Symantec falls as Romanian hacker strikes again

By Phil Muncaster
Nov 24, 2009 8:28 AM
Tags: symantec | hacker | security | web | access | customer

SQL injection attack exposes customer data.

The Romanian hacker who successfully broke into a web site owned by security vendor Kaspersky Lab has struck again, this time exposing shortcomings in a Symantec web server.

The hacker, known only as Unu, said in a blog post today that he was able to access a server belonging to the security giant using a blind SQL injection attack.

Once in, he accessed sensitive information including customer address data and catalogue keys on the Symantec Store database.

The hacker also expressed outrage that user passwords were displayed in plain text and had not been encrypted.

"A secured bad parameter allows full access to Symantec servers, allows access to many sensitive data stored on this server," wrote Unu.

"So, it seems quite strange how a company like Symantec, which sells software and security solutions, the famous Norton for example, wants to protect ourselves. Instead, it is not able to protect its own database."

Symantec has confirmed the vulnerability at pcd.symantec.com, a Norton support web site for customers in Japan and South Korea only.

"This incident impacts customer support in Japan and South Korea but does not affect the safety and usage of Symantec's Norton-branded consumer products," the firm said in a statement.

"Symantec is currently in the process of updating the web site with appropriate security measures, and will bring it back online as soon as possible. Symantec is still investigating the incident, and has no further details to share at this time."

  • Email a Friend
  • Print Page
Symantec falls as Romanian hacker strikes again
 

Copyright ©v3.co.uk

 


Comments

Be the first to comment on this article.
Thoughts on this article? Add a comment below.
Comment:
Want to participate in the discussion?
Or log in now to comment


Top Stories
A guided tour of Cisco's proof-of-concept centre
A data centre to test your customers' rigs.
 
Interview: Peter Kazacos and the "wild west" of IT
CRN talks to Hostech chairman and industry veteran, Peter Kazacos.
 
On the Move: March
Updated: Appointments and promotions.
 
Shortcutsall you need to know on...
  • How to run your business successfully 
  • NBN 
  • Windows 7 
  • Unified Communications 
  • Smart Power 
Latest Comments
"Informative post. thanks for the info shared here about the Cloud computing conference. Recently ..."
by shruthihr_80 Mar 20, 2010 10:37 PM
 
"Haha...What a sad little man JL must be. Whinges about the NBN now wants in on it, We don't want ..."
by firey1 Mar 20, 2010 4:56 PM
 
"Thanks Glen, I've made those corrections."
by sholtomacpherson Mar 19, 2010 10:33 AM
 
"This result is the law! It even applies to the small telco sellers in the mall of a shopping ..."
by peter Mar 18, 2010 9:10 PM
 
"Additionally, any small business with growth (and competition) on their mind would do well to ..."
by bld Mar 16, 2010 9:54 PM
Polls
Have you experienced a problem when returning faulty goods to online retailers?


   |   View results
Never
  40%
 
Only once
  10%
 
All the time
  50%
TOTAL VOTES: 10

Vote now
CRN Magazine

Issue: 277 | March, 2010

CRN Magazine looks in-depth at the emerging issues and developments for the Channel, and provides insight, analysis and strategic information to help resellers better run their businesses.