David M Williams
Monday, 09 February 2009 03:16
IT Industry -
Market
Page 2 of 2
The post was made by a user called “unu” on Saturday, February 7th 2009, and titled
“usa.kaspersky.com hacked ... full database access , sql.”
unu was kind enough to Kaspersky not to give specific details of how he or she circumvented security on the site, save to say SQL injection was used and that just one parameter was altered.
Access was opened to everything, says unu – users, activation codes, lists of bugs, administrator names, retail outlets and more. Unu listed the database tables by name and gave the following three screen shots to prove the claims being made. (Click to open at a larger size.)
unu said he or she would not divulge any information identifying users or activation keys.
Kaspersky have not posted any comment on their web site, although ironically a February 3rd press release announces Kaspersky Lab experts outline the major threats facing the IT security industry in 2009. SQL injection is not listed, but perhaps it now should be.