Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security

December 18th, 2011, 14:18 GMT · By Eduard Kovacs

G2Secure Hacked for Discrimination Against Sick Man (Exclusive)

SHARE:

Adjust text size:


G2Secure Staff website
Enlarge picture
A hacker considered that the fine G2 Secure Staff had to pay to an individual as a result of a discrimination lawsuit wasn’t enough, so he breached their poorly secured databases, leaking administrator log-ins and employee records.

G2Secure Staff, a company that provides a wide range of aviation staffing and security solutions, was called to court by the U.S. Equal Employment Opportunity Commission (EEOC) for an incident in May 2010, when they denied a man who suffered a renal disease the opportunity to take a job application drug test by other means than with a urine sample.

The man completed all the requirements except for the urine test, which he could not provide due to his illness. When the EEOC found out about the situation, they filed a lawsuit against G2Secure, who was sentenced in court to pay $30,000 (21,000 EUR) and additional damages to the individual involved.

After hearing about the incident, the hacker known as Kahuna decided the ruling wasn’t severe enough for the organization, so he hacked into their website to punish them more. At the same time, he wanted to show that not even those who provide security are better protected.

“I found this to be ridiculous, that they would do something like this, so then I decided I would take a look at their site. Not a bad target if this is how they act as a company, with such little ethics,” the hacker told me.

“So I looked at their site and checked to see if I could find any vulnerabilities. After a perfunctory search, I found an SQL injection vulnerability in their services tab page, located linked off their homepage.”

The databases he found contained 63 administrative and executive e-mail addresses, passwords (not in clear text), names and access levels. Names, email addresses, addresses, and phone numbers belonging to more than 8,000 of their employees were also stored in the databases.

“At that point, I pulled the full database and leaked out the info that was most damaging to them to have hacked,” Kahuna added.

“I think this just goes to show further that companies can choose to be corrupt, and can choose to act unethically, but that doesn’t mean people won’t notice, and that just paying a settlement may not always be the only punishment. Especially when they have security issues on their site and choose to also include their employee records in the same database”

TELL US WHAT YOU THINK:

1,744 hits · 2 comments · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Police Raids ‘The Age’ for Political Hacking Suspicions

Rutgers and Tasmania University Websites Hacked by SODT (Updated)

Special Forces Hacked, 18,000 Accounts Leaked (Updated)

Botnets Attempt to Silence Russian Political Forums

Italian and Bhutan Government Websites Hacked by Kahuna

READER COMMENTS:


Comment #1 by: Mrs.MadAsF*** on 27 Jan 2012, 23:09 UTC reply to this comment

Well, I'm not even a employee to this company and didn't even know of what was done to this man but I only filled out a application and now I have to get punished just because of this one person that felt like it wasn't enough???? Now i already had to move my family already once before because of one individual that was stalking and harassing me and my family now were do I stand at on that...I blame there site for not being secure but I blame that * hole for putting my personally business on the web...I DON'T WORK FOR THAT COMPANY so why should it have been taking out on some people that didn't even know what was going on...is this * going to pay for me and my family to move again just because they wanted to prove a * point now this person is back at it again and I fear for the safety of me and my children...if I can find this person I will sue there asses and g2secure because they both are * full of * .


Comment #2 by: MichaelK on 30 Jan 2012, 22:42 UTC reply to this comment

From what I read in a different article, nobody on the leaked information actually works for G2, they were just applying. So the hacker really didn't do much to hurt G2, he only hurt the individuals trying to get a job. Real smart Kahuna......

Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM