea si lipsa replay-ului
February 8th, 2009 at 10:51 am
“mai am si eu cunostinte sa ma angajez la ei … ?! o gainarie nu inseamna neaparat cunostinte avansate in domeniu”
True. Tocmai de aia trebuie sa inteleaga lumea ca daca spargi un server/site mare nu inseamna ca sar toti sa te angajeze. Faza asta era la moda prin anii 90 dar s-au schimbat multe de atunci.
February 8th, 2009 at 2:36 pm
[...] Heise, Fefe und die Hauptquelle hackersblog.com berichten, ist die Webseite von Kaspersky mit einer eigenen massiven Sicherheitslücke betroffen, [...]
February 8th, 2009 at 2:47 pm
2fingers, nu uita sa-ti faci about/faq/terms in engleza, daca citesti articolul de pe theregister esti citat drept “the hacker” asa ca ai grija sa nu calci in alte strachini
February 8th, 2009 at 2:52 pm
Tocmai la asta m-am gandit adineauri, o sa modificam pagina About
February 8th, 2009 at 3:55 pm
[...] aparece en hackersblog.org alguien que se hace llamar Unu, dice haber accedido a la base de datos de unas de las compañías [...]
February 8th, 2009 at 4:48 pm
[...] der Website hackersblog.org berichtet ein Teilnehmer mit dem K
February 8th, 2009 at 5:03 pm
This is trully open up my mind to what’s going on in Ebay
February 8th, 2009 at 5:13 pm
[...] has not heard yet so they can look into see if UT users/customers have anything to worry about. HackersBlog
February 8th, 2009 at 5:41 pm
[...] 今天usa.kaspersky.com被黑了。黑客还写了个blog:usa.kaspersky.com hacked … full database acces , sql injection [...]
February 8th, 2009 at 5:46 pm
bl
Poti sa-mi spui mai exact ce ai vrut sa spui legat de IP.ce anume din calc meu au la ei pe site?
February 8th, 2009 at 6:04 pm
Why the hell do Romanians always used mixed case letters? It’s annoying. If they’re going to attempt to use English, they might as well do it right.
It’s ON, ALL and SELECT, not On, aLL and SelECT.
Idiots.
February 8th, 2009 at 6:14 pm
[...] Veröffentlicht in Februar 8, 2009 von Klaus Alrutz Auf der Website hackersblog.org berichtet ein Teilnehmer mit dem Kürzel “unu” von seinen Erkenntnissen, wie man durch einfache [...]
February 8th, 2009 at 6:16 pm
@Internets, stop being such a smartass. Some websites have case-sensitive input filtering, thus blocking URLs that contain possible malicious keywords like UNION, SELECT.
February 8th, 2009 at 6:40 pm
[...] Kaspersky gehackt. So berichten Heise, Mitternachtshacking.de und Fefes Blog über die Berichte von Hackersblog.org, in deren Beitrag das ganze mit Screenshots untermauert [...]
February 8th, 2009 at 6:47 pm
[...] You can read the full run down from the hacker at HackersBlog.Org. [...]
February 8th, 2009 at 7:43 pm
[...] got this information from here that show us usa.kaspersky.com hacked.. here some [...]
February 8th, 2009 at 7:58 pm
[...] HackersBlog » Blog Archive » usa.kaspersky.com hacked ¦ full database acces , sql injection. Share and [...]
February 8th, 2009 at 8:57 pm
Bound to happen as the product gets more notice
February 8th, 2009 at 9:41 pm
[...] HackersBlog [...]
February 8th, 2009 at 10:50 pm
[...] informatie of activatie codes publiceren.” Wel heeft hij de lijst met database tabellen online gezet en dat is een behoorlijke lijst. Unu, zoals de hacker zich noemt, is niet over de beveiliging van [...]
February 9th, 2009 at 12:57 am
now i know it wasn`t my wife who cleaned out my cc -… alone..she had help:-
February 9th, 2009 at 3:05 am
[...] Oh great. This is all we need. Kaspersky Lab, a big antivirus software company, has been hacked, according to the Register. That seems to be the conclusion based on evidence posted on a blog yesterday. [...]
February 9th, 2009 at 3:20 am
[...] by admin on Feb.09, 2009, under Microsoft Oh great. This is all we need. Kaspersky Lab, a big antivirus software company, has been hacked, according to the Register. That seems to be the conclusion based on evidence posted on a blog yesterday. [...]
February 9th, 2009 at 3:24 am
[...] You can read the full story at The Register. If you are interested, you can view the original post by the hacker at HackersBlog. [...]
February 9th, 2009 at 3:57 am
[...] You can read more about this attack at The Hacker’s Blog. [...]
February 9th, 2009 at 5:46 am
[...] Oh great. This is all we need. Kaspersky Lab, a big antivirus software company, has been hacked, according to the Register. That seems to be the conclusion based on evidence posted on a blog yesterday. [...]
February 9th, 2009 at 6:10 am
[...] a posting made Saturday, the hacker claimed a simple SQL injection gave access to a database containing [...]
February 9th, 2009 at 6:33 am
[...] Grab more details about the incident here. [...]
February 9th, 2009 at 7:58 am
[...] вроде подломали пост [...]
February 9th, 2009 at 8:22 am
[...] cosa ha scritto il presento hacker su http://hackersblog.org Kaspersky is one of the leading companies in the security and antivirus market. It seems as though [...]
February 9th, 2009 at 9:34 am
oh yeah
amazing
February 9th, 2009 at 10:35 am
[...] Kundendatenbank von Kaspersky ein und veröffentlichte Tabellenzeilen daraus in einem glaubwürdig erscheinenden Protokoll. Glück im Unglück: Es war offenbar ein “freundlicher” Hacker, der nur auf eine [...]
February 9th, 2009 at 10:42 am
[...] apparently one of them (at least until yesterday) was kaspersky.com. A hacker codenamed unu posted details – not all the details, but enough to show that the vulnerability was real. The hack exposed [...]
February 9th, 2009 at 11:05 am
You funny people, which fucking language are you writing?
February 9th, 2009 at 11:12 am
@Wicked – romanian
February 9th, 2009 at 11:43 am
[...] post su HackersBlog ha riportato le prove di un attacco ai danni del sito web usa.kaspersky.com andato a “buon [...]
February 9th, 2009 at 12:10 pm
bravo baieti… si cate traceback-uri =)) nice.
February 9th, 2009 at 12:19 pm
[...] http://hackersblog.org/2009/02/07/usakasperskycom-hacked-full-database-acces-sql-injection/ [...]
February 9th, 2009 at 12:26 pm
[...] ”Kaspersky is one of the heading companies in the confidence and antivirus market. It seems as yet they have been not means to secure their own interpretation bases. Seems implausible but unfortunately, it’s true. Alter one of the parameters and you have entrance to everything,” says Unu. [...]
February 9th, 2009 at 12:37 pm
[...] en tout cas ce que laisse penser l’article publié par des membres de HackersBlog qui affirment être parvenus à accéder à une base de donnée contenant un grand nombre [...]
February 9th, 2009 at 1:07 pm
[...] a posting made Saturday, the hacker claimed a simple SQL injection gave access to a database containing [...]
February 9th, 2009 at 3:02 pm
I wish to get 5 years kaspersky lincense from him. please donate me….
February 9th, 2009 at 3:11 pm
[...] Será o fim dos tempos, a empresa de segurança da informação que “fabrica” o famoso antivírus de mesmo foi atacada por hackers segundo evidência no blog HackerBlog: http://hackersblog.org/2009/02/07/usakasperskycom-hacked-full-database-acces-sql-injection/ [...]
February 9th, 2009 at 3:56 pm
[...] ce que l’on pourrait penser à la lecture – inquiétante – de cette histoire, publiée par un hacker roumain sur HackersBlog : le pirate (ou appelez ça comme vous voulez) [...]
February 9th, 2009 at 4:17 pm
hahahaha 2fingers ce ti-am zis eu de about ala… uite ce zic francezii aia
))
par un hacker roumain sur HackersBlog : le pirate
February 9th, 2009 at 4:50 pm
[...] منبع خبر: hackersblog [...]
February 9th, 2009 at 5:14 pm
[...] hacker contó su hito en este post y para logar poner al descubierto la base de datos de los servidores de kaspersky usó una técnica [...]
February 9th, 2009 at 5:28 pm
Claudel, stii cum e cu presa si “infrumusetatul” situatiei
A modificat 2fingers disclaimer-ul
February 9th, 2009 at 5:28 pm
[...] Da verkaufe ich meinen Kunden eine der verbreitetsten Internet Secutity Software, und dann das! [...]
February 9th, 2009 at 5:34 pm
I have tried installed Kaps into my laptop but display saying remove old kaps 8. I did tried remove but itself cannoy emove so stuck there. Could you help me to do it.
Thanks
February 9th, 2009 at 5:36 pm
Rob, try their official support center: http://www.kaspersky.com/support/
February 9th, 2009 at 5:38 pm
LOOOL! tocsixu sa cereti banii pe support
) ca vin astia si va cer ajutor ptr antiv
)) lmao
February 9th, 2009 at 7:53 pm
[...] was hacked at the weekend, exposing a database containing customer details A hacker claimed in a blog posting that he was able to access Kasperky’s databases containing a customer details including users, [...]
February 9th, 2009 at 8:04 pm
[...] to Hacker’s Blog article on 07-Feb-2009, Russian’s desktop security vendor “Kaspersky” was target of a [...]
February 9th, 2009 at 9:02 pm
[...] you have access to EVERYTHING: users, activation codes, lists of bugs, admins, shop, etc. Source: HackersBlog Blog Archive usa.kaspersky.com hacked … full database acces , sql injection __________________ -Jason / WTF Admin Little girl, this seems to say, Never stop upon the [...]
February 9th, 2009 at 9:37 pm
[...] an attack on the site“. Howell The Kaspersky hacker, who published their finding on the Hackersblog.org website, has since said that confidential data would not be released. “[The] Kaspersky team [...]
February 9th, 2009 at 10:01 pm
[...] original post appeared on Hackersblog with follow on discussion [...]
February 9th, 2009 at 10:04 pm
I there an email address for you guys so I can give you some contact info?
Thanks
February 9th, 2009 at 10:05 pm
hackersblog.org at gmail.com
February 9th, 2009 at 10:24 pm
[...] Kaspersky noto e famosissimo per la sua qualità come antivirus è stato violato da un attacco in SQL Injection . Hackersblog ha fornito in dettaglio tutta la procedura dell’attacco con tanto di screenshot di chi di mestiere dovrebbe sapersi difendere dagli “attacchi”. Ecco le dichiarazioni: “Sabato 7 febbraio, una vulnerabilità è stata rilevata in una sottosezione del nostro dominio usa.kaspersky.com, dove un hacker ha portato un attacco sul sito. Il sito è stato vulnerabile solamente per un breve periodo e a subito dopo la rilevazione del bug abbiamo preso le misure necessarie per sostituire la sottosezione del sito e la vulnerabilità è stata eliminata entro 30 minuti. La vulnerabilità non era critica e nessun dato è stato compromesso”. Ecco il sito documentato sull’attacco: KasperskyHacked [...]
February 9th, 2009 at 10:59 pm
[...] web de Kasperksy USA hackeada Aqui teneis el enlace de la noticia: HackersBlog
February 9th, 2009 at 11:10 pm
[...] http://hackersblog.org/2009/02/07/usakasperskycom-hacked-full-database-acces-sql-injection/ : encore site connu piraté à cause d’une injection SQL [...]
February 9th, 2009 at 11:34 pm
Haha, nice one guys
) tot romanii ma, tot noi
)
February 10th, 2009 at 12:08 am
[...] fi fost rusii??? , conform hachersblog.org site-ul din state a celor de la Kaspersky Labs a fost spart de un hacker care sustine ca a accesat [...]
February 10th, 2009 at 12:11 am
[...] line is that its defenses were strong enough to repel all but the most sophisticated hackers. The hacker’s line, no surprise, is that he’s grey hat, not black hat, and had no interest in probing around and [...]
February 10th, 2009 at 1:17 am
ostaakaa prk parempia FIIIIIrus systeemejä,äläkää tänne tulko itkeen jos on koneen tiedot maailmalla,tai ÄLKÄÄ OSTAKO TÄTÄ
February 10th, 2009 at 1:22 am
[...] Wow! Qualcuno ha bucato la sicurezza del sito di Kaspersky Usa, il famoso antivirus. Il tutto a fin di [...]
February 10th, 2009 at 1:43 am
[...] informações foram postadas no blog “Hackers Blog” que não apresentou maiores [...]
February 10th, 2009 at 2:49 am
[...] hackers, who are presumed to be Romanian, went public early Saturday in a blog post where they claimed that after launching a SQL injection attack on Kaspersky’s [...]
February 10th, 2009 at 9:01 am
[...] auf der Webseite hackersblog.org zu lesen ist konnte man mittels SQL Injection Daten abrufen, die normalerweise nicht für die [...]
February 10th, 2009 at 9:30 am
[...] hacker contó su hito en este post y para lograr poner al descubierto la base de datos de los servidores de kaspersky usó una [...]
February 10th, 2009 at 9:42 am
[...] The post by the hacker who cracked the Kaspersky website can be found here: Kaspersky Website Hacked [...]
February 10th, 2009 at 9:54 am
[...] cắp thông tin khách hàng. Theo tuyên bố của nhóm hacker được đăng trên trang HackersBlog, chúng đã đột nhập được vào cơ sở dữ liệu của trang web thuộc chi nhánh [...]
February 10th, 2009 at 10:10 am
The hackers, who are presumed to be Romanian, went public early Saturday in a blog post where they claimed that after launching a SQL injection attack on Kaspersky’s U.S. support site, they were
able to access a customer database that included e-mail addresses and software activation codes
LOL!
February 10th, 2009 at 10:12 am
Ia uite ce parere are Kaspersky despre voi

“A more advanced hacker could have potentially accessed about 2,500 e-mail addresses of customers and about 25,000 product activation codes that were on the compromised server, but that did not happen, Schouwenberg said.”
http://news.cnet.com/8301-1009_3-10159640-83.html?part=rss&subj=news&tag=2547-1_3-0-20
February 10th, 2009 at 10:20 am
E momentul sa inceapa sa isi refaca si ei imaginea. E de inteles.
February 10th, 2009 at 11:34 am
[...] and no data was revealed," he said. The hackers, who are presumed to be Romanian, went public early Saturday in a blog post. There, they claimed that after launching a SQL injection attack on Kaspersky’s U.S. [...]
February 10th, 2009 at 11:38 am
Bravo! Inca un articol despre voi:
http://www.tomsguide.com/us/Kaspersky-Hacker-Internet-Security,news-3456.html
“The attack was unsuccessful and, despite their attempts, the hackers were unable to gain access to restricted information stored on the website,” said the company in a press release.
February 10th, 2009 at 12:54 pm
ce distrusi… “The attack was unsuccessful and, despite their attempts, the hackers were unable to gain access to restricted information stored on the website” … vai de pula lor, noroc ca ati gasit voi treaba asta si nu altul care ar fi facut pagube. Full disclosure FTW si multumim ca aveti grija de imformatiile noastre confidentiale prin a expune niste GAURI in site-urile in care ar trebui ‘cica’ sa avem incredere.
February 10th, 2009 at 2:10 pm
Does anyone know how to register on this site?
February 10th, 2009 at 2:21 pm
Just incredible !!! It’s funny to see that one of the leading companies in the security and antivirus market is not able to secure their own data bases. SQL Injections is still alive !
February 10th, 2009 at 2:24 pm
[...] alte stiri hackersblog au devenit faimosi dupa ce au descoperit o vulnerabilitate in kaspersky.com pe care au exploatat-o. [...]
February 10th, 2009 at 2:27 pm
[...] un e-mail către Kaspersky. Ne-au oferit exact o oră să răspundem, după care au postat totul pe blogul lor fără să aştepte un răspuns din partea noastră. Suntem norocoşi că atacatorii şi-au [...]
February 10th, 2009 at 2:37 pm
Just Incredible ! It’s funny to see that one of the leading companies in the security and antivirus market is not secured. SQL Injections is still alive !
February 10th, 2009 at 5:32 pm
[...] Una entrada en el sitio Hackersblog.org incluye capturas del hacker inyectando código SQL para acceder a la base de datos de la compañía a través del sitio de soporte técnico de la división norteamericana, presuntamente creado por terceros y nunca evaluado apropiadamente en términos de seguridad. De acuerdo a los datos de Kaspersky, el sitio se puso en-línea el pasado día 28 de enero, haciéndose público apenas un día después de eso. [...]
February 10th, 2009 at 6:41 pm
It only proves that no company no technology is secure, next time could be symantec or microsoft or even mcafee, who know right!?
February 10th, 2009 at 6:51 pm
We need to make a difference between websites and av products. Yes the website was hacked but still kaspersky av is one of the best security products, right next to symantec, eset, mcafee, bitdefender & others.
This is just my opinion of course.
February 10th, 2009 at 7:15 pm
[...] angajat roman al Kaspersky a dat alarma dupa ce a vazut o informatie publicata pe site-ul romanesc Hackers Blog, Angajatul a alertat Kaspersky USA si intr-o jumatate de ora sectiunea cu probleme a fost inlocuita [...]
February 10th, 2009 at 7:17 pm
daca McAfee va avea situl vulnerabil e nasol pentru ei, avand in vedere ca un produs pentru testarea problemelor de genu
February 10th, 2009 at 8:07 pm
[...] hacker, who officially publicized the hack on Hackersblog, informs that he only planned to hack the website after he got no response from the Kaspersky Labs [...]
February 10th, 2009 at 9:13 pm
[...] site Hackers Blog notificou que o site da empresa de antivírus Kaspersky foi invadido nos EUA. Os Hackers [...]
February 10th, 2009 at 9:26 pm
Ai de capu’ meu şi eu care credeam că e cel mai bun antivirus, implicit că se pricep la securitate.
Oricum, când am văzut că scrie în limba română, parcă eram mândru că ne pricepem şi noi la ceva.
Ar trebui să vă răsplătească într-un fel că le-aţi arătat cât de prost stau cu securitatea.
February 10th, 2009 at 9:29 pm
This is embarrassing..such a big site..and still such a easy attack.I bet that more than 80% of website are vulnerable to some kind of attack..It only requires a lot of patiance..
February 10th, 2009 at 9:29 pm
[...] Site-ul care dezbate problema si explica ce si cum. Nu va speriati, puteti vizita fara probleme. E un site un site onorabil care se ocupa cu probleme de securitate informatica. Ii salutam cordial cu ocazia asta (ne guduram si noi putin acum, ca doar nu vrem sa ne imprietenim cu Kaspersky gauritul). [...]
February 10th, 2009 at 9:34 pm
Deja au inceput si parodiile pe teme asta
http://www.martianul.ro/gaura-lui-kaspersky-a-fost-sparta-de-un-hacker-roman-10-02-2009/
February 10th, 2009 at 9:51 pm
[...] The hacker himself told that a small modification could have gained him access to activation codes, users, admins, lists of bugs, shop etc. He also said that he informed kaspersky about the vulnerability, and leaked it to public right after 1 hour. [...]
February 10th, 2009 at 10:52 pm
Felicitarile mele echipei de aici! Sa mai auzim astfel de lucruri, chiar si mai mari!
February 10th, 2009 at 11:47 pm
[...] Şuradaki linkte ise olayın teknik boyutu ele alınmış. Veri tabanına full erişimin sağlandığından ve veri tabanındaki tablo yapısından açıkça söz ediliyor. Büyük ihtimalle bütün veriler ele geçirildi. Kaspersky bi’ şekilde bunu yapanı çok ağır bir şekilde cezalandıracak gibi duruyor. [...]
February 11th, 2009 at 12:44 am
[...] The Hacker’s Blog nous montre comment ils ont réussi, avec une faille plus que basique d’injection SQL, a pirater leur site et acceder à toutes les informations les plus critiques de leur base. [...]
February 11th, 2009 at 1:09 am
well i think you won a job in kaspersky labs dude
February 11th, 2009 at 1:49 am
[...] hacker, who officially publicized the hack on Hackersblog, informs that he only planned to hack the website after he got no response from the Kaspersky Labs [...]
February 11th, 2009 at 1:52 am
[...] hacklendiği ve bütün müşteri bilgilerinin dışarı sızdığı iddia edildi. İlgili yazıya buradan ulaşabilirsiniz. Her ne kadar Kaspersky bu olayı yalanlasa da görünen o ki bir SQL injection [...]
February 11th, 2009 at 5:45 am
[...] hacker, who officially publicized the hack on Hackersblog, informs that he only planned to hack the website after he got no response from the Kaspersky Labs [...]
February 11th, 2009 at 6:43 am
[...] portare a segno: “Basta alterare uno dei parametri” da passare all’URL composito, scrive unu su HackersBlog, “per avere accesso a TUTTO: utenti, attivazioni, codici, lista dei bug, [...]
February 11th, 2009 at 8:06 am
[...] hacker claimed in a blog posting that he was able to access Kasperky’s databases containing a customer details including [...]
February 11th, 2009 at 8:11 am
Congrats dude.
February 11th, 2009 at 11:08 am
Vooooo
February 11th, 2009 at 12:29 pm
[...] Tags: Razboiul Ideilor trackback La cafea citeam astazi o stire in Hotnews despre o noua “reusita” a hackerilor romani. Victima Kaspersky LAB. Dupa mine devine plictisitor cum chiar firmele [...]
February 11th, 2009 at 12:36 pm
[...] http://hackersblog.org/2009/02/07/usakasperskycom-hacked-full-database-acces-sql-injection/ [...]
February 11th, 2009 at 12:45 pm
[...] que ha comprometido la seguridad del sitio web de karpersky de los EE.UU. En un post puesto en HackersBlog, unu ha publicado capturas de pantalla, así como una lista de las tablas de la base de datos [...]
February 11th, 2009 at 2:21 pm
[...] (Articolul in continuare) [...]
February 11th, 2009 at 3:57 pm
[...] (the Antivirus vendor) support database left the company with a bit of explaining to do. The hacker published a blog post on hackersblog detailing stunts with Kaspersky’s USA support website. Kaspersky also [...]
February 11th, 2009 at 6:20 pm
[...] Cei de la Kaspersky au fost anuntati printr-un e-mail vinerea trecuta despre o vulnerabilitate a site-ului. O ora mai tarziu le-a fost spart site-ul. “unu” – asa isi spune hackerul, a reusit sa afle parola de la baza de date a site-ului si, a afisat structura tabelelor si cateva screen-sht-uri pe site-ul romanesc Hackers Blog. [...]
February 11th, 2009 at 6:32 pm
omg cate trackbackuri. sunteti vedete !!
apropo, scriu si dajtebtii astia de la libertatea de voi http://libertatea.ro/stire/un-hacker-roman-a-spart-site-urile-kaspersky-si-bitdefender-229681.html
February 11th, 2009 at 6:47 pm
[...] ste pratili vesti na Internetu, verovatno ste već pročitali da je uhakovan američki sajt ruske anti-virus kompanije Kaspersky. Tom prilikom, neimenovani haker imao je pristup kompletnoj listi klijenta, sa svim njihovim [...]
February 11th, 2009 at 7:46 pm
[...] serverului portal.edu.ro prin LFI in Bugs (142 Visits)AsociatiaBrokerilor.ro in Bugs (43 Visits)usa.kaspersky.com hacked … full database acces , sql injection in Local File Inclusion (461 Visits)RedTube.com … The Free Sex Video Community in Local File [...]
February 11th, 2009 at 8:17 pm
foarte tare … bravo! mai paypal trebuie hackuit
February 12th, 2009 at 4:39 am
[...] Post Hack BitDefender PT Post Hack Kaspersky USA [...]
February 12th, 2009 at 6:24 am
Congratulations on the hack. There is nothing worse than false security, and these guys definitely gave that. Good work guys.
February 12th, 2009 at 7:29 am
mda, subiectul acesta imi tot apare prin reader… era momentul sa dau si eu un comment, ca de nu cred ca ma urmarea in continuare…
February 12th, 2009 at 9:34 am
most large systems is the cost of even minuscule holes so that the end of
February 12th, 2009 at 9:41 am
[...] oameni hăcuiesc kaspersky.com la nivel demonstrativ, fără intenţii criminale. Ca să arate că există [...]
February 12th, 2009 at 10:08 am
[...] taką opublikował 7 lutego 2009 roku jeden z redaktorów witryny hackersblog.org. W artykule stwierdzono, że w stronę tego [...]
February 12th, 2009 at 10:25 am
[...] εδώ » και εδώ [...]
February 12th, 2009 at 1:28 pm
[...] please! iodus 12 Feb, 2009 Securitate Dupa Kaspersky si BitDefender, a venit timpul si celor de la F-Secure.com… vulnerabil la SQL Injection si la [...]
February 12th, 2009 at 5:12 pm
cat m-am bucurat cand am auzit stirea asta, sincer. in schimb m-am intristat ca in continuare, olandezii cel putin (locuiesc prin zona lor de ceva timp), nu au zis nimic in niciun ziar sau la vreun tv de asta ca deh, sunteti romani, de ce sa zica ca ati descoperit ceva bun… neah, tot pe tiganii care fura ii promoveaza in continuare. niste jegosi. stiu ca suntem mai buni decat multi altii pe IT.
bravo inca o data!
diseara ma duc sa mai bag un acces de 777 pe o olandeza, numai asa de ciuda.
February 12th, 2009 at 7:31 pm
Now, a lot of associates who always chidded me for NOT using Kaspersky products in my servers and other machines will shut up. I hope the rest of the so-called antivirus companies will immediately take appropriate measures so this kind of thing does not occur in their own backyards. Kaspersky’s reputation certainly got very compromised. Sorry.
February 13th, 2009 at 8:29 am
Internet related…
1. hackersblog.org anunta ca e o vulnerabilitate in site-ul celor de la kaspersky in us. Se dau screenshot-uri, liste cu tabele si explicatii. Kaspersky USA recunoaste o parte a atacului pe 10 februarie, adica la 3 zile !!! de la postarea anuntului cu …
February 13th, 2009 at 11:15 am
[...] hacker, who officially publicized the hack on Hackersblog, informs that he only planned to hack the website after he got no response from the Kaspersky Labs [...]
February 13th, 2009 at 12:39 pm
The Kaspersky Lab official response: no data was stolen or compromized. Read the entire article http://www.downloadtube.com/blog/
February 13th, 2009 at 3:49 pm
Huhu, I thought that Kaspersky the best antivirus solutions, but it hacked now, since Kaspersky Malaysia hacked before this…
From,
http://www.xetech.info
February 13th, 2009 at 11:21 pm
[...] ce un blog romanesc de securitate a descoperit o vulnerabilitate in site-ul usa.kaspersky.com s-a pornit un mare scandal. Imaginea [...]
February 13th, 2009 at 11:51 pm
[...] Am scris nu demult despre white – hacking-ul celor de la http://hackersblog.org asupra kaspersky (usa.kaspersky.com hacked … full database acces , sql injection ), am scris aici. Si apoi urmeaza replica celor de la [...]
February 14th, 2009 at 12:52 pm
[...] 3. usa.kaspersky.com hacked … full database acces , sql injection [...]
February 14th, 2009 at 8:13 pm
[...] hacking Saturday, February 14, 2009, 20:09 Posted in hacking and has 0 Comments so far. After Kaspersky and BitDefender, it’s now time for F-Secure.com … vulnerable to SQL Injection plus Cross Site [...]
February 14th, 2009 at 8:47 pm
[...] několika dny se jistý člověk vystupující pod přezdívkou Unu na blogu Hackersblog.org pochlubil tím, že se mu díky SQL Injection údajně podařilo hacknout webové stránky ruské [...]
February 15th, 2009 at 5:35 pm
[...] firması Kaspersky Lab müşteri veritabanının hack edildiğini 11 gün sonra hacker’s blog sitesindeki yazılardan [...]
February 17th, 2009 at 10:24 am
[...] injection and cross-site scripting to gain access to a database on the Kaspersky support site, he advertised his accomplishment, and that’s when the company learned of the attack.The company, which many (arguably) say produces [...]
February 18th, 2009 at 7:45 pm
[...] (read more) [...]
February 20th, 2009 at 5:56 am
[...] over a week ago, Unu found a similar problem in Kaspersky Lab’s site, as well as in a partner site for security vendor BitDefender and in the F-Secure Web [...]
February 20th, 2009 at 11:17 am
[...] over a week ago, Unu found a similar problem in Kaspersky Lab’s site, as well as in a partner site for security vendor BitDefender, and in the F-Secure Web [...]
February 21st, 2009 at 5:46 am
[...] De fato que a invasão houve e o próprio hacker publicou no Hackersblog ? * Clique aqui e veja o link da invasão [...]
February 21st, 2009 at 10:46 pm
[...] : http://hackersblog.org/2009/02/07/usakasperskycom-hacked-full-database-acces-sql-injection/ [...]
February 24th, 2009 at 8:04 pm
[...] The hacker, Officially favored them by reporting them about the vulnerability through email.Check Hackersblog, For more [...]
February 26th, 2009 at 9:03 am
[...] “hacking series” against major antivirus companies. After the recent SQL injections in Kaspersky, BitDefender (here and here) and F-Secure the regular user might wonder in which company should [...]
March 8th, 2009 at 8:06 pm
[...] американском сайте “Лаборатории Касперского” и опубликовали список таблиц баз данных ресурса, якобы содержащих [...]
March 25th, 2009 at 12:20 am
[...] Kaspersky Lab, a huge antivirus software company (of all things), has been hacked according to the Register. That seems to be the conclusion based on evidence posted on a blog yesterday. [...]
March 26th, 2009 at 5:08 am
if u hack http://www.rising.com.cn
U r so stronger
March 28th, 2009 at 7:25 pm
[...] BTW….Kaspersky (USA) was also hit with a SQL injection back in February exposing everything. HackersBlog Blog Archive usa.kaspersky.com hacked … full database acces , sql injection __________________ For HELP, summon support with the Bat-Signal: http://support.hostv.com/ [...]
May 1st, 2009 at 5:01 am
Does anyone know if there is another language or set of commands beside SQL for talking with databases?
I’m working on a project and am doing some research thanks
May 16th, 2009 at 1:34 am
HyG:
Get lost with your IIS/6.0
May 19th, 2009 at 1:39 pm
din cate am observat au reusit sa repare vulnerabilitatea, e adevarat?
June 6th, 2009 at 9:10 am
[...] http://hackersblog.org/2009/02/07/usakasperskycom-hacked-full-database-acces-sql-injection/ Share and Enjoy: [...]
June 15th, 2009 at 5:53 pm
[...] hacklendiği ve bütün müşteri bilgilerinin dışarı sızdığı iddia edildi. İlgili yazıya buradan ulaşabilirsiniz. Her ne kadar Kaspersky bu olayı yalanlasa da görünen o ki bir SQL injection [...]
June 30th, 2009 at 9:39 pm
[...] Details on this as yet. Hackers blog has more on the Kaspersky hack which seems to be good old SQL [...]
August 8th, 2009 at 5:31 pm
August 28th, 2009 at 7:37 pm
Good job
September 6th, 2009 at 6:37 pm
good … very good
September 29th, 2009 at 9:00 pm
Wow this gave me a good laugh lol
October 22nd, 2009 at 9:27 pm
[...] Those two(?) vulnerabilities are NOT confirmed. Read more about usa.kaspersky.com vulnerabilities here. [...]
November 23rd, 2009 at 12:50 pm
[...] in February of this year, the Romanian hacker Unu found a SQL injection vulnerability in a Kaspersky tech support portal server based in the USA. That vulnerability when exploited allowed full access [...]
November 25th, 2009 at 11:36 am
[...] Szczegółowy opis ataku znajduje się na blogu Unu: http://unu123456.baywords.com/2009/11/23/symantec-exposed-passwordsserials-sql-injection-full-database-access/ Dla przypomnienia, opis ataku na stronę Kaspersky’ego: http://www.hackersblog.org/2009/02/07/usakasperskycom-hacked-full-database-acces-sql-injection/ [...]
November 26th, 2009 at 1:04 am
[...] sulit dibobol dengan cara mengumumkan nama tabel yang mestinya tidak diketahui umum. Menariknya, Kapersky dengan jantan telah membenarkan bahwa situsnya memang kebobolan data [...]
November 26th, 2009 at 2:54 pm
[...] информация, с която разполага. Същият хакер беше счупил сайта на Kaspersky в началото на [...]
November 27th, 2009 at 5:50 pm
[...] 2009 | by Rik Ferguson | 1 views Back in February of this year, the Romanian hacker Unu found a SQL injection vulnerability in a Kaspersky tech support portal server based in the U.S. That vulnerability when exploited [...]
December 2nd, 2009 at 5:53 pm
[...] http://www.security-watchdog.co.uk/2009/02/kaspersky-gets.html http://hackersblog.org/2009/02/07/usakasperskycom-hacked-full-database-acces-sql-injection/ [...]
December 2nd, 2009 at 8:32 pm
Kaspersky este unul din cel mai de rahat antivirus pe care lai putea avea eu prefer sami fac proprii antivirusi si firewalluri dar eu va recomand AVG si va garantez ca nu va va lasa la greu.
December 3rd, 2009 at 3:18 am
[...] the big scandal regarding usa.kaspersky.com data breach posted for the first time here on hackersblog by our former member “unu”, [...]
April 15th, 2010 at 2:13 pm
Ce vremuri… hehe
April 19th, 2010 at 7:09 pm
[...] postarii unui blogger printr-un atac simplu de tip “SQL injection” asupra site-ului Kaspersky USA a putut avea [...]