Loading....
Loading....

    Posted by Shocker in English News

    Posted on February 11th, 2009

    untitledEnglish version:
    After Kaspersky and BitDefender, it’s now time for F-Secure.com … vulnerable to SQL Injection plus Cross Site Scripting. Fortunately, F-Secure doesn’t leak sensitive data, just some statistics regarding past virus activity.

    Exposed database tables:
    MailboxInfo, VirusUpdated, dtproperties, Country, sysconstraints, VirusTrends, Virus_Top50_24h, Virus_Top50_30days, Virus_Top50_7days, Virus_Top50_90days, Virus_Top50_Month, Virus_Top50_Week, VirusDateTotal, VirusDate, VirusMonthTotal, VirusReports, VirusReportsTemp, VirusTrends.

    Screenshots:
    SQL Injection (SQL Server info / Extracting table names):

    Cross Site Scripting (XSS):

    =========================================================

    Romanian version:
    Dupa Kaspersky si BitDefender, a venit timpul si celor de la F-Secure.com… vulnerabil la SQL Injection si la atacuri de tip Cross Site Scripting. Din fericire, cei de la F-Secure nu au scurgeri de informatii sensibile, doar cateva statistici referitoare la raspandirea virusilor din ultima perioada.

    Tabelele expuse din baza de date:
    MailboxInfo, VirusUpdated, dtproperties, Country, sysconstraints, VirusTrends, Virus_Top50_24h, Virus_Top50_30days, Virus_Top50_7days, Virus_Top50_90days, Virus_Top50_Month, Virus_Top50_Week, VirusDateTotal, VirusDate, VirusMonthTotal, VirusReports, VirusReportsTemp, VirusTrends.

    Screenshot-uri:
    SQL Injection (Informatii despre serverul SQL / Listarea tabelelor):

    Cross Site Scripting (XSS):

    Related Posts

    30 Responses to “F-Secure.com – SQL Injection + Cross Site Scripting”

    1. F-Secure.com - SQL Injection + Cross Site Scripting Says:

      [...] ca, Tocsixu ne arata intr-un articol pe HackersBlog cum F-Secure este vulnerabil la SQL Injection si Cross Site [...]

    2. necenzurat Says:

      ura… nodu cand vine
      si norton ?

    3. Ali Kapucu Says:

      :) very funy I think it’s a competition :)

    4. ILoveMe Says:

      http://www.libertatea.ro/stire/un-hacker-roman-a-spart-site-urile-kaspersky-si-bitdefender-229681.html

      Maine o sa fiti in ziar , probabil . Nice :D

    5. forthisworld Says:

      sunteti tari :) imi place blogu ! bafta

    6. Updates about Kaspersky SQL injection | Security and the Net Says:

      [...] try to downplay this issue, and that the hackers that found this issue are also keeping their competitors alert. It’s also a good reminder never to trust any code, whether it was produced in-house or [...]

    7. نوشته های رضا در دنیای زیبای وب » Blog Archive » سریال ادامه دار ِ ضعف امنیتی “سایت های امنیتی”! Says:

      [...] اگر فکر می کنید که داستان غم انگیز شرکت های امنیتی به همین دو مورد ختم می شود، سخت در اشتباه به سر می برید چرا که امروز برای سومین بار خبر هک شدن ِ سومین سایتی که قرار بود کامپیوترهای کاربران را امن کند، منتشر شد! سایت F-secure که در زمینه ی آنتی ویروس و ابزارهای امنیتی اینترنتی فعالیت می کند نیز هک شد. البته به گفته ی hackersblog در این حمله خوشبختانه اطلاعات حساس در دسترس قرار نگرفت و فقط بعضی از اطلاعات آماری از طریق دسترسی غیرمجاز به روش های تزریق کدهای SQL و Cross Site Scripting مورد نفوذ و دسترس قرار گرفت(منبع خبر). [...]

    8. Strangely Says:

      Whatever next!! Are you all working your way through all the AV vendors, I wonder? I think #3 has it right – it’s a competition.

      Seriously though, as I said on my blog; How do You Keep the Gates Closed when the Gatekeeper Loses the Keys?

      Thanks for the work keeping people on their toes.

    9. Vlad Says:

      ^^^^ Lol astia au trimis Al-Qaeda pe voi :) )

    10. Chris Saddler Says:

      chiar asa, o gramada de arabi va citeaza :) )
      nu il aveti pe bin laden in spate sa va apere, nu? :) )

    11. Ionescu Latul Says:

      nice job ;)

    12. vlad Says:

      apropo :) ) dupa faza cu kaspersky au scris despre voi pe site-ul acunetix … cica “probabily using a pirated version of acunetix” :) )
      http://www.acunetix.com/blog/web-security-articles/sql-injection-sneaks-into-kasperskys-support-website/

    13. paxnwo Says:

      ce se caca aia de la acunetix pe ei

    14. Skippy Says:

      @Strangely: AV companies are no way near being the standard that all computer security should be measured against. AV products basically use blacklisting, which means playing an eternal game of catch-up with endless lists of malware, which they lose every minute of every day. This approach is flawed from the start. The answer for that particular problem is something like this (incidentally, that article also mentions Kaspersky).

      Likewise, security on the web is achieved not by trial and error, running “scans”, automated injection tools, or running firewalls or automatic sanitizers, it’s by following basic security design from the ground up. But I wouldn’t expect an AV company to understand that, given their faulty reasoning.

      Sure, let all script kiddies run all the attacks they can think of. It’s meaningless. If a site is really secure then it won’t matter, and if it’s not, it was already exposed, even if nobody exploits it. And it’s not the kiddies fault, it’s the site builders’.

      Către echipa Hacker’s Blog: cred că a venit timpul şi pentru un articol care să explice diferenţele între “securitatea” obţinută prin scanări şi teste automate de penetrare, respectiv cea gîndită serios, şi metode concrete de eliminare a SQL injection şi XSS. Plănuiam oricum să scriu aşa ceva dar dacă o faceţi şi voi, cu atît mai bine. Ar închide în orice caz gura celor care vă acuză că descoperiţi aceste găuri de securitate “din greşeală”.

      Pînă atunci, iată un articol mai vechi care sper că e util; it’s in English and contains an overview of the various forms of injection on the Web.

    15. dblackshell Says:

      si iar explozia de trackbackuri… oricum eu mai mult apreciez f-secure si se simte ca aplica “defense in depth”… mi-a placut declaratia lor oficiala nu ca s-au tras pe cur ca si Kaspersky…

      http://www.f-secure.com/weblog/archives/00001605.html

    16. dblackshell Says:

      @unu: ai folosit sau nu acunetix? =)) (doar acum observasem)… oricum acunetix (l-am incercat si eu) si tinde sa rateze cateva vulnerabilitati… e mai funky =))

    17. whatever Says:

      Nu avea cum sa foloseasca Acunetix daca vulnerabilitatea a fost intr-un url de tipul http://usa.kaspersky.com/support/5355453. Nici un scaner automat nu poate sa descopere asa ceva. Ca sa testezi asa ceva ai nevoie de creier sau de regulile de URL rewrite. Deci clar nu a folosit Acunetix.

    18. Not Only Kaspersky, But Also BitDefender and F-Secure Attacked Says:

      [...] but they also attacking another antivirus company with the same technic, BitDefender Antivirus and Security Company F-Secure. Its amaze me they can attack those site in a week.., hell yeah.. Here’s the Screenshoot [...]

    19. 2fingers Says:

      @Skippy – nu putem sa scriem despre diferentele dintre scanari cu programele si partea manuala. Nu stim ce sa spunem despre scannere pentru ca le evitam. Dau mult prea multe rateuri.

    20. Skippy Says:

      Nu la asta mă refeream ci la un articol din partea cealaltă a “baricadei”, unul despre cum se scrie o aplicaţie sigură. Mi se pare corect ca dacă tot arăţi cu degetul şi spui “aşa nu” să oferi şi varianta “aşa da”.

    21. F-Secure joins the ranks of the hacked security vendors. « InfoSec Musings Says:

      [...] joins the ranks of the hacked security vendors. The Romanian hackers are at it again.  Earier this week I posted about Kaspersky Labs getting hacked.  The same group [...]

    22. 2fingers Says:

      Ca sa inveti sa scrii o aplicatie sigura e nevoie de: rtfm cu atentie.

      End of article :)

    23. Serial security hackers hit F-secure - UsR: Unique Specialist Racing Says:

      [...] anyway at worldmap.f-secure.com and because of our IT security strategy, the impact was minimal. A posting on hacking forums about the F-secure attack backs up the security firm’s version of events. Any [...]

    24. Site da F-Secure é atacado por hackers - O Futuro do Passado Says:

      [...] da Kaspersky e BitDefender, vítima de ataques de injeção SQL. Os hackers (provavelmente romenos)postaram no Hackersblog.org que conseguiram executar ataques de injeção SQL e cross-site scripting (XSS) no [...]

    25. P Says:

      I just found this blog, seems nice but I would be very happy if posts with a english version had a “english” tag.

    26. 2fingers Says:

      Done. Thanks for the advice.

    27. Site da F-Secure é atacado por hackers « Ld Technology’s Says:

      [...] da Kaspersky e BitDefender, vítima de ataques de injeção SQL. Os hackers (provavelmente romenos) postaram no Hackersblog.org que conseguiram executar ataques de injeção SQL e cross-site scripting (XSS) no [...]

    28. SQL injection attacks on security vendor Says:

      [...] security company can make mistakes too, and perhaps faces a successful attack. “Although the attackers were able to read information from the database they [...]

    29. Un groupe de pirates cible les firmes de sécurité @ TTBA Says:

      [...] considéré comme de bas niveau, et qu’aucune donnée confidentielle ne s’y trouve. Des détails techniques sur l’attaque ont été publiés sur le blogue [...]

    30. Zero Day mobile edition Says:

      [...] group of serial pen-testers of security vendors, which discovered similar flaws in the web sites of F-Secure, Symantec, BitDiffender, and Kaspersky USA. Let’s start from the basics. PR contingency planning in [...]

    Leave a Reply

    Studio videochat bucuresti Studio videochat Bucuresti
    Download Muzica Filme
    Studio videochat Iasi videochat Iasi