Attacks/Breaches

2/26/2008
06:53 AM
50%
50%

Hacker Steals Data on 18M Auction Customers in South Korea

Chinese attacker asks for ransom on data, reports say

South Korea’s largest online shopping site earlier this month was attacked by a Chinese hacker who made off with the user information on 18 million members and a large amount of financial data.

According to reports on Hack in the Box and the Web Application Security Consortium Incident Report, Auction.co.kr has disclosed the theft of data from some 18 million buyers and sellers.

The attack was launched from China's internet. After the incident, Auction.co.kr received a phone call offering to exchange the user information for money, the reports said.

According to a report on Dark Visitor, a security blog site, the Chinese hacker did not directly attack the server. The hacker sent out bulk emailings to the auction staff containing “hacker procedures" that may have contained malware. When the staff members confirmed the emails, the hacker was able to gain their IDs. The hacker was then able to log into the Auction server using the staffer’s ID.

The WASC report categorizes the exploit as a cross-site request forgery attack. "The attack description is vague, but can be best described as session hijacking," the organization said.

Auction.co.kr waited 20 hours after the attack before confirming the loss of information, according to the Chinese site Hackbase.com. Korean users rebuked the Website for being too slow to act, the reports said.

The incident occurred around Feb. 12, but it has gone largely unreported. "In the U.S. this would be front news," the WASC report said. "We don't know if it was front news in Korea, but it did not get to the international media." Most of the reports on the incident have been in Korean, which make it difficult for English speaking researchers and media to report it, WASC observed.

Have a comment on this story? Please click "Discuss" below. If you'd like to contact Dark Reading's editors directly, send us a message.

Tim Wilson is Editor in Chief and co-founder of Dark Reading.com, UBM Tech's online community for information security professionals. He is responsible for managing the site, assigning and editing content, and writing breaking news stories. Wilson has been recognized as one ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
WebAuthn, FIDO2 Infuse Browsers, Platforms with Strong Authentication
John Fontana, Standards & Identity Analyst, Yubico,  9/19/2018
Turn the NIST Cybersecurity Framework into Reality: 5 Steps
Mukul Kumar & Anupam Sahai, CISO & VP of Cyber Practice and VP Product Management, Cavirin Systems,  9/20/2018
NSS Labs Files Antitrust Suit Against Symantec, CrowdStrike, ESET, AMTSO
Kelly Jackson Higgins, Executive Editor at Dark Reading,  9/19/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: "I'm not sure I like this top down management approach!"
Current Issue
Flash Poll
The Risk Management Struggle
The Risk Management Struggle
The majority of organizations are struggling to implement a risk-based approach to security even though risk reduction has become the primary metric for measuring the effectiveness of enterprise security strategies. Read the report and get more details today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-17338
PUBLISHED: 2018-09-23
An issue has been found in pdfalto through 0.2. It is a heap-based buffer overflow in the function TextPage::dump in XmlAltoOutputDev.cc.
CVE-2018-17341
PUBLISHED: 2018-09-23
BigTree 4.2.23 on Windows, when Advanced or Simple Rewrite routing is enabled, allows remote attackers to bypass authentication via a ..\ substring, as demonstrated by a launch.php?bigtree_htaccess_url=admin/images/..\ URI.
CVE-2018-17332
PUBLISHED: 2018-09-22
An issue was discovered in libsvg2 through 2012-10-19. The svgGetNextPathField function in svg_string.c returns its input pointer in certain circumstances, which might result in a memory leak caused by wasteful malloc calls.
CVE-2018-17333
PUBLISHED: 2018-09-22
An issue was discovered in libsvg2 through 2012-10-19. A stack-based buffer overflow in svgStringToLength in svg_types.c allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact because sscanf is misused.
CVE-2018-17334
PUBLISHED: 2018-09-22
An issue was discovered in libsvg2 through 2012-10-19. A stack-based buffer overflow in the svgGetNextPathField function in svg_string.c allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact because a strncpy copy limit is miscalculated.