Loading....
Loading....

    Posted by 2fingers in English News

    Posted on September 27th, 2009

    Ok. First let me start with this image http://i34.tinypic.com/zw0x34.png. This image was posted yesterday by TinKode on RST board. But I won’t talk about this now.

    Now let’s try something. What is happening if I use https://eset.ro instead of http://eset.ro?

    1. I will be redirected to https://partner.axelsoft.ro/partner/

    eset panel

    2. After I press “Login” this will show up:

    eset partners

    3. Bingo! We have a cookie :)

    eset partners panel

    Now let’s see what we have here.

    a) a security product website

    b) a security product website with login credentials already filled in

    c) a security product website with login credentials already filled in, that gives access to anyone in some areas that should stay private.

    Probably someone from Eset will tell us that eset.ro is just an partener. But they use Eset logo and we can see in the footer “Copyright © 2008 ESET, LLC si ESET, spol. s.r.o. Toate drepturile rezervate.”

    Just take the right conclusions by yourself.

    Random Posts

    7 Responses to “Nod32.ro/Eset.ro or let’s talk about fail”

    1. Andrei Rinea Says:

      WTF? No hacking? They just hacked themselves and left the door open..

    2. Kabron Says:

      One word : NICE !

    3. Ne0h Says:

      Este de plans cand ne gandim ca aceste site-uri promoveaza securitatea.Dar ce securitate promoveaza cand nu se protejeaza pe ei insusi?

    4. Bob Says:

      Look at the eset staff try to come up with excuse(?) here: http://www.wilderssecurity.com/showthread.php?t=254446

    5. 2fingers Says:

      @Bob – Yes, it’s a lame excuse used by ALL security vendors when they were hacked. You can see the proof of that right here on hackersblog. Just take a look on our articles about hacked security vendors, and search on Google for their official response. They always say “it was vulnerable just for few hours or a day or two”. This is just PR bullshit, believe me. And btw just take another look at the first link posted in this article. That was a successful hacking intrusion and I heard that few guys still have access to that page because eset.ro staff didn’t realised yet what method was used for this intrusion.

      But, and this is very important, i’m pretty sure that eset.ro wasn’t coded (entirely at least) by Eset.com coders. I like nod32 antivirus, I used nod32 AV on my machines from work, and I was very satisfied to see this product working very good.

      Eset.ro is just a crappy website, probably coded by some noobs (I hate this word but it’s true in this case), but we can’t judge the entire Eset network/products by looking just at this (bad) example.

    6. dak Says:

      Um, just one thing. That .ro at the end of the URL marks the sight as a ROMANIAN SITE.

    7. Andrei Rinea Says:

      it’s called a TLD (Top Level Domain)

    Leave a Reply