69568 cazuri COVID-19 în Moldova
17505 – cazuri active
50422 – cazuri vindecate
1641 – cazuri fatale
Actualizarea datelor: 23 octombrie 2020 ora 07:24

Update la Hackersblog

Am scris nu demult despre white - hacking-ul celor de la http://hackersblog.org asupra kaspersky (usa.kaspersky.com hacked … full database acces , sql injection ), am scris aici. Si apoi urmeaza replica celor de la kaspersky:

The American support website of Kaspersky Lab was illegally accessed by hackers on Saturday, delivering a black eye to a company responsible for providing security solutions to some 250 million users worldwide.

“Yes, this is not good,” Roel Schouwenberg, Kaspersky’s senior anti-virus researcher, said on a conference call Monday with reporters. “This is not good for any company, especially for a company dealing with security. We are now doing everything within our power to do the forensics on this case.”

A Romanian hacker using the nickname “Unu” claimed responsibility for the attack, which leveraged SQL injection to exploit a vulnerability in the site’s code that enabled the hackers to view a list of database tables.

The intruders, however, did not access or leak any data. But Schouwenberg said a more sophisticated hacker could have accessed 2,500 customer email addresses and 25,000 product activation codes that were residing on the server.

The incident affected http://usa.kaspersky.com/support, a new part of the Kaspersky website that officially was launched Jan. 29 and had been live 10 days prior to the breach, Schouwenberg said. The support site was built by a third-party code developer.

Kaspersky learned of the attack at noon Saturday, and 15 minutes later took down the new site and replaced it with the older version, which is still operating, according to the company.

“We fell victim because something went wrong in our internal code reviewing process,” Schouwenberg said. “Obviously, we are not happy about that and we are in the process of making the review process stricter than it currently is.”

The company has hired David Litchfield, considered a leading expert on database security, to conduct a forensic exam. Kaspersky plans to release the results of the study as soon as they are available.

What is not surprising is how the hackers got in. Last year, SQL injection, related to improper validation of user input that allows hackers to run queries on a database, became the most common web-application vulnerability, according to IBM-ISS’ annual X-Force Trend and Risk Report.

Matt Wood, senior security researcher at Hewlett-Packard’s web security research group, said the support site appears to have not been properly vetted prior to going live.

“Any time you roll out any kind of new code, it’s likely to have some kind of problem in it,” he told SCMagazineUS.com on Monday.

Wood said it appears the Kaspersky support site wrongly allowed privileged access.

“There’s no reason your support site needs to have access to mission-critical data on the database,” he said. “That’s Security 101.”

Companies such as Kaspersky — which is headquartered in Moscow, but has offices in Woburn, Mass. — must have a comprehensive process in place to validate the security of new code, especially code developed by third parties.

“There’s a lot of stuff you can do to protect against this sort of thing that it sounds like they didn’t adhere to,” Wood said.

The same Romanian hacker also claimed responsibility for gaining access to the Portuguese website of security firm BitDefender. But a company spokeswoman said BitDefender was not impacted.

“A partner site was compromised, and we are working to investigate exactly what happened so we can help our partner prevent this from happening again,” the spokeswoman told SCMagazineUS.com on Monday. (de aici)

si :

A forensic exam has confirmed Kaspersky Lab’s initial findings that Romanian hackers did not compromise any personal data when they launched an SQL injection attack against the anti-virus company’s U.S. support site. David Litchfield of Next Generation Security Software said in a Thursday report that other attackers, upon learning of the vulnerable site at usa.kaspersky.com, attempted to access data but also were unable.(de aici)

Intrebarea este: Oare cei de la Kaspersky USA, mai navigheaza pe net? Adica mai fac cite un search pe Google, ca sa se mai documenteze?

2009-02-13 23:50:01


Ultimele 25 posturi adăugate

07:10:20Un șir de vagoane.... —» Andrei LANGA. Blogul personal
20:06:45EGAL: De ce România nu trebuie să intre în zona EURO? —» Curaj.TV | Media alternativă
18:21:56Jurnal de lecturi (3) —» Lumeadanei's Blog
17:47:16©️ „Crearea lui Adam” —» Licurici de suflet
16:48:55Noul Regulament de atestare a cadrelor didactice —» Liceul Teoretic “Mihail Sadoveanu”, Călăraşi
14:51:56Metoda Kaț —» Gheorghe Erizanu
14:43:37Leo BUTNARU - POEME RECENTE —» Leo Butnaru
14:09:57Hygge de toamnă: 30 de idei pentru a aduce în casă confortul și liniștea —» Sunt MAMĂ!
11:48:56UE-GIZ// Grupul de Inițiativă a Părinților și Profesorilor (GIPP) a dezvoltat competențe sociale și civice aplicabile în procesul de planificare și monitorizare a lucrărilor de eficiență energetică a infrastructurii publice. —» Asociaţia Obştească "Demos"
11:34:57Poveşti de dragoste între femei —» Curaj.TV | Media alternativă
11:23:48Nou pe piață: Divus Winery —» Fine Wine
09:57:37FRP TV – Mărturii despre un omor în custodia statului —» Curaj.TV | Media alternativă
09:53:58Replica administraţiei la plîngerea unei beneficiare —» Curaj.TV | Media alternativă
09:34:22Posibil tratament împotriva Covid-19, dezvoltat de o elevă de 14 ani —» Elena Robu
08:12:40Analiză la sînge a lui Mocanu/Antimafie şi unionişti —» Curaj.TV | Media alternativă
19:32:41Zaiafet – Cum ne salvăm lumea —» Curaj.TV | Media alternativă
19:12:49Croissant cu oua jumari si somon slab sarat —» Bucataria Talinei - condimentat cu dragoste
19:01:05Acrobaţii riscante cu bicicleta —» Curaj.TV | Media alternativă
19:00:40Solidaritate în Franța: Zeci de mii de persoane au ieșit pe străzi pentru a-l omagia pe profesorul decapitat —» Elena Robu
18:37:12Care e rolul școlii contemporane? —» Liceul Teoretic “Mihail Sadoveanu”, Călăraşi
18:29:06Cine sunt eu în spatele nemulțumirilor mele? —» Frinturi din suflet de femeie
16:58:19Igor Fediuş îi descîntă pe toţi candidaţii —» Curaj.TV | Media alternativă
16:14:49Primarul şi paznica se cam potrivesc, la Fierbinţi, IL —» Curaj.TV | Media alternativă
19:34:27Знаете ли вы, почему пальцы Бога и Адама не соприкасаются на знаменитом произведении искусства Микеланджело на потолке Сикстинской капеллы Апостольского дворца в Ватикане? —» Curbet Alexandru
19:31:04Rolul tatălui învățat de apostolul Pavel in 1 Tesaloniceni 2 —» Curbet Alexandru