Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
TRENDING TODAY
Home > News > Security > Security Blog

January 30th, 2013, 12:11 GMT · By

BLOG

Hacker Gains Access to 7 ESA Databases by Leveraging Blind SQL Injection Flaw

SHARE:

Adjust text size:


Blind SQL Injection vulnerability in ESA website Enlarge picture - Blind SQL Injection vulnerability in ESA website
The hacker known as D35m0nd142 has identified a Blind SQL Injection vulnerability on a domain owned by the European Space Agency (ESA). 

The hacker has managed to gain access to the information stored in 7 databases. To demonstrate his findings, he has published database and table names, but also the contents of one table with user IDs, email addresses and passwords.

However, all the sensitive information has been redacted.

“It was a very simple hack because this database isn't least protected. I've published some tables and the content of a user table from one single DB, but as you can see, I could take any record of the database. I've already warned administrators but until now they haven't respond to me,” the hacker told me.

This isn’t the first time when D35m0nd142 shows that the systems of ESA are vulnerable to cyberattacks. He says he has identified similar security holes on at least three other occasions. 

TELL US WHAT YOU THINK:

1,194 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Flaws in NASA’s GSFC Site Allowed Hackers to Bypass Firewalls, Steal Information

Website of Harvard’s School of Engineering and Applied Sciences Hacked

Royal Navy, Federal Reserve and Other Sites Hacked by D35m0nd142

Hacker Claims to Have Gained Access to 1,300 Databases Owned by 4 Universities

Hacker Leaks 600 User Accounts from Indian Entertainment Site to Prove Flaws

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2013 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM