BitDefender partner site hit by hackers

Hackers elicited customer details from a Portuguese partner site associated with the security company BitDefender.

Hackers elicited customer details from a Portuguese partner site associated with the security company BitDefender, the second intrusion in recent days targeting computer security companies.

The details are posted on hackersblog.org, which publishes information on security problems but says it will notify Web site operators and not reveal sensitive data.

The hackers used a form of a SQL injection attack to reveal personal details and e-mail addresses. SQL injection, one of the most common types of attacks, involves inputting commands into Web-based forms or URLs (Uniform Resource Locators) in order to return data held in back-end databases.

A 2006 survey by the Web Application Security Consortium of 31,373 sites found more than 25 percent were vulnerable to SQL injection, with more than 85 percent vulnerable to cross-site scripting attacks.

Screenshots posted on the blog show how the hackers were able to see data they shouldn't, although they took care to black out sensitive data.

BitDefender said the site was shut down after the vulnerability was found, and reopened on Monday around 6 p.m. GMT. BitDefender believes that none of the data exposed will be used for malicious purposes and that the attack was intended to illustrate the vulnerability. No customer credit card data was stored on the site, the company said.

BitDefender said it advises partners on good security practices but that "we can't control how our partners manage their sites."

Major computer security companies have seen their sites come under attack, highlighting how even organizations with deep knowledge of the dangers of hacking can still be caught off guard.

Last weekend, a hacker broke into part of Russian security company Kaspersky Lab's new U.S. support Web site. Company officials confirmed a programming flaw left the site open to SQL injection. The hacker could have accessed about 2,500 customer e-mail addresses and perhaps 25,000 product activation codes.

In July 2008, a Malaysian partner site for Kaspersky was defaced as it was still under development, although no sensitive data was lost.

Join the newsletter!

Or

Sign up to gain exclusive access to email subscriptions, event invitations, competitions, giveaways, and much more.

Membership is free, and your security and privacy remain protected. View our privacy policy before signing up.

Error: Please check your email address.

Tags hackbitdefender

Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Jeremy Kirk

IDG News Service
Show Comments

Father’s Day Gift Guide

Brand Post

Most Popular Reviews

Latest Articles

Resources

PCW Evaluation Team

Luke Hill

MSI GT75 TITAN

I need power and lots of it. As a Front End Web developer anything less just won’t cut it which is why the MSI GT75 is an outstanding laptop for me. It’s a sleek and futuristic looking, high quality, beast that has a touch of sci-fi flare about it.

Emily Tyson

MSI GE63 Raider

If you’re looking to invest in your next work horse laptop for work or home use, you can’t go wrong with the MSI GE63.

Laura Johnston

MSI GS65 Stealth Thin

If you can afford the price tag, it is well worth the money. It out performs any other laptop I have tried for gaming, and the transportable design and incredible display also make it ideal for work.

Andrew Teoh

Brother MFC-L9570CDW Multifunction Printer

Touch screen visibility and operation was great and easy to navigate. Each menu and sub-menu was in an understandable order and category

Louise Coady

Brother MFC-L9570CDW Multifunction Printer

The printer was convenient, produced clear and vibrant images and was very easy to use

Edwina Hargreaves

WD My Cloud Home

I would recommend this device for families and small businesses who want one safe place to store all their important digital content and a way to easily share it with friends, family, business partners, or customers.

Featured Content

Product Launch Showcase

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?