Slashdot Mirror


Kaspersky Customer Database Exposed

secmartin writes "A hacker has managed to gain access to several databases via a SQL injection vulnerability on Kaspersky's US website. He has posted several screenshots and a list of available tables; judging from the table names, the information available includes data on bugs and user- and reseller accounts. The hacker has indicated that no confidential information will be posted on the Internet, but since a large part of the URLs used was visible in screenshots, it will only be a matter of time before somebody else manages to duplicate this."

8 of 175 comments (clear)

  1. Little Bobby Tables strikes again! by Anonymous Coward · · Score: -1, Troll

    Kaspersky? Not readin' TFA, sorry.

  2. frosty piss by Anonymous Coward · · Score: -1, Troll

    Eat horseshit jewish niggers /godwin

  3. Secure? Sure. by Anonymous Coward · · Score: -1, Troll

    Linux just isn't ready for the desktop yet. It may be ready for the web servers that you nerds use to distribute your TRON fanzines and personal Dungeons and Dragons web-sights across the world wide web, but the average user isn't going to spend months learning how to use a CLI and then hours compiling packages so that they can get a workable graphic interface to check their mail with, especially not when they already have a Windows machine that does its job perfectly well and is backed by a major corporation, as opposed to Linux which is only supported by a few unemployed nerds living in their mother's basement somewhere. The last thing I want is a level 5 dwarf (haha) providing me my OS.

    1. Re:Secure? Sure. by Anonymous Coward · · Score: -1, Troll

      Hail Hitler You fucking kike! Hail Hitler You fucking kike! Jesus Eats Babies Hail Hitler You fucking kike! Hail Hitler You fucking kike! Nigger Hail Hitler You fucking kike! Hail Hitler You fucking kike! Spic Hail Hitler You fucking kike! Hail Hitler You fucking kike! Coon Hail Hitler You fucking kike! Hail Hitler You fucking kike!

  4. Romanians.. by Anonymous Coward · · Score: -1, Troll

    Romanians at their best...

  5. i just got off the toilet by Anonymous Coward · · Score: -1, Troll

    i shit out an obama.

  6. Wait just a second here.. by Strep · · Score: 0, Troll

    Since when was it supposed to be legal to do this? This hacker should be thrown in the slammer. What the hell is this world coming to when you blame the vendor/sql/whatever-else when a "user" intentionally performs a malicious attack for whatever reason? This guy is a criminal and no better than any of the virus and malware writers out there. Do any of you have a clue as to how much these cyber-criminals actually cost the rest of us? Here's a partial answer: More than I want to pay.

  7. Re:For Gods sake escape those quotes by FlyingGuy · · Score: 0, Troll

    How about something even simpler....

    Simply do not accept ANYTHING that does not consist of a..z.A..Z,0..9 !

    Accepting anything other then that is simply stupid.

    You can discourage it on the front end by using a JS onkeyup method and on the back end you just strip them out, or if you detect anything other then those, simply reject the entire form.

    --
    Hey KID! Yeah you, get the fuck off my lawn!