ARN

BitDefender partner site hit by hackers

Hackers elicited customer details from a Portuguese partner site associated with the security company BitDefender.

Hackers elicited customer details from a Portuguese partner site associated with the security company BitDefender, the second intrusion in recent days targeting computer security companies.

The details are posted on hackersblog.org, which publishes information on security problems but says it will notify Web site operators and not reveal sensitive data.

The hackers used a form of a SQL injection attack to reveal personal details and e-mail addresses. SQL injection, one of the most common types of attacks, involves inputting commands into Web-based forms or URLs (Uniform Resource Locators) in order to return data held in back-end databases.

A 2006 survey by the Web Application Security Consortium of 31,373 sites found more than 25 percent were vulnerable to SQL injection, with more than 85 percent vulnerable to cross-site scripting attacks.

Screenshots posted on the blog show how the hackers were able to see data they shouldn't, although they took care to black out sensitive data.

BitDefender said the site was shut down after the vulnerability was found, and reopened on Monday around 6 p.m. GMT. BitDefender believes that none of the data exposed will be used for malicious purposes and that the attack was intended to illustrate the vulnerability. No customer credit card data was stored on the site, the company said.

BitDefender said it advises partners on good security practices but that "we can't control how our partners manage their sites."

Major computer security companies have seen their sites come under attack, highlighting how even organizations with deep knowledge of the dangers of hacking can still be caught off guard.

Last weekend, a hacker broke into part of Russian security company Kaspersky Lab's new U.S. support Web site. Company officials confirmed a programming flaw left the site open to SQL injection. The hacker could have accessed about 2,500 customer e-mail addresses and perhaps 25,000 product activation codes.

In July 2008, a Malaysian partner site for Kaspersky was defaced as it was still under development, although no sensitive data was lost.

Nominations for the 2012 ARN IT Industry Awards open on Tuesday, June 12.

More about: BitDefender, Kaspersky, Kaspersky Lab
References show all

Comments

Post new comment

The content of this field is kept private and will not be shown publicly.
Users posting comments agree to the ARN comments policy.
Login or register to link comments to your user profile, or you may also post a comment without being logged in.
Related Coverage
Related Whitepapers
Latest Stories
Community Comments
Tags: bitdefender, hack
ARN Directory | Distributors relevant to this article
SMS eTechnologies , WhiteGold Solutions , XiT Distribution
ARN Directory | Vendors relevant to this article
Kaspersky Lab
rhs_login_lockGet exclusive access to ARN's news, research and invitation only events.
ARN Distributor Directory
ARN Vendor Directory

iAsset is a channel management ecosystem that automates all major aspects of the entire sales,marketing and service process, including data tracking, integrated learning, knowledge management and product lifecycle management.