Powered By InformationWeek Business Technology Network
 
Welcome Guest. | Log In| Register | Membership Benefits
  • Email this page E-mail this page
  • |  Print Print this page
  • |   Bookmark and Share

Intel Website Hacked With SQL Injection

Hacker reveals major hole that exposes personal passport information on channel partner events Website

Dec 23, 2009 | 02:12 PM

By Kelly Jackson Higgins
DarkReading

A Romanian hacker who goes by the handle "unu" has struck again: This time, he demonstrated how a SQL injection vulnerability left personal information in the form of passports exposed on an Intel Website.

Unu, who previously exposed SQL injection vulnerabilities in The Wall Street Journal and Kaspersky Lab's Websites, this time focused on an Intel site that runs online registrations for channel partner events. The site, which is currently down, has a message posted that it's offline for maintenance.

An Intel spokesperson says the company has taken down the site and is "investigating the matter."

In his blog post on the Intel site's vulnerability, unu says: "Not only is the website vulnerable to sql injection but it also allows load_file to be executed making it very dangerous because with a little patience, a writable directory can be found and injection a malicious code we get command line access with wich we can do virtualy anything we want with the website: upload phpshells, redirects, INFECT PAGES WITH TROJAN DROPPERS, even deface the whole website."

Unu was able to hack into the front-end Web application and then discovered that server administrators had their passwords stored in clear text, according to the post.

"Intel is Intel, users' personal data is user personal data, so this vulnerability normally should not happen," he says.

Security experts at Praetorian Security Group who analyzed Unu's hack say most alarming about it is a screenshot that appears to show people who registered for an event, along with their passport numbers, birth dates, and credit card types. "Unu acknowledges that he simply is not showing the credit card numbers, expiration dates, and CW/CID codes but they are also in the table," they blogged.

Daniel Kennedy, a partner with Praetorian, says the site had been defaced before by someone else. "So Intel or the supporting vendor has to take a long look at who besides Unu could have been in that database," Kennedy says.

"Intel realistically has to notify everyone who could be affected ... this is passport and credit card data," he says.

Have a comment on this story? Please click "Discuss" below. If you'd like to contact Dark Reading's editors directly, send us a message.


Subscribe to RSS



Database Security Reports

report You've Been Breached: Responding to a Database Compromise
Criminals are after your corporate databases, and sometimes, despite your best efforts, they get in and steal credit card numbers, personally identifiable information, proprietary business data or sensitive intellectual property. What do you do then? In this Dark Reading Tech Center report, we discuss the basics of incident response; discovering what was breached, and how; and the best way to protect your assets going forward.

report Beyond the Database: Protecting Unstructured Data
Corporate databases may be the crown jewels, but unstructured data stores contain plenty of diamonds in the rough. Organizations can be burned by an exposed spreadsheet of credit card numbers, an e-mail with patient information or a file share containing reports on a pharmaceutical company's new wonder drug. In this Dark Reading Tech Center report, we show how to classify, find and protect unstructured data across the enterprise.

report Protecting Databases from Web Applications
Most external hacks of databases occur because of flaws in Web applications that link to those databases. Yet, enterprises are increasingly exposing their most valuable data to these outward-facing interfaces. In this Dark Reading Tech Center report, we'll discuss how security teams, database administrators and application developers can work together to improve the defenses of both front-end Web applications and back-end databases to prevent these attacks from succeeding, and offer a look at the most frequent Web-borne database attacks.

Other reports from the Database Security Tech Center:

Related Content

HOWTO Secure and Audit Oracle 10g and 11g
Read the "Hardening Your Database" chapter from the 454-page book "HOWTO Secure and Audit Oracle 10g and 11g" and learn how to navigate the many security options within Oracle (authored by database security expert and Guardium CTO, Ron Ben Natan, Ph.D.)

HOWTO Monitor Database Activity
Read the "Database Activity Monitoring (DAM)" chapter from "HOWTO Secure and Audit Oracle 10g and 11g" (CRC Press, 2009) and learn how to leverage DAM to prevent cyberattacks, monitor privileged users and track access to sensitive data.

8 Steps to Holistic Database Security
Get the 8 essential best practices for a holistic approach to both safeguarding databases and achieving compliance with key regulations such as SOX, PCI-DSS, NIST 800-53 and data protection laws.

Essential Steps to Implementing Database Security and Auditing
Learn best practices and specific tips for effectively securing Oracle, SQL Server, DB2, MySQL and Sybase environments, including tracking security vulnerabilities, the anatomy of buffer overflow vulnerabilities and database auditing.

Databases at Risk: Current State of Database Security (ESG Research)
This recently published ESG report analyzes the current state of database security -- concluding it depends upon too many manual processes -- and also offers concrete steps to improve database security across the enterprise.