Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security > Hacking News

September 22nd, 2009, 10:00 GMT · By

The Internet Archive Leaks Member Data

SHARE:

Adjust text size:


Internet Archive website vulnerable to SQL injection
Enlarge picture
A hacker has disclosed an SQL injection vulnerability in the website of the Internet Archive project, which exposed sensitive information about registered members. The leaked data included personal details such as the e-mail address, names, home address, zip, city and state.

The vulnerability was discovered and reported by a prominent Romanian hacker going by the online handle of Unu. A self-proclaimed grey hat hacker, Unu is in the habit of searching and disclosing mainly SQL injection weaknesses in high-profile websites. Some of his recent reports involved websites belonging to the likes of Yahoo, the UK Parliament, ING Belgium, Dexia, HSBC France or WorldPay.

SQL injections are attacks that target a specific type of programming errors in Web applications in order to execute SQL queries into a website's underlying database. These vulnerabilities are the result of the failure to sanitize parameters passed to a script and can be exploited by simply manipulating the URL.

The Internet Archive is a project to build a digital library of digital content and the World Wide Web. The Web archive, called the Wayback Machine, stores periodical snapshots of web pages dating back to 1996, which can be browsed and viewed. Over 150 billion archived web pages are currently available through the Wayback Machine.

According to Unu's findings, the Internet Archive content is spread over 2,770 servers. The website allows users to register and obtain their own "virtual library cards." These accounts allow people to bookmark archives, write reviews, post in the forums, upload media, request researcher access and access other features.

At the moment of writing the article, the website had 802,261 registered users, including yours truly, and all of their account data was accessible through the SQL injection vulnerability. The data includes the screen name, e-mail address, hashed password and registration date and, for some members, their full, personal info is also available.

Judging from the screenshots published by Unu, the flaw was located in the Frequently Asked Questions (FAQ) section of the Internet Archive website. However, the Romanian hacker points out that he reported it to the webmaster and that it has been fixed.

TELL US WHAT YOU THINK:

1,745 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


RBS WorldPay Websites Riddled with Security Holes

Hacked: ING Belgium, Dexia and HSBC France Websites

Top Facebook Applications Vulnerable to XSS and SQLi

UK Parliament Website Hacked

Yahoo! Local Hacked

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM