<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0" xml:base="http://www.xiom.com/whid-rss">
  <channel>
    <title>List of Web Hacking Incidents</title>
    <link>http://www.xiom.com/whid-rss</link>
    <description />
    <language>en</language>
          <atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" href="http://feeds.feedburner.com/TheWebHackingIncidentsDatabase" type="application/rss+xml" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com" /><item>
    <title>WHID 2009-45: Outcome: Death</title>
    <link>http://feedproxy.google.com/~r/TheWebHackingIncidentsDatabase/~3/2QoGfEkVsvY/outcome_death</link>
    <description>&lt;div class="field field-type-date field-field-updated"&gt;
    &lt;div class="field-items"&gt;
            &lt;div class="field-item odd"&gt;
                      &lt;div class="field-label-inline-first"&gt;
              Updated:&amp;nbsp;&lt;/div&gt;
                    &lt;span class="date-display-single"&gt;8 June 2009&lt;/span&gt;        &lt;/div&gt;
        &lt;/div&gt;
&lt;/div&gt;
&lt;p&gt;This must be the worse incident reported by the Web Hacking Incident Database.&lt;/p&gt;
&lt;p&gt;We all know that web security is highly important but neglected. We tell frightening stories but listners think they are only "FUD": fear, uncertainty and doubt, used to sell products and services. I hope that the VAServ incident will serve to warn that those are not fairytale stories. Even so, I wish this one would not have happened.&lt;/p&gt;
&lt;p&gt;In this story, like most calamities, it seems that the laymen suffer: small entrepreneurs &amp;amp; upstart companies who lost everything in a hacking incident. One of them even lost his life.&lt;/p&gt;
&lt;table style="height: 141px; width: 50%;" border="1" align="right"&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td style="background-color: #faebd7;"&gt;&lt;strong&gt;&lt;span style="font-size: small;"&gt;Vaserv web site reporting recovery status, June 10&lt;sup&gt;th&lt;/sup&gt;:&lt;/span&gt;&lt;/strong&gt;&lt;br /&gt; &lt;span style="font-size: xx-small;"&gt;22:19 vz47uk restored&lt;br /&gt; 22:21 vz46uk data loss&lt;br /&gt; 22:42 Please allow upto 2 hours for a ticket response as currently we have 200+ active tickets&lt;br /&gt; 23:02 vz67uk data loss&lt;br /&gt; 23:20 vz50uk data restored&lt;br /&gt; 23:23 vz51uk data loss&lt;br /&gt;00:03 FsckVPS server26 and server27 are still being worked on, but data *appears* to be intact&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;It all started on Sunday, June 7&lt;sup&gt;th&lt;/sup&gt;: someone broke into the web servers of VAServ, a tiny UK based hosting company. The hackers ruined many of VAServ virtual servers. Some of them lost were for ever as the snippet from VAServ home page, serving as an emergency bulletin board, shows.&lt;/p&gt;
&lt;p&gt;As tiny as VAServ is, probably no more than 3 people, in today's virtual and flat world they could serve tens of thousands of low cost web sites, many of them now lost for ever. Behind each one of these web sites there is a story of someone who worked hard, whether on a hobby or a small business and is now left with nothing. A comment made on one of the blog entries about the incident reads:&lt;/p&gt;
&lt;p style="padding-left: 30px;"&gt;&lt;em&gt;"yeah thanks for ruining my life for the last 2 years i had built up my site spending alot of money and giving up my job for nothing.........what am i going to tell the wife?"&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;Just think about tens of thousand of such stories. Daniel Voyce, a web developer using VAServ for all of his clients, told the &lt;a href="http://www.theregister.co.uk/2009/06/08/webhost_attack/"&gt;Register: &lt;/a&gt;&lt;/p&gt;
&lt;p style="padding-left: 30px;"&gt;&lt;em&gt;"Since last night, I've had probably 40 phone calls from clients saying 'Why is my website down, It's making me look bad."&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;But this domino effect ruining so many small businesses had another even more devastating angle. Just days before the hack, someone &lt;a href="http://www.milw0rm.com/exploits/8880"&gt;posted on milw0rm&lt;/a&gt; a long list of yet unpatched vulnerabilities in Kloxo, a virtual machine management software. The list certainly looks comprehensive enough to enable anyone to penetrate a site using Kloxo, which VAServ where, leading VAServ and others to believe that LxLabs, the Bangalorian software company behind Kloxo is the culprit. Somebody claiming to be the hacker &lt;a href="http://www.inquisitr.com/25617/update-new-information-on-the-vaserv-hack-that-wiped-100k-sites/"&gt;commented to the inquistir blog&lt;/a&gt;, claiming that weak password at VAServ where to blame for the hack, which &lt;a href="http://www.theregister.co.uk/2009/06/10/vaserv_follow_up/"&gt;Rus Foster from VAServ denied&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;We may never know who is right and who is wrong. LxLabs, just like Vaserv, is a tiny company using the Internet to look big. However one area that suffers a lot in small companies, is their security. It is never important enough to invest resource in security in such a lean and mean operations.&lt;/p&gt;
&lt;p&gt;&lt;img src="http://www.xiom.com/sites/default/files/ligesh.jpg" width="179" height="206" style="float: right;" /&gt;But tiny giants have another weakness: it all falls on the shoulders of too few people. In the case of LxLabs, on &lt;a href="http://timesofindia.indiatimes.com/Bangalore/Techie-hangs-himself-in-HSR-Layout-/articleshow/4633101.cms"&gt;KT Ligesh the CEO&lt;/a&gt;. Ligesh&lt;a href="http://timesofindia.indiatimes.com/Bangalore/Techie-hangs-himself-in-HSR-Layout-/articleshow/4633101.cms"&gt; committed suicide&lt;/a&gt; just a day after the hack for which his company was blamed. While already a troubled person, one cannot escape the thought that the hacking incident was the last straw.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?a=2QoGfEkVsvY:ayam8OsbB_E:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?a=2QoGfEkVsvY:ayam8OsbB_E:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?i=2QoGfEkVsvY:ayam8OsbB_E:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?a=2QoGfEkVsvY:ayam8OsbB_E:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?i=2QoGfEkVsvY:ayam8OsbB_E:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/TheWebHackingIncidentsDatabase/~4/2QoGfEkVsvY" height="1" width="1"/&gt;</description>
     <comments>http://www.xiom.com/whid/2009/45/outcome_death#comments</comments>
 <pubDate>Wed, 10 Jun 2009 20:32:49 +0000</pubDate>
 <dc:creator>Ofer Shezaf</dc:creator>
 <guid isPermaLink="false">463 at http://www.xiom.com</guid>
  <feedburner:origLink>http://www.xiom.com/whid/2009/45/outcome_death</feedburner:origLink></item>
  <item>
    <title>WHID 2009-43: Web Mail Company to Pay Prize After CEO Hacked</title>
    <link>http://feedproxy.google.com/~r/TheWebHackingIncidentsDatabase/~3/7uBwU9NhoPw/StrongWebMail_XSS</link>
    <description>&lt;div class="field field-type-date field-field-updated"&gt;
    &lt;div class="field-items"&gt;
            &lt;div class="field-item odd"&gt;
                      &lt;div class="field-label-inline-first"&gt;
              Updated:&amp;nbsp;&lt;/div&gt;
                    &lt;span class="date-display-single"&gt;5 June 2009&lt;/span&gt;        &lt;/div&gt;
        &lt;/div&gt;
&lt;/div&gt;
&lt;p&gt;What does a &lt;a href="http://www.strongwebmail.com/secure/email/contests/hack/tc"&gt;challenge &lt;/a&gt;to break an web mail system and get $10,000, &lt;a href="http://blogs.zdnet.com/security/?p=3514"&gt;broken within minutes&lt;/a&gt; prove? Is it a lesson in vanity? Or about the state of web security? Or about security in general. Probably all.&lt;/p&gt;
&lt;p&gt;The most obvious observatoins is that offering $10,000 for anyone who can break your site and being broken within an hour shows that you don't know what you taking about. Maybe it would be a lesson to all security vendors to not believe their own marketing verbiage. A quick browse of the &lt;a href="http://www.securityfocus.com/bid"&gt;bugtraq vulnerability archives&lt;/a&gt; will show how insecure and easy to evade security products can be.&lt;/p&gt;
&lt;p&gt;However, judging from the number and seriousness of the incidents reported on the &lt;a href="http://www.xiom.com/whid"&gt;web hacking incidents database, &lt;/a&gt;StrongWebmail is not alone and far stronger companies suffers severe incidents, making web applications the weakest link in an organizations information security.&lt;/p&gt;
&lt;p&gt;Lastly, we should always remember that there is never perfect security. By making systems more secure we are just raising the price required to attack them and lowering the damage of such an attack, but never. As the old joke goes: the only secure system is one without users.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?a=7uBwU9NhoPw:ROY6A-lAd-A:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?a=7uBwU9NhoPw:ROY6A-lAd-A:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?i=7uBwU9NhoPw:ROY6A-lAd-A:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?a=7uBwU9NhoPw:ROY6A-lAd-A:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?i=7uBwU9NhoPw:ROY6A-lAd-A:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/TheWebHackingIncidentsDatabase/~4/7uBwU9NhoPw" height="1" width="1"/&gt;</description>
     <comments>http://www.xiom.com/whid/2009/43/StrongWebMail_XSS#comments</comments>
 <pubDate>Wed, 10 Jun 2009 15:14:40 +0000</pubDate>
 <dc:creator>Ofer Shezaf</dc:creator>
 <guid isPermaLink="false">461 at http://www.xiom.com</guid>
  <feedburner:origLink>http://www.xiom.com/whid/2009/43/StrongWebMail_XSS</feedburner:origLink></item>
  <item>
    <title>WHID 2009-42: Puerto Rico sites redirected in a DNS attack</title>
    <link>http://feedproxy.google.com/~r/TheWebHackingIncidentsDatabase/~3/fatFf6g-rWI/Puerto_Rico_DNS_SQL_Injection</link>
    <description>&lt;div class="field field-type-date field-field-updated"&gt;
    &lt;div class="field-items"&gt;
            &lt;div class="field-item odd"&gt;
                      &lt;div class="field-label-inline-first"&gt;
              Updated:&amp;nbsp;&lt;/div&gt;
                    &lt;span class="date-display-single"&gt;10 June 2009&lt;/span&gt;        &lt;/div&gt;
        &lt;/div&gt;
&lt;/div&gt;
&lt;p&gt;Attacking web sites by going to the source, targeting DNS servers rather than the web sites themselves shows both the boldness of hackers as well as the fragility of the Internet.&lt;/p&gt;
&lt;p&gt;While not new, DNS hijacking attacks took an important turn this year showing how much we rely on the web and now little we care for its protection. In the past DNS hijacking required complete control over the DNS server. In recent years most applications are controlled through a web interface, including DNS servers. Earlier this year attackers found an &lt;a href="http://www.xiom.com/whid/2009/24/new_phishing_attacks_combine_wildcard_dns_and_xss"&gt;XSS vulnerability in a common DNS platform&lt;/a&gt; to hijack unused DNS entries for phishing&lt;/p&gt;
&lt;p&gt;But this was only a small prelude to the real thing. &lt;a href="http://news.cnet.com/8301-1009_3-10228436-83.html"&gt;CNet reports &lt;/a&gt;that this time hackers took over an entire TLD (Top Level Domain, or country) DNS server using SQL injection, virtually defacing the Puerto Rican site of companies such as Google and Microsoft.&lt;/p&gt;
&lt;p&gt;The amazing story unfolds in the comments to CNet story, which outlines a mischievous professor and slow authorities who let him privatize and monetize on domain registration in Puerto Rico without any control.&lt;/p&gt;
&lt;p&gt;The question we are left with is whether other countries and geographies different? Or even other industries for that matter?&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?a=fatFf6g-rWI:GgTL4oCZayM:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?a=fatFf6g-rWI:GgTL4oCZayM:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?i=fatFf6g-rWI:GgTL4oCZayM:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?a=fatFf6g-rWI:GgTL4oCZayM:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?i=fatFf6g-rWI:GgTL4oCZayM:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/TheWebHackingIncidentsDatabase/~4/fatFf6g-rWI" height="1" width="1"/&gt;</description>
     <comments>http://www.xiom.com/whid/2009/42/Puerto_Rico_DNS_SQL_Injection#comments</comments>
 <pubDate>Wed, 10 Jun 2009 14:31:02 +0000</pubDate>
 <dc:creator>Ofer Shezaf</dc:creator>
 <guid isPermaLink="false">460 at http://www.xiom.com</guid>
  <feedburner:origLink>http://www.xiom.com/whid/2009/42/Puerto_Rico_DNS_SQL_Injection</feedburner:origLink></item>
  <item>
    <title>WHID 2009-41: Malware in Advertizing at Digital Spy</title>
    <link>http://feedproxy.google.com/~r/TheWebHackingIncidentsDatabase/~3/aXS8iMbhw-o/Ad_Malware_on_Digital_Spy</link>
    <description>&lt;div class="field field-type-date field-field-updated"&gt;
    &lt;div class="field-items"&gt;
            &lt;div class="field-item odd"&gt;
                      &lt;div class="field-label-inline-first"&gt;
              Updated:&amp;nbsp;&lt;/div&gt;
                    &lt;span class="date-display-single"&gt;3 June 2009&lt;/span&gt;        &lt;/div&gt;
        &lt;/div&gt;
&lt;/div&gt;
&lt;p&gt;The register &lt;a href="http://www.theregister.co.uk/2009/06/02/digital_spy_malware/"&gt;reports &lt;/a&gt;that Digital Spy, a high profile UK gossip site carried banner inflicting ads. Digital Spy has acknowledged the issue and said it promptly addressed it, however details on the source of the malicious banners is still not availalbe.&lt;/p&gt;
&lt;p&gt;Malware distribution through ad programs is a borderline phenomenon. While there is no question that malware distribucion is malicious, and in most geographies illegal, in many cases the site owners are not technically responsible for the content of the ads they serve&amp;nbsp; as the ad content comes directly from a 3&lt;sup&gt;rd&lt;/sup&gt; party. The question whether they are legally responsible is open.&lt;/p&gt;
&lt;p&gt;Another issue is defining a malware. Many times ads are used to entice users to download and install programs that are questionable. a rootkit installed through a known browser vulnerability is a malware, however the distinction between adware and malware is many time blurred and depends on:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;The ratio between benefit to the user and benefit to the software distributor, &lt;/li&gt;
&lt;li&gt;The clarity in which the benefit to the software distributor is explained to the user, and lastly:&lt;/li&gt;
&lt;li&gt;The legality of this benefit&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?a=aXS8iMbhw-o:niyTgoflrxs:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?a=aXS8iMbhw-o:niyTgoflrxs:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?i=aXS8iMbhw-o:niyTgoflrxs:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?a=aXS8iMbhw-o:niyTgoflrxs:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?i=aXS8iMbhw-o:niyTgoflrxs:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/TheWebHackingIncidentsDatabase/~4/aXS8iMbhw-o" height="1" width="1"/&gt;</description>
     <comments>http://www.xiom.com/whid/2009/41/Ad_Malware_on_Digital_Spy#comments</comments>
 <pubDate>Wed, 03 Jun 2009 09:51:26 +0000</pubDate>
 <dc:creator>Ofer Shezaf</dc:creator>
 <guid isPermaLink="false">459 at http://www.xiom.com</guid>
  <feedburner:origLink>http://www.xiom.com/whid/2009/41/Ad_Malware_on_Digital_Spy</feedburner:origLink></item>
  <item>
    <title>WHID 2009-40: SQL injection Hits Sensitive US Army servers</title>
    <link>http://feedproxy.google.com/~r/TheWebHackingIncidentsDatabase/~3/DZhrQzxYC60/US_army_SQL_injection</link>
    <description>&lt;div class="field field-type-date field-field-updated"&gt;
    &lt;div class="field-items"&gt;
            &lt;div class="field-item odd"&gt;
                      &lt;div class="field-label-inline-first"&gt;
              Updated:&amp;nbsp;&lt;/div&gt;
                    &lt;span class="date-display-single"&gt;31 May 2009&lt;/span&gt;        &lt;/div&gt;
        &lt;/div&gt;
&lt;/div&gt;
&lt;p&gt;Information Week &lt;a href="http://www.informationweek.com/news/government/federal/showArticle.jhtml?articleID=217700619"&gt;reports &lt;/a&gt;that a well known Turkish hacker penetrated two sensitive US army servers, one at McAlester Ammunition Plant in McAlester, Okla., and the other at the U.S. Army Corps of Engineers' Transatlantic Center in Winchester, Va. The hacks are the currently under criminal investigation by Defense Department officials.&lt;/p&gt;
&lt;p&gt;The breaches where not publicly disclosed and the level of exposure is therefore not known. It is known however that web site visitors where redirected to a site protesting against climate change.&lt;/p&gt;
&lt;p&gt;The Register &lt;a href="http://www.theregister.co.uk/2009/05/29/army_website_breaches/"&gt;speculates &lt;/a&gt;that the attack method was SQL injection.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?a=DZhrQzxYC60:clxmGFH0r9o:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?a=DZhrQzxYC60:clxmGFH0r9o:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?i=DZhrQzxYC60:clxmGFH0r9o:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?a=DZhrQzxYC60:clxmGFH0r9o:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?i=DZhrQzxYC60:clxmGFH0r9o:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/TheWebHackingIncidentsDatabase/~4/DZhrQzxYC60" height="1" width="1"/&gt;</description>
     <comments>http://www.xiom.com/whid/2009/40/US_army_SQL_injection#comments</comments>
 <pubDate>Sun, 31 May 2009 12:22:11 +0000</pubDate>
 <dc:creator>Ofer Shezaf</dc:creator>
 <guid isPermaLink="false">457 at http://www.xiom.com</guid>
  <feedburner:origLink>http://www.xiom.com/whid/2009/40/US_army_SQL_injection</feedburner:origLink></item>
  <item>
    <title>WHID 2009-39: Uno is back: 245,000 records stolen from Orange France using SQL injection</title>
    <link>http://feedproxy.google.com/~r/TheWebHackingIncidentsDatabase/~3/AlxBG9XgpE0/orange-france-sqlinjection</link>
    <description>&lt;div class="field field-type-date field-field-updated"&gt;
    &lt;div class="field-items"&gt;
            &lt;div class="field-item odd"&gt;
                      &lt;div class="field-label-inline-first"&gt;
              Updated:&amp;nbsp;&lt;/div&gt;
                    &lt;span class="date-display-single"&gt;26 May 2009&lt;/span&gt;        &lt;/div&gt;
        &lt;/div&gt;
&lt;/div&gt;
&lt;p&gt;After focusing earlier this year on Anti-Virus vendors, Uno, the Romanian Hacker is now back and &lt;a href="http://www.hackersblog.org/2009/05/25/orange-is-so-cool/"&gt;reports in his blog&lt;/a&gt; that an Orange France web site dedicated to photo management is vulnerable to SQL injection and that he was able to access 245,000 records from the web site.&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?a=AlxBG9XgpE0:5G_lvJQwKHU:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?a=AlxBG9XgpE0:5G_lvJQwKHU:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?i=AlxBG9XgpE0:5G_lvJQwKHU:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?a=AlxBG9XgpE0:5G_lvJQwKHU:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?i=AlxBG9XgpE0:5G_lvJQwKHU:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/TheWebHackingIncidentsDatabase/~4/AlxBG9XgpE0" height="1" width="1"/&gt;</description>
     <comments>http://www.xiom.com/whid/2009/39/orange-france-sqlinjection#comments</comments>
 <category domain="http://www.xiom.com/taxonomy/term/238">e-mail</category>
 <category domain="http://www.xiom.com/taxonomy/term/229">Name</category>
 <category domain="http://www.xiom.com/taxonomy/term/232">Password</category>
 <category domain="http://www.xiom.com/taxonomy/term/233">User name</category>
 <pubDate>Tue, 26 May 2009 14:36:04 +0000</pubDate>
 <dc:creator>Ofer Shezaf</dc:creator>
 <guid isPermaLink="false">456 at http://www.xiom.com</guid>
  <feedburner:origLink>http://www.xiom.com/whid/2009/39/orange-france-sqlinjection</feedburner:origLink></item>
  <item>
    <title>WHID 2009-38: Time's Poll For Most Influencial Hacked</title>
    <link>http://feedproxy.google.com/~r/TheWebHackingIncidentsDatabase/~3/tR1W3I83u2w/time_poll_hacking</link>
    <description>&lt;div class="field field-type-date field-field-updated"&gt;
    &lt;div class="field-items"&gt;
            &lt;div class="field-item odd"&gt;
                      &lt;div class="field-label-inline-first"&gt;
              Updated:&amp;nbsp;&lt;/div&gt;
                    &lt;span class="date-display-single"&gt;19 April 2009&lt;/span&gt;        &lt;/div&gt;
        &lt;/div&gt;
&lt;/div&gt;
&lt;div class="field field-type-text field-field-teaser"&gt;
    &lt;div class="field-items"&gt;
            &lt;div class="field-item odd"&gt;
                    &lt;p&gt;Polls are easy target for automation abuse. You can usually participate anonymously and the poll operator has an interest in drawing as many participants as possible, but as &lt;a href="http://www.xiom.com/whid-2009-3"&gt;demonstrated by previous incidents&lt;/a&gt; such loose security enables hackers to distort the results.&lt;/p&gt;
&lt;p&gt;This time a &lt;span&gt;hacker&lt;/span&gt; &lt;span&gt;succeeded&lt;/span&gt; in manipulating &lt;span&gt;Time's&lt;/span&gt; poll for most &lt;span&gt;influential&lt;/span&gt; people in 2009.&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.xiom.com/whid/2009/38/time_poll_hacking"&gt;Read more...&lt;/a&gt;&lt;/p&gt;
        &lt;/div&gt;
        &lt;/div&gt;
&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?a=tR1W3I83u2w:S3rLGzrNf3Y:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?a=tR1W3I83u2w:S3rLGzrNf3Y:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?i=tR1W3I83u2w:S3rLGzrNf3Y:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?a=tR1W3I83u2w:S3rLGzrNf3Y:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?i=tR1W3I83u2w:S3rLGzrNf3Y:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/TheWebHackingIncidentsDatabase/~4/tR1W3I83u2w" height="1" width="1"/&gt;</description>
     <comments>http://www.xiom.com/whid/2009/38/time_poll_hacking#comments</comments>
 <pubDate>Sun, 19 Apr 2009 08:17:12 +0000</pubDate>
 <dc:creator>Ofer Shezaf</dc:creator>
 <guid isPermaLink="false">447 at http://www.xiom.com</guid>
  <feedburner:origLink>http://www.xiom.com/whid/2009/38/time_poll_hacking</feedburner:origLink></item>
  <item>
    <title>WHID 2009-37: Twitter XSS/CSRF worm series (Updated)</title>
    <link>http://feedproxy.google.com/~r/TheWebHackingIncidentsDatabase/~3/SP664kWbFaM/twitter_csrf_xss</link>
    <description>&lt;div class="field field-type-date field-field-updated"&gt;
    &lt;div class="field-items"&gt;
            &lt;div class="field-item odd"&gt;
                      &lt;div class="field-label-inline-first"&gt;
              Updated:&amp;nbsp;&lt;/div&gt;
                    &lt;span class="date-display-single"&gt;19 April 2009&lt;/span&gt;        &lt;/div&gt;
        &lt;/div&gt;
&lt;/div&gt;
&lt;div class="field field-type-text field-field-teaser"&gt;
    &lt;div class="field-items"&gt;
            &lt;div class="field-item odd"&gt;
                    &lt;p&gt;Twitter is in the spotlights again. &lt;span&gt;&lt;span&gt;Mikeyy&lt;/span&gt;&lt;/span&gt; Mooney, the 17-year-old creator of &lt;span&gt;&lt;span&gt;StalkDaily&lt;/span&gt;&lt;/span&gt;.com, a Twitter alternative, &lt;a href="http://www.bnonews.com/news/242.html"&gt;admitted &lt;/a&gt;to hacking his giant competitor by implementing a series of worms. The first one propagated itself through twitter making every affected user tweet about &lt;span&gt;&lt;span&gt;StalkDaily&lt;/span&gt;&lt;/span&gt;.&lt;span&gt; &lt;span&gt;Mikeyy&lt;/span&gt; certainly got the advertising and page views he was looking for. Even more, Mookey even got a job as a security analyst following the worm series.&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;&lt;span&gt;Mikeyy's&lt;/span&gt; worms are a good example of how CSRF and XSS can be combined to create a strong blended attack,&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;&lt;a href="http://www.xiom.com/whid/2009/37/twitter_csrf_xss"&gt;Read more...&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;
        &lt;/div&gt;
        &lt;/div&gt;
&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?a=SP664kWbFaM:_TRqznxTZYA:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?a=SP664kWbFaM:_TRqznxTZYA:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?i=SP664kWbFaM:_TRqznxTZYA:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?a=SP664kWbFaM:_TRqznxTZYA:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?i=SP664kWbFaM:_TRqznxTZYA:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/TheWebHackingIncidentsDatabase/~4/SP664kWbFaM" height="1" width="1"/&gt;</description>
     <comments>http://www.xiom.com/whid/2009/37/twitter_csrf_xss#comments</comments>
 <pubDate>Fri, 17 Apr 2009 20:41:13 +0000</pubDate>
 <dc:creator>Ofer Shezaf</dc:creator>
 <guid isPermaLink="false">443 at http://www.xiom.com</guid>
  <feedburner:origLink>http://www.xiom.com/whid/2009/37/twitter_csrf_xss</feedburner:origLink></item>
  <item>
    <title>WHID 2009-36: Hackers steal Austalian and NZ Shell customer info (Updated)</title>
    <link>http://feedproxy.google.com/~r/TheWebHackingIncidentsDatabase/~3/6-sttL2QXsc/shell_au_hacking</link>
    <description>&lt;div class="field field-type-date field-field-updated"&gt;
    &lt;div class="field-items"&gt;
            &lt;div class="field-item odd"&gt;
                      &lt;div class="field-label-inline-first"&gt;
              Updated:&amp;nbsp;&lt;/div&gt;
                    &lt;span class="date-display-single"&gt;19 April 2009&lt;/span&gt;        &lt;/div&gt;
        &lt;/div&gt;
&lt;/div&gt;
&lt;p&gt;&lt;em&gt;&lt;strong&gt;Update (Apr 19&lt;sup&gt;th&lt;/sup&gt; 2009)&lt;/strong&gt;&lt;/em&gt; - (Presumably) the hacker posted a comment to this story with some details. He says that the number of records leaking was much higher: 17,000 Aussies and 7,000 Kiwis. The rest we did not understand and hope that either he or any of you can clarify.&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.xiom.com/whid/2009/36/shell_au_hacking"&gt;Read more...&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;hr /&gt;
Leakage of information from an energy company is usually associated with gas stations fraud such as installing a stealth credit card reader at the pump. However, a &lt;a href="http://www.stuff.co.nz/national/2269256/Hackers-steal-Shell-customer-info"&gt;report&lt;/a&gt; suggests that an incident in which information about 4500 Australian and 1400 Kiwis leaked was a result of  a glitch in a web based application for applying for a Shell fuel card. The information obtained included company names, address details, email addresses and some bank account details.&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?a=6-sttL2QXsc:xmKg1X5TWFw:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?a=6-sttL2QXsc:xmKg1X5TWFw:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?i=6-sttL2QXsc:xmKg1X5TWFw:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?a=6-sttL2QXsc:xmKg1X5TWFw:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?i=6-sttL2QXsc:xmKg1X5TWFw:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/TheWebHackingIncidentsDatabase/~4/6-sttL2QXsc" height="1" width="1"/&gt;</description>
     <comments>http://www.xiom.com/whid/2009/36/shell_au_hacking#comments</comments>
 <category domain="http://www.xiom.com/taxonomy/term/227">Address</category>
 <category domain="http://www.xiom.com/taxonomy/term/222">Bank Account Number</category>
 <category domain="http://www.xiom.com/taxonomy/term/239">Company Name</category>
 <category domain="http://www.xiom.com/taxonomy/term/238">e-mail</category>
 <pubDate>Thu, 09 Apr 2009 20:26:56 +0000</pubDate>
 <dc:creator>Ofer Shezaf</dc:creator>
 <guid isPermaLink="false">441 at http://www.xiom.com</guid>
  <feedburner:origLink>http://www.xiom.com/whid/2009/36/shell_au_hacking</feedburner:origLink></item>
  <item>
    <title>WHID 2009-35: Former US Senator Donors Information Leaks</title>
    <link>http://feedproxy.google.com/~r/TheWebHackingIncidentsDatabase/~3/6UOCNifUCqk/seantor_donors_leak</link>
    <description>&lt;div class="field field-type-date field-field-updated"&gt;
    &lt;div class="field-items"&gt;
            &lt;div class="field-item odd"&gt;
                      &lt;div class="field-label-inline-first"&gt;
              Updated:&amp;nbsp;&lt;/div&gt;
                    &lt;span class="date-display-single"&gt;17 March 2009&lt;/span&gt;        &lt;/div&gt;
        &lt;/div&gt;
&lt;/div&gt;
&lt;div class="field field-type-text field-field-teaser"&gt;
    &lt;div class="field-items"&gt;
            &lt;div class="field-item odd"&gt;
                    &lt;p&gt;Norm Coleman, a former senator from Minnesota, is going through a legal battle to try to win back his seat in the senate. If the way he manages his web site security and the crises it created are an indicator, I am not sure that he has a place there.&lt;/p&gt;
&lt;p&gt;&lt;a href="/whid/2009/35/seantor_donors_leak"&gt;read more...&lt;/a&gt;&lt;/p&gt;
        &lt;/div&gt;
        &lt;/div&gt;
&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?a=6UOCNifUCqk:Jt-iomKdAIU:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?a=6UOCNifUCqk:Jt-iomKdAIU:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?i=6UOCNifUCqk:Jt-iomKdAIU:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?a=6UOCNifUCqk:Jt-iomKdAIU:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?i=6UOCNifUCqk:Jt-iomKdAIU:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/TheWebHackingIncidentsDatabase/~4/6UOCNifUCqk" height="1" width="1"/&gt;</description>
     <comments>http://www.xiom.com/whid/2009/35/seantor_donors_leak#comments</comments>
 <category domain="http://www.xiom.com/taxonomy/term/221">Credit Card Number</category>
 <category domain="http://www.xiom.com/taxonomy/term/224">Credit Card Security Code</category>
 <category domain="http://www.xiom.com/taxonomy/term/238">e-mail</category>
 <category domain="http://www.xiom.com/taxonomy/term/229">Name</category>
 <pubDate>Tue, 17 Mar 2009 13:51:54 +0000</pubDate>
 <dc:creator>Ofer Shezaf</dc:creator>
 <guid isPermaLink="false">439 at http://www.xiom.com</guid>
  <feedburner:origLink>http://www.xiom.com/whid/2009/35/seantor_donors_leak</feedburner:origLink></item>
  <item>
    <title>WHID 2009-34: Romanian Hacker Moves On To The Telegraph</title>
    <link>http://feedproxy.google.com/~r/TheWebHackingIncidentsDatabase/~3/4qDeBFs5Esw/telegraph_sql_injection</link>
    <description>&lt;div class="field field-type-date field-field-updated"&gt;
    &lt;div class="field-items"&gt;
            &lt;div class="field-item odd"&gt;
                      &lt;div class="field-label-inline-first"&gt;
              Updated:&amp;nbsp;&lt;/div&gt;
                    &lt;span class="date-display-single"&gt;10 March 2009&lt;/span&gt;        &lt;/div&gt;
        &lt;/div&gt;
&lt;/div&gt;
&lt;p&gt;Another week, another hack by the &lt;a href="http://www.hackersblog.org"&gt;HackerBlog&lt;/a&gt;, and when it targets an important web site and the impact is severe it is worthy of WHID. This time the Romanian hacker &lt;a href="http://www.hackersblog.org/2009/03/06/telegraphcouk-hacked-sql-injection/"&gt;used blind SQL injection to penetrate to the web site of the Telegraph&lt;/a&gt;, a leading English daily paper.&lt;/p&gt;
&lt;p&gt;Among his findings is a table including 700,000 e-mails, which would be a gold mine for spammers.&lt;/p&gt;
&lt;p&gt;The Telegraph &lt;a href="http://blogs.telegraph.co.uk/shane_richmond/blog/2009/03/09/hackersblog_and_telegraphcouk"&gt;response&lt;/a&gt; was published on their official blog.&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?a=4qDeBFs5Esw:SFPo--yEWII:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?a=4qDeBFs5Esw:SFPo--yEWII:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?i=4qDeBFs5Esw:SFPo--yEWII:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?a=4qDeBFs5Esw:SFPo--yEWII:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?i=4qDeBFs5Esw:SFPo--yEWII:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/TheWebHackingIncidentsDatabase/~4/4qDeBFs5Esw" height="1" width="1"/&gt;</description>
     <comments>http://www.xiom.com/whid/2009/34/telegraph_sql_injection#comments</comments>
 <pubDate>Tue, 10 Mar 2009 11:05:03 +0000</pubDate>
 <dc:creator>Ofer Shezaf</dc:creator>
 <guid isPermaLink="false">437 at http://www.xiom.com</guid>
  <feedburner:origLink>http://www.xiom.com/whid/2009/34/telegraph_sql_injection</feedburner:origLink></item>
  <item>
    <title>WHID 2009-33: eBay Fraud Abuses Zero Day XSS</title>
    <link>http://feedproxy.google.com/~r/TheWebHackingIncidentsDatabase/~3/xzKc3blAg0c/ebay_xss_fraud</link>
    <description>&lt;div class="field field-type-date field-field-updated"&gt;
    &lt;div class="field-items"&gt;
            &lt;div class="field-item odd"&gt;
                      &lt;div class="field-label-inline-first"&gt;
              Updated:&amp;nbsp;&lt;/div&gt;
                    &lt;span class="date-display-single"&gt;10 March 2009&lt;/span&gt;        &lt;/div&gt;
        &lt;/div&gt;
&lt;/div&gt;
&lt;div class="field field-type-text field-field-teaser"&gt;
    &lt;div class="field-items"&gt;
            &lt;div class="field-item odd"&gt;
                    &lt;p&gt;A zero day XSS vector enables hackers to include in an eBay offer an arbitrary code which is executed by both FireFox and IE. As a result they were able to spoof the content of the offer, so that the user saw different information than the details known to eBay.&lt;/p&gt;
&lt;p&gt;&lt;a mce_href="/whid/2009/33/ebay_xss_fraud" href="/whid/2009/33/ebay_xss_fraud"&gt;Read more&lt;/a&gt;...&lt;br /&gt;&lt;/p&gt;
        &lt;/div&gt;
        &lt;/div&gt;
&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?a=xzKc3blAg0c:iY7yQqk8vFQ:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?a=xzKc3blAg0c:iY7yQqk8vFQ:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?i=xzKc3blAg0c:iY7yQqk8vFQ:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?a=xzKc3blAg0c:iY7yQqk8vFQ:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?i=xzKc3blAg0c:iY7yQqk8vFQ:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/TheWebHackingIncidentsDatabase/~4/xzKc3blAg0c" height="1" width="1"/&gt;</description>
     <comments>http://www.xiom.com/whid/2009/33/ebay_xss_fraud#comments</comments>
 <pubDate>Tue, 10 Mar 2009 10:49:26 +0000</pubDate>
 <dc:creator>Ofer Shezaf</dc:creator>
 <guid isPermaLink="false">436 at http://www.xiom.com</guid>
  <feedburner:origLink>http://www.xiom.com/whid/2009/33/ebay_xss_fraud</feedburner:origLink></item>
  <item>
    <title>WHID 2008-60: Miley Cyrus Pictures Leaked Due to a Web Hack (Updated)</title>
    <link>http://feedproxy.google.com/~r/TheWebHackingIncidentsDatabase/~3/9xZPze2hRXc/miley_cyrus_myspace_gmail</link>
    <description>&lt;div class="field field-type-date field-field-updated"&gt;
    &lt;div class="field-items"&gt;
            &lt;div class="field-item odd"&gt;
                      &lt;div class="field-label-inline-first"&gt;
              Updated:&amp;nbsp;&lt;/div&gt;
                    &lt;span class="date-display-single"&gt;19 April 2009&lt;/span&gt;        &lt;/div&gt;
        &lt;/div&gt;
&lt;/div&gt;
&lt;div class="field field-type-text field-field-teaser"&gt;
    &lt;div class="field-items"&gt;
            &lt;div class="field-item odd"&gt;
                    &lt;p&gt;&lt;em&gt;&lt;strong&gt;Update (April 19th 2009)&lt;/strong&gt;&lt;/em&gt; - E!News provides additional interesting details about Josh Holly, the hacker who carried out the attack providing an interesting insight into the celebs hacking phenomena.&lt;/p&gt;
&lt;p&gt;&lt;a href="/whid/2008/60/miley_cyrus_myspace_gmail"&gt;Read more&lt;/a&gt;...&lt;/p&gt;
&lt;hr /&gt;
&lt;p&gt;Celebs are fast becoming a prime hacking target. Miley Cyrus already made her debut at WHID when her Twitter account was raided. But it seems that this was not her first &lt;span&gt;cyber&lt;/span&gt; incident for her. As reported by Wired&lt;span&gt;, late last year a hacker named  Josh Holly published private photos of Ms. Cyrus stolen from her G-mail account.&lt;/span&gt;&lt;/p&gt;
        &lt;/div&gt;
        &lt;/div&gt;
&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?a=9xZPze2hRXc:Fh_NnTekKKU:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?a=9xZPze2hRXc:Fh_NnTekKKU:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?i=9xZPze2hRXc:Fh_NnTekKKU:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?a=9xZPze2hRXc:Fh_NnTekKKU:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?i=9xZPze2hRXc:Fh_NnTekKKU:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/TheWebHackingIncidentsDatabase/~4/9xZPze2hRXc" height="1" width="1"/&gt;</description>
     <comments>http://www.xiom.com/whid/2008/60/miley_cyrus_myspace_gmail#comments</comments>
 <pubDate>Tue, 10 Mar 2009 10:33:57 +0000</pubDate>
 <dc:creator>Ofer Shezaf</dc:creator>
 <guid isPermaLink="false">435 at http://www.xiom.com</guid>
  <feedburner:origLink>http://www.xiom.com/whid/2008/60/miley_cyrus_myspace_gmail</feedburner:origLink></item>
  <item>
    <title>WHID 2009-32: 750 Twitter Accounts Hacked</title>
    <link>http://feedproxy.google.com/~r/TheWebHackingIncidentsDatabase/~3/aZkr05ZH7Qs/twitter_brute_force</link>
    <description>&lt;div class="field field-type-date field-field-updated"&gt;
    &lt;div class="field-items"&gt;
            &lt;div class="field-item odd"&gt;
                      &lt;div class="field-label-inline-first"&gt;
              Updated:&amp;nbsp;&lt;/div&gt;
                    &lt;span class="date-display-single"&gt;10 March 2009&lt;/span&gt;        &lt;/div&gt;
        &lt;/div&gt;
&lt;/div&gt;
&lt;p&gt;Twitter reports in a &lt;a href="http://blog.twitter.com/2009/03/safekeeping-twitter-accounts.html"&gt;blog entry&lt;/a&gt; that 750 accounts were hacked. The hacker posted messages linking to a porn webcam. While Twitter did not disclose how the attack was carried out, the suggested remediation hints that the account passwords were guessed, probably using a brute force attack.&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?a=aZkr05ZH7Qs:_Yvcxs8Avqc:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?a=aZkr05ZH7Qs:_Yvcxs8Avqc:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?i=aZkr05ZH7Qs:_Yvcxs8Avqc:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?a=aZkr05ZH7Qs:_Yvcxs8Avqc:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?i=aZkr05ZH7Qs:_Yvcxs8Avqc:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/TheWebHackingIncidentsDatabase/~4/aZkr05ZH7Qs" height="1" width="1"/&gt;</description>
     <comments>http://www.xiom.com/whid/2009/32/twitter_brute_force#comments</comments>
 <category domain="http://www.xiom.com/taxonomy/term/232">Password</category>
 <pubDate>Tue, 10 Mar 2009 10:04:48 +0000</pubDate>
 <dc:creator>Ofer Shezaf</dc:creator>
 <guid isPermaLink="false">434 at http://www.xiom.com</guid>
  <feedburner:origLink>http://www.xiom.com/whid/2009/32/twitter_brute_force</feedburner:origLink></item>
  <item>
    <title>WHID 2008-59: Spotify Streaming Music Service Hacked and Millions of Records Leaked</title>
    <link>http://feedproxy.google.com/~r/TheWebHackingIncidentsDatabase/~3/KtBaWnZfMV4/spotify</link>
    <description>&lt;div class="field field-type-date field-field-updated"&gt;
    &lt;div class="field-items"&gt;
            &lt;div class="field-item odd"&gt;
                      &lt;div class="field-label-inline-first"&gt;
              Updated:&amp;nbsp;&lt;/div&gt;
                    &lt;span class="date-display-single"&gt;8 March 2009&lt;/span&gt;        &lt;/div&gt;
        &lt;/div&gt;
&lt;/div&gt;
&lt;div class="field field-type-text field-field-teaser"&gt;
    &lt;div class="field-items"&gt;
            &lt;div class="field-item odd"&gt;
                    &lt;p&gt;This time we may need to remove the word "web" leaving this &lt;a mce_href="http://www.spotify.com/blog/archives/2009/03/04/spotify-security-notice/" href="http://www.spotify.com/blog/archives/2009/03/04/spotify-security-notice/"&gt;incident&lt;/a&gt;&lt;span class="mceItemHidden"&gt; classified only as "application security". A weakness in &lt;span class="mceItemHiddenSpellWord"&gt;&lt;span class="mceItemHidden"&gt;&lt;span class="mceItemHiddenSpellWord"&gt;Spotify&lt;/span&gt;&lt;/span&gt;&lt;/span&gt; streaming protocols led to leakage of sensitive information.&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span class="mceItemHidden"&gt;&lt;a mce_href="/whid/2008/59/spotify" href="/whid/2008/59/spotify"&gt;read more...&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;
        &lt;/div&gt;
        &lt;/div&gt;
&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?a=KtBaWnZfMV4:zdeubsdXxMc:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?a=KtBaWnZfMV4:zdeubsdXxMc:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?i=KtBaWnZfMV4:zdeubsdXxMc:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?a=KtBaWnZfMV4:zdeubsdXxMc:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?i=KtBaWnZfMV4:zdeubsdXxMc:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/TheWebHackingIncidentsDatabase/~4/KtBaWnZfMV4" height="1" width="1"/&gt;</description>
     <comments>http://www.xiom.com/whid/2008/59/spotify#comments</comments>
 <pubDate>Sun, 08 Mar 2009 09:32:44 +0000</pubDate>
 <dc:creator>Ofer Shezaf</dc:creator>
 <guid isPermaLink="false">431 at http://www.xiom.com</guid>
  <feedburner:origLink>http://www.xiom.com/whid/2008/59/spotify</feedburner:origLink></item>
  <item>
    <title>WHID 2009-31: Double Clickjacking Worm on Twitter</title>
    <link>http://feedproxy.google.com/~r/TheWebHackingIncidentsDatabase/~3/aTFOIGxGoU4/twitter_clickjacking</link>
    <description>&lt;div class="field field-type-date field-field-updated"&gt;
    &lt;div class="field-items"&gt;
            &lt;div class="field-item odd"&gt;
                      &lt;div class="field-label-inline-first"&gt;
              Updated:&amp;nbsp;&lt;/div&gt;
                    &lt;span class="date-display-single"&gt;25 February 2009&lt;/span&gt;        &lt;/div&gt;
        &lt;/div&gt;
&lt;/div&gt;
&lt;div class="field field-type-text field-field-teaser"&gt;
    &lt;div class="field-items"&gt;
            &lt;div class="field-item odd"&gt;
                    &lt;p&gt;Twitter is certainly bypassing Facebook as the most popular site out there, at least when it comes to security incidents.This time somebody decided abuse Twitter to demonstrate Clickjacking,&lt;/p&gt;
&lt;p&gt;&lt;a href="/whid/2009/31/twitter_clickjacking"&gt;read more...&lt;/a&gt;&lt;/p&gt;
        &lt;/div&gt;
        &lt;/div&gt;
&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?a=aTFOIGxGoU4:_q7J6_Wq56E:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?a=aTFOIGxGoU4:_q7J6_Wq56E:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?i=aTFOIGxGoU4:_q7J6_Wq56E:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?a=aTFOIGxGoU4:_q7J6_Wq56E:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?i=aTFOIGxGoU4:_q7J6_Wq56E:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/TheWebHackingIncidentsDatabase/~4/aTFOIGxGoU4" height="1" width="1"/&gt;</description>
     <comments>http://www.xiom.com/whid/2009/31/twitter_clickjacking#comments</comments>
 <pubDate>Wed, 25 Feb 2009 21:47:27 +0000</pubDate>
 <dc:creator>Ofer Shezaf</dc:creator>
 <guid isPermaLink="false">427 at http://www.xiom.com</guid>
  <feedburner:origLink>http://www.xiom.com/whid/2009/31/twitter_clickjacking</feedburner:origLink></item>
  <item>
    <title>WHID 2009-30: Sage SaaS Withdrawn Due to Security Flaws</title>
    <link>http://feedproxy.google.com/~r/TheWebHackingIncidentsDatabase/~3/3vMTeIpelak/sage_saas_vulnerable</link>
    <description>&lt;div class="field field-type-date field-field-updated"&gt;
    &lt;div class="field-items"&gt;
            &lt;div class="field-item odd"&gt;
                      &lt;div class="field-label-inline-first"&gt;
              Updated:&amp;nbsp;&lt;/div&gt;
                    &lt;span class="date-display-single"&gt;25 February 2009&lt;/span&gt;        &lt;/div&gt;
        &lt;/div&gt;
&lt;/div&gt;
&lt;div class="field field-type-text field-field-teaser"&gt;
    &lt;div class="field-items"&gt;
            &lt;div class="field-item odd"&gt;
                    &lt;p&gt;SaaS is the new buzzword in the IT world. Is it secure enough? &lt;a href="/whid/2009/30/sage_saas_vulnerable"&gt;read &lt;/a&gt;about the latest blunder of Sage, the leading provider of accounting software in the UK, when it was about to launch a trendy small business SaaS offering.&lt;/p&gt;
&lt;p&gt;&lt;a href="/whid/2009/30/sage_saas_vulnerable"&gt;read more...&lt;/a&gt;&lt;/p&gt;
        &lt;/div&gt;
        &lt;/div&gt;
&lt;/div&gt;
&lt;p&gt;While we have no public record of an exploit in this case, it seems that the mare discovery of vulnerabilities in sage new SaaS (software as a service) offering created so much damage to classify it as an incident.&lt;/p&gt;
&lt;p&gt;Sage is the leading provider of accounting software in the UK and it was about to launch a trendy small business SaaS offering. However as &lt;a href="http://blogs.zdnet.com/SAAS/?p=655"&gt;ZDnet reports&lt;/a&gt;, serious security flaws were discovered in the public beta and the company has to call off the launch. Who discovered the issues? naturally the competition. Duane Jackson, the CEO of a tiny rival company &lt;a href="http://blog.kashflow.com/2009/01/21/sage-live-security/"&gt;reported&lt;/a&gt; them on his blog&lt;span class="post-author vcard"&gt;&lt;span class="fn"&gt;.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span class="post-author vcard"&gt;&lt;span class="fn"&gt;More than anything, the incident shows how difficult it is for developers to migrate from desktop software to a web based offering. This is a whole new ball game, and security is one of the more difficult issues to adjust to. On the other hand it also shows that on line services are much more exposed to scrutiny, which may result in better security down the line.&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span class="post-author vcard"&gt;&lt;span class="fn"&gt;As for the technical details, the reports found that the following issues in the application:&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;span class="post-author vcard"&gt;&lt;span class="fn"&gt;Password displayed in clear text and sent in the request line.&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span class="post-author vcard"&gt;&lt;span class="fn"&gt;Remember me is on by default on any login.&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span class="post-author vcard"&gt;&lt;span class="fn"&gt;Access to management sections of the site and other users data.&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?a=3vMTeIpelak:_HX6celOoY4:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?a=3vMTeIpelak:_HX6celOoY4:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?i=3vMTeIpelak:_HX6celOoY4:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?a=3vMTeIpelak:_HX6celOoY4:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?i=3vMTeIpelak:_HX6celOoY4:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/TheWebHackingIncidentsDatabase/~4/3vMTeIpelak" height="1" width="1"/&gt;</description>
     <comments>http://www.xiom.com/whid/2009/30/sage_saas_vulnerable#comments</comments>
 <category domain="http://www.xiom.com/taxonomy/term/213">SaaS</category>
 <pubDate>Wed, 25 Feb 2009 21:18:48 +0000</pubDate>
 <dc:creator>Ofer Shezaf</dc:creator>
 <guid isPermaLink="false">426 at http://www.xiom.com</guid>
  <feedburner:origLink>http://www.xiom.com/whid/2009/30/sage_saas_vulnerable</feedburner:origLink></item>
  <item>
    <title>WHID 2009-29: FBI  &amp; Secret Service warn of a sophisticated HSM attack</title>
    <link>http://feedproxy.google.com/~r/TheWebHackingIncidentsDatabase/~3/vFpI-KKmdpU/HSM_Attack</link>
    <description>&lt;div class="field field-type-date field-field-updated"&gt;
    &lt;div class="field-items"&gt;
            &lt;div class="field-item odd"&gt;
                      &lt;div class="field-label-inline-first"&gt;
              Updated:&amp;nbsp;&lt;/div&gt;
                    &lt;span class="date-display-single"&gt;25 February 2009&lt;/span&gt;        &lt;/div&gt;
        &lt;/div&gt;
&lt;/div&gt;
&lt;div class="field field-type-text field-field-teaser"&gt;
    &lt;div class="field-items"&gt;
            &lt;div class="field-item odd"&gt;
                    &lt;p&gt;&lt;span&gt;The FBI and US Secret Service issue an alert on attack using SQL injection to penetrate banks secret key vaults: the enigmatic &lt;span&gt;HSMs&lt;/span&gt;. Yet, nobody hears about it. Sounds like a movie plot, can it really be?&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="/whid/2009/29/HSM_Attack"&gt;read more...&lt;/a&gt;&lt;/p&gt;
        &lt;/div&gt;
        &lt;/div&gt;
&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?a=vFpI-KKmdpU:NpImEEqxUqE:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?a=vFpI-KKmdpU:NpImEEqxUqE:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?i=vFpI-KKmdpU:NpImEEqxUqE:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?a=vFpI-KKmdpU:NpImEEqxUqE:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?i=vFpI-KKmdpU:NpImEEqxUqE:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/TheWebHackingIncidentsDatabase/~4/vFpI-KKmdpU" height="1" width="1"/&gt;</description>
     <comments>http://www.xiom.com/whid/2009/29/HSM_Attack#comments</comments>
 <pubDate>Wed, 25 Feb 2009 20:12:30 +0000</pubDate>
 <dc:creator>Ofer Shezaf</dc:creator>
 <guid isPermaLink="false">425 at http://www.xiom.com</guid>
  <feedburner:origLink>http://www.xiom.com/whid/2009/29/HSM_Attack</feedburner:origLink></item>
  <item>
    <title>WHID 2009-28: Serious Leakage on Mac clone Maker's site</title>
    <link>http://feedproxy.google.com/~r/TheWebHackingIncidentsDatabase/~3/QvkY2PuCJh8/mac_cloner_leaking</link>
    <description>&lt;div class="field field-type-date field-field-updated"&gt;
    &lt;div class="field-items"&gt;
            &lt;div class="field-item odd"&gt;
                      &lt;div class="field-label-inline-first"&gt;
              Updated:&amp;nbsp;&lt;/div&gt;
                    &lt;span class="date-display-single"&gt;25 February 2009&lt;/span&gt;        &lt;/div&gt;
        &lt;/div&gt;
&lt;/div&gt;
&lt;p&gt;The Register &lt;a href="http://www.theregister.co.uk/2009/02/11/psystart_website/"&gt;reports &lt;/a&gt;that the online shop of Psystar, a maker of Mac compatible equipment is heavily leaking technical information that can  be expoited to hack the site.&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?a=QvkY2PuCJh8:Atf53GjF-XY:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?a=QvkY2PuCJh8:Atf53GjF-XY:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?i=QvkY2PuCJh8:Atf53GjF-XY:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?a=QvkY2PuCJh8:Atf53GjF-XY:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?i=QvkY2PuCJh8:Atf53GjF-XY:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/TheWebHackingIncidentsDatabase/~4/QvkY2PuCJh8" height="1" width="1"/&gt;</description>
     <comments>http://www.xiom.com/whid/2009/28/mac_cloner_leaking#comments</comments>
 <pubDate>Wed, 25 Feb 2009 18:53:56 +0000</pubDate>
 <dc:creator>Ofer Shezaf</dc:creator>
 <guid isPermaLink="false">424 at http://www.xiom.com</guid>
  <feedburner:origLink>http://www.xiom.com/whid/2009/28/mac_cloner_leaking</feedburner:origLink></item>
  <item>
    <title>WHID 2009-27: Panasonic Products for Cheap</title>
    <link>http://feedproxy.google.com/~r/TheWebHackingIncidentsDatabase/~3/OaWxTdBYLE8/panasonic_uk_hacked</link>
    <description>&lt;div class="field field-type-date field-field-updated"&gt;
    &lt;div class="field-items"&gt;
            &lt;div class="field-item odd"&gt;
                      &lt;div class="field-label-inline-first"&gt;
              Updated:&amp;nbsp;&lt;/div&gt;
                    &lt;span class="date-display-single"&gt;25 February 2009&lt;/span&gt;        &lt;/div&gt;
        &lt;/div&gt;
&lt;/div&gt;
&lt;p&gt;A &lt;a href="http://www.zdnet.co.uk/talkback/0,1000001161,39610697-39001058c-20100458o,00.htm"&gt;report &lt;/a&gt;suggests that the UK retail site of the electronic equipment giant Panasonic was hacked and prices of products where set to pennies. Since the incident followed a layoff of 15,000 employees, it is assumed to be a disgruntled employees doing.&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?a=OaWxTdBYLE8:hv9eFcSYNSw:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?a=OaWxTdBYLE8:hv9eFcSYNSw:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?i=OaWxTdBYLE8:hv9eFcSYNSw:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?a=OaWxTdBYLE8:hv9eFcSYNSw:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?i=OaWxTdBYLE8:hv9eFcSYNSw:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/TheWebHackingIncidentsDatabase/~4/OaWxTdBYLE8" height="1" width="1"/&gt;</description>
     <comments>http://www.xiom.com/whid/2009/27/panasonic_uk_hacked#comments</comments>
 <pubDate>Wed, 25 Feb 2009 18:39:15 +0000</pubDate>
 <dc:creator>Ofer Shezaf</dc:creator>
 <guid isPermaLink="false">423 at http://www.xiom.com</guid>
  <feedburner:origLink>http://www.xiom.com/whid/2009/27/panasonic_uk_hacked</feedburner:origLink></item>
  <item>
    <title>WHID 2009-26: F-Secure Joins The Breached AV Vendors Club</title>
    <link>http://feedproxy.google.com/~r/TheWebHackingIncidentsDatabase/~3/OGvpTJ_SKLw/f-secure_joins_the_breached_av_vendors_club</link>
    <description>&lt;div class="field field-type-date field-field-updated"&gt;
    &lt;div class="field-items"&gt;
            &lt;div class="field-item odd"&gt;
                      &lt;div class="field-label-inline-first"&gt;
              Updated:&amp;nbsp;&lt;/div&gt;
                    &lt;span class="date-display-single"&gt;19 February 2009&lt;/span&gt;        &lt;/div&gt;
        &lt;/div&gt;
&lt;/div&gt;
&lt;div class="field field-type-text field-field-teaser"&gt;
    &lt;div class="field-items"&gt;
            &lt;div class="field-item odd"&gt;
                    &lt;p&gt;It wasn't surprising that after attacking a Kaspereski and a BitDefender web sites,another anti-virus vendor would follow&lt;/p&gt;
&lt;p&gt;&lt;a href="/whid/2009/26/f-secure_joins_the_breached_av_vendors_club"&gt;Read more...&lt;/a&gt;&lt;/p&gt;
&lt;p&gt; &lt;/p&gt;
        &lt;/div&gt;
        &lt;/div&gt;
&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?a=OGvpTJ_SKLw:-DOnt6zYjtY:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?a=OGvpTJ_SKLw:-DOnt6zYjtY:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?i=OGvpTJ_SKLw:-DOnt6zYjtY:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?a=OGvpTJ_SKLw:-DOnt6zYjtY:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?i=OGvpTJ_SKLw:-DOnt6zYjtY:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/TheWebHackingIncidentsDatabase/~4/OGvpTJ_SKLw" height="1" width="1"/&gt;</description>
     <comments>http://www.xiom.com/whid/2009/26/f-secure_joins_the_breached_av_vendors_club#comments</comments>
 <category domain="http://www.xiom.com/taxonomy/term/211">F-Secure</category>
 <pubDate>Thu, 19 Feb 2009 02:12:31 +0000</pubDate>
 <dc:creator>Ofer Shezaf</dc:creator>
 <guid isPermaLink="false">415 at http://www.xiom.com</guid>
  <feedburner:origLink>http://www.xiom.com/whid/2009/26/f-secure_joins_the_breached_av_vendors_club</feedburner:origLink></item>
  <item>
    <title>WHID 2009-25: Zone-H defaced</title>
    <link>http://feedproxy.google.com/~r/TheWebHackingIncidentsDatabase/~3/LqH-YdqBiUg/zone-h_defaced</link>
    <description>&lt;div class="field field-type-date field-field-updated"&gt;
    &lt;div class="field-items"&gt;
            &lt;div class="field-item odd"&gt;
                      &lt;div class="field-label-inline-first"&gt;
              Updated:&amp;nbsp;&lt;/div&gt;
                    &lt;span class="date-display-single"&gt;19 February 2009&lt;/span&gt;        &lt;/div&gt;
        &lt;/div&gt;
&lt;/div&gt;
&lt;div class="field field-type-text field-field-teaser"&gt;
    &lt;div class="field-items"&gt;
            &lt;div class="field-item odd"&gt;
                    &lt;p&gt;When the defacements shrine is defaced...&lt;/p&gt;
&lt;p&gt;&lt;a href="/whid/2009/25/zone-h_defaced"&gt;Read more...&lt;/a&gt;&lt;/p&gt;
&lt;p&gt; &lt;/p&gt;
        &lt;/div&gt;
        &lt;/div&gt;
&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?a=LqH-YdqBiUg:WXMoZRKeWdw:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?a=LqH-YdqBiUg:WXMoZRKeWdw:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?i=LqH-YdqBiUg:WXMoZRKeWdw:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?a=LqH-YdqBiUg:WXMoZRKeWdw:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?i=LqH-YdqBiUg:WXMoZRKeWdw:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/TheWebHackingIncidentsDatabase/~4/LqH-YdqBiUg" height="1" width="1"/&gt;</description>
     <comments>http://www.xiom.com/whid/2009/25/zone-h_defaced#comments</comments>
 <category domain="http://www.xiom.com/taxonomy/term/209">Zone-H</category>
 <pubDate>Thu, 19 Feb 2009 01:52:14 +0000</pubDate>
 <dc:creator>Ofer Shezaf</dc:creator>
 <guid isPermaLink="false">414 at http://www.xiom.com</guid>
  <feedburner:origLink>http://www.xiom.com/whid/2009/25/zone-h_defaced</feedburner:origLink></item>
  <item>
    <title>WHID 2009-24: New Phishing Attacks Combine Wildcard DNS and XSS</title>
    <link>http://feedproxy.google.com/~r/TheWebHackingIncidentsDatabase/~3/ZLSHUD-Qah8/new_phishing_attacks_combine_wildcard_dns_and_xss</link>
    <description>&lt;div class="field field-type-date field-field-updated"&gt;
    &lt;div class="field-items"&gt;
            &lt;div class="field-item odd"&gt;
                      &lt;div class="field-label-inline-first"&gt;
              Updated:&amp;nbsp;&lt;/div&gt;
                    &lt;span class="date-display-single"&gt;19 February 2009&lt;/span&gt;        &lt;/div&gt;
        &lt;/div&gt;
&lt;/div&gt;
&lt;div class="field field-type-text field-field-teaser"&gt;
    &lt;div class="field-items"&gt;
            &lt;div class="field-item odd"&gt;
                    &lt;p&gt;While many WHID entries are interesting for their impact, this one is very interesting for the its technical aspects. Not everyday XSS is used to spoof DNS&lt;/p&gt;
&lt;p&gt;&lt;a href="/whid/2009/24/new_phishing_attacks_combine_wildcard_dns_and_xss"&gt;Read more...&lt;/a&gt;&lt;/p&gt;
&lt;p&gt; &lt;/p&gt;
        &lt;/div&gt;
        &lt;/div&gt;
&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?a=ZLSHUD-Qah8:M9LVIZA8dio:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?a=ZLSHUD-Qah8:M9LVIZA8dio:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?i=ZLSHUD-Qah8:M9LVIZA8dio:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?a=ZLSHUD-Qah8:M9LVIZA8dio:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?i=ZLSHUD-Qah8:M9LVIZA8dio:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/TheWebHackingIncidentsDatabase/~4/ZLSHUD-Qah8" height="1" width="1"/&gt;</description>
     <comments>http://www.xiom.com/whid/2009/24/new_phishing_attacks_combine_wildcard_dns_and_xss#comments</comments>
 <pubDate>Thu, 19 Feb 2009 01:38:36 +0000</pubDate>
 <dc:creator>Ofer Shezaf</dc:creator>
 <guid isPermaLink="false">413 at http://www.xiom.com</guid>
  <feedburner:origLink>http://www.xiom.com/whid/2009/24/new_phishing_attacks_combine_wildcard_dns_and_xss</feedburner:origLink></item>
  <item>
    <title>WHID 2009-23: Miley Cyrus Twitter Account Hit By Sex-Obsessed Hacker</title>
    <link>http://feedproxy.google.com/~r/TheWebHackingIncidentsDatabase/~3/k2ZB0Dc1qmY/miley_cyrus_twitter_account_hit_by_sex-obsessed_hacker</link>
    <description>&lt;div class="field field-type-date field-field-updated"&gt;
    &lt;div class="field-items"&gt;
            &lt;div class="field-item odd"&gt;
                      &lt;div class="field-label-inline-first"&gt;
              Updated:&amp;nbsp;&lt;/div&gt;
                    &lt;span class="date-display-single"&gt;19 February 2009&lt;/span&gt;        &lt;/div&gt;
        &lt;/div&gt;
&lt;/div&gt;
&lt;div class="field field-type-text field-field-teaser"&gt;
    &lt;div class="field-items"&gt;
            &lt;div class="field-item odd"&gt;
                    &lt;p&gt;It is Twitter again, it is a celebrity again.&lt;/p&gt;
&lt;p&gt;&lt;a href="/whid/2009/23/miley_cyrus_twitter_account_hit_by_sex-obsessed_hacker"&gt;Read more...&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
        &lt;/div&gt;
        &lt;/div&gt;
&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?a=k2ZB0Dc1qmY:ND5jQK0sK5E:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?a=k2ZB0Dc1qmY:ND5jQK0sK5E:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?i=k2ZB0Dc1qmY:ND5jQK0sK5E:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?a=k2ZB0Dc1qmY:ND5jQK0sK5E:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?i=k2ZB0Dc1qmY:ND5jQK0sK5E:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/TheWebHackingIncidentsDatabase/~4/k2ZB0Dc1qmY" height="1" width="1"/&gt;</description>
     <comments>http://www.xiom.com/whid/2009/23/miley_cyrus_twitter_account_hit_by_sex-obsessed_hacker#comments</comments>
 <category domain="http://www.xiom.com/taxonomy/term/205">Celebrities</category>
 <pubDate>Thu, 19 Feb 2009 00:10:59 +0000</pubDate>
 <dc:creator>Ofer Shezaf</dc:creator>
 <guid isPermaLink="false">411 at http://www.xiom.com</guid>
  <feedburner:origLink>http://www.xiom.com/whid/2009/23/miley_cyrus_twitter_account_hit_by_sex-obsessed_hacker</feedburner:origLink></item>
  <item>
    <title>WHID 2009-22: Federal Travel Booking Site Spreads Malware (Updated)</title>
    <link>http://feedproxy.google.com/~r/TheWebHackingIncidentsDatabase/~3/IXDb-2XLWFw/federal_travel_booking_site_spreads_malware</link>
    <description>&lt;div class="field field-type-date field-field-updated"&gt;
    &lt;div class="field-items"&gt;
            &lt;div class="field-item odd"&gt;
                      &lt;div class="field-label-inline-first"&gt;
              Updated:&amp;nbsp;&lt;/div&gt;
                    &lt;span class="date-display-single"&gt;22 February 2009&lt;/span&gt;        &lt;/div&gt;
        &lt;/div&gt;
&lt;/div&gt;
&lt;div class="field field-type-text field-field-teaser"&gt;
    &lt;div class="field-items"&gt;
            &lt;div class="field-item odd"&gt;
                    &lt;p&gt;This one is somewhat more than your average "I got infected by a malware honey" b-movie.&lt;/p&gt;
&lt;p&gt;&lt;a href="/whid/2009/22/federal_travel_booking_site_spreads_malware"&gt;Read more...&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
        &lt;/div&gt;
        &lt;/div&gt;
&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?a=IXDb-2XLWFw:YPtcMqhiUbM:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?a=IXDb-2XLWFw:YPtcMqhiUbM:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?i=IXDb-2XLWFw:YPtcMqhiUbM:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?a=IXDb-2XLWFw:YPtcMqhiUbM:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheWebHackingIncidentsDatabase?i=IXDb-2XLWFw:YPtcMqhiUbM:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/TheWebHackingIncidentsDatabase/~4/IXDb-2XLWFw" height="1" width="1"/&gt;</description>
     <comments>http://www.xiom.com/whid/2009/22/federal_travel_booking_site_spreads_malware#comments</comments>
 <pubDate>Wed, 18 Feb 2009 20:50:18 +0000</pubDate>
 <dc:creator>Ofer Shezaf</dc:creator>
 <guid isPermaLink="false">409 at http://www.xiom.com</guid>
  <feedburner:origLink>http://www.xiom.com/whid/2009/22/federal_travel_booking_site_spreads_malware</feedburner:origLink></item>
  </channel>
</rss>
