NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home / News / Security / Hacking News

Hacking News


Symantec Website Hacked

Blind SQL injection vulnerability disclosed

By Lucian Constantin, Web News Editor

19th of February 2009, 08:41 GMT

Adjust text size:


Symantec website compromised through SQL injection
Enlarge picture
The Romanian ethical hacking outfit HackersBlog shames yet another antivirus vendor – Symantec. A SQL injection vulnerability in a section of the Symantec website allows unauthorized access to the database.

Symantec is one of the biggest IT security companies in the world, developing a wide range of products for both home and enterprise consumers. It is a veteran on the antivirus market, its flagship product being Norton Antivirus.

According to “unu,” a Romanian hacker associated with HackersBlog, the Document Download Centre section of the Symantec website contains a poorly-sanitized parameter, which facilitates SQL injection attacks. Successful exploitation results in giving an attacker access to the database.

“The irony of the situation is that it’s done on https, on a login page, a page that promotes security products like Norton AntiVirus 2009 and Norton Internet SECURITY,” the hacker, who doesn't specify what sensitive information, if any, is stored in that particular database, notes.

The documented attack is actually a “blind” SQL injection. As opposed to regular SQL injections, such attacks are harder to instrument, because the website does not respond back with useful error information that would give the hacker an idea of how to proceed.

According to the few items of information “unu” has provided, the website runs on an Apache Web server with PHP 5.2.6 and a MySQL 5.0.22 backend. The published screenshots demonstrate how executing SQL commands through URL manipulation alters the content of the page.

TRUE condition AND 1=1 - Page loads normally
Enlarge picture
FALSE condition AND 1=2 - Text disappears
Enlarge picture
SELECT function, AND (SELECT 1)=1 returns true - Text doesn't disappear
Enlarge picture


“Unu” claims to have contacted Symantec regarding the problem, or at least attempted to. “[...] On the website there is no contact email address for cases such as this, I’ve sent an email to webmaster@symantec.com and security@symantec.com. The email didn’t bounce, so someone must have received it. No answer as of yet,” he writes, while pointing out that more detailed info could be revealed after the company fixes the issue.

During the past two weeks, hackers from the HackersBlog crew have been disclosing various SQL injection vulnerabilities on websites belonging to no less than four antivirus vendors: Kaspersky, F-Secure, Bitdefender, and now Symantec. The site operated by the Bitdefender business partner in Portugal has also been compromised by the same group through SQL injection.

Antivirus vendors are not the only targets of the Romanian group of hackers. Yahoo! has also made the subject of attacks from them more than once, while “unu” has just recently disclosed a similar vulnerability on the website of the International Herald Tribune, the global edition of the New York Times.

Note: Read about Symantec's official response on the matter.

TAGS:

Symantec | SQL injection | database access | HackersBlog | data breach
Read by 5,869 user(s) | Add comment | Link to this article TWEET THIS


Article rating:
Excellent (4.8/5) 5 vote(s)    

Subscribe to news | Print article | Send to friend

© Copyright 2001-2009 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


International Herald Tribune SQL Injection

Bitdefender Hit Again by Romanian Hackers

F-Secure Joins the List of Compromised Antivirus Websites

Kaspersky Reveals Details of Attack on Its Website

Kaspersky and Bitdefender Websites Hacked

SQL Injection Malicious Tools Cost on Average $63

New Massive Wave of Web Hacks

BusinessWeek Victim of SQL Injection Attacks

User opinions:


Comment #1 by: trx on 19 Feb 2009, 09:31 GMT reply to this comment

symantec is really not reliable sometimes. Their antivirus cannot remove the USB autorun viruses.

Share your opinion:

Your Name:
Your Email Address:
(will not be used for commercial purposes)
Solve this to prove you're not a bot: =
Your review/opinion:

 




Windows tabGames tabDrivers tabMac tabLinux tabScripts tabMobile tabHandheld tabGadgets tabNews tab

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM