Monday, February 9, 2009

Kaspersky Breach Exposes Sensitive Database, Says Hacker

"A security lapse at Kaspersky has exposed a wealth of proprietary information about the anti-virus provider's products and customers", writes The Register.

"In a posting made Saturday, the hacker claimed a simple SQL injection gave access to a database containing "users, activation codes, lists of bugs, admins, shop, etc." Kaspersky has declined to comment, but two security experts who reviewed the evidence said the claims appeared convincing."

Assuming that the hack is real it wouldn't be the first time that Kaspersky site has been hacked with a SQL injection. In July 2008, Kaspersky's Malaysian site and several subdomains were harmed by hacker leaving pro-Turkish slogans behind.

No comments: