Risk
11/19/2008
07:33 PM
Dark Reading
Dark Reading
Products and Releases
Connect Directly
RSS
E-Mail
50%
50%

LegitScript Shuts Down 500 No-Prescription-Required Online Pharmacies

Web sites fueling prescription drug abuse, selling non-FDA approved drugs taken offline

ARLINGTON, Va., Nov. 18 /PRNewswire/ -- LegitScript, an online pharmacy certification program, announced today that it has succeeded in getting nearly 500 "rogue" Internet pharmacy websites shut down.

The sites had been selling prescription drugs or steroids without requiring a prescription, a practice that is illegal and considered unsafe by medical authorities. In most cases, the drugs were sold from outside of the United States.

"The Internet is a safer place today because these illicit prescription drug websites have been terminated," said John Horton, LegitScript's President.

Among the domain name registrars to take the lead in shuttering the rogue Internet pharmacies was Directi. Horton praised the domain name registrars that terminated the rogue Internet pharmacies. "Directi, in particular, has been a leader in fighting rogue Internet pharmacies, and has steadily demonstrated its commitment to Internet safety by refusing to sponsor websites engaged in spam, malware, the illicit sale of prescription or other drugs, or similar activities."

The takedown also won praise from Internet safety proponents and prescription drug abuse experts. Susan Foster, Vice President at The National Center on Addiction and Substance Abuse at Columbia University (CASA), said, "CASA congratulates LegitScript for its successful shut down of hundreds of illegal Internet prescription drug trafficking sites. This work, done in cooperation with website registrars like Directi, provides a model that all website registrars should immediately adopt."

The websites were members of "online pharmacy affiliate programs" that allow people without any training as a pharmacist to operate their own online pharmacy and share in profits from the sale of prescription drugs without a valid prescription.

"Our family applauds the termination of these rogue online pharmacies," said Dan Pearson, whose son, Justin Pearson, overdosed and died after ordering drugs from a rogue Internet pharmacy. "Directi and other registrars that are taking a stand against these illicit Internet pharmacy affiliate networks are helping prevent future tragedies."

LegitScript is the largest online pharmacy verification service in the United States and has approved 185 online pharmacies as having met its baseline standards for legitimacy and safety. LegitScript does not accept payment or funding from the online pharmacies it reviews and approves.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Flash Poll
Current Issue
Cartoon
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-2227
Published: 2014-07-25
The default Flash cross-domain policy (crossdomain.xml) in Ubiquiti Networks UniFi Video (formerly AirVision aka AirVision Controller) before 3.0.1 does not restrict access to the application, which allows remote attackers to bypass the Same Origin Policy via a crafted SWF file.

CVE-2014-5027
Published: 2014-07-25
Cross-site scripting (XSS) vulnerability in Review Board 1.7.x before 1.7.27 and 2.0.x before 2.0.4 allows remote attackers to inject arbitrary web script or HTML via a query parameter to a diff fragment page.

CVE-2014-5100
Published: 2014-07-25
Multiple cross-site request forgery (CSRF) vulnerabilities in Omeka before 2.2.1 allow remote attackers to hijack the authentication of administrators for requests that (1) add a new super user account via a request to admin/users/add, (2) insert cross-site scripting (XSS) sequences via the api_key_...

CVE-2014-5101
Published: 2014-07-25
Multiple cross-site scripting (XSS) vulnerabilities in WeBid 1.1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) TPL_name, (2) TPL_nick, (3) TPL_email, (4) TPL_year, (5) TPL_address, (6) TPL_city, (7) TPL_prov, (8) TPL_zip, (9) TPL_phone, (10) TPL_pp_email, (11) TPL_authn...

CVE-2014-5102
Published: 2014-07-25
SQL injection vulnerability in vBulletin 5.0.4 through 5.1.3 Alpha 5 allows remote attackers to execute arbitrary SQL commands via the criteria[startswith] parameter to ajax/render/memberlist_items.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Sara Peters hosts a conversation on Botnets and those who fight them.