CGISecurity Logo
  • American Express web bug exposes card holders

    "A glaring vulnerability on the American Express website has unnecessarily put visitors at risk for more than two weeks and violates industry regulations governing credit card companies, a security researcher says. Among other things, the cross-site scripting (XSS) error on americanexpress.com allows attackers to steal users' authentication cookies, which are used to validate American Express…

  • College students rig Victoria Secret online contest

    "At Drexel University and a handful of other colleges, students created computer scripts to sway the contest—an online vote to nominate a university to receive its own clothing line—in their campuses’ favor. Tim Plunkett, a junior at Drexel, created a script that could cast 1,500 votes per second, according to The Daily Pennsylvanian, the University…

  • WoW users targetted in mass site hack

    "Kaspersky reports that the crackers are adding a JavaScript tag to the html of hacked sites. This causes surfers visiting the site to pull content from one of six gateway sites, which redirect to a server hosting malware located in China. A range of exploits are hosted on this site designed to take advantage of…

  • Redhat/Fedora Servers compromised, package signing key stolen, rogue packages possibly signed

    Both the Redhat and Fedora servers have been hacked by an attacker who has not only gained access to these systems, but may have also deployed rogue packages and signed them with Redhat’s private key. Redhat has provided a script for users to check to see if the compromised packages have been deployed on their…

  • Sony PlayStation’s site SQL injected, redirecting to rogue security software

    "The latest high trafficked web site to fall victim into the continuing waves of massive SQL injection attacks courtesy of Sony PlayStation's site SQL injected copycats and the ASProx botnet, is Sony's PlayStation U.S site according to a recent post at SophosLabs's blog" – ZDNet Article Link: http://blogs.zdnet.com/security/?p=1394

  • ARP Spoofing leads to hijacking of metasploit website

    Normally I don't post news about specific website issues however this was a great example of why you need to protect your webserver from local networks threats as well as remote. "Monday morning, Metasploit.com was temporarily hijacked using an attack on the local area network of Metasploit's hosting provider. Using what is technically known as…

  • Cool hack: Man exploits random deposit verification flows to steal $50,000

    "A California man has been indicted for an inventive scheme that allegedly siphoned $50,000 from online brokerage houses E-trade and Schwab.com in six months — a few pennies at a time. Michael Largent, of Plumas Lake, California, allegedly exploited a loophole in a common procedure both companies follow when a customer links his brokerage account…

  • How NOT to handle finding vulnerabilities at your company

    UPDATED Link to Steve's interview with CrYpTiC_MauleR added below. At first I wasn't going to post about this but since it doesn't seem to be dying I will. Long story short 1. A Low level techie finds weaknesses/vulnerabilities at the company he works for (TJX) 2. ?He reports these issues to who he thinks should…

  • Bots Use SQL Injection Tool in Web Attack

    "The Asprox botnet, a relatively small botnet known mainly for sending phishing emails, has been spotted in the last few days installing an SQL injection attack tool on its bots. The bots then Google for .asp pages with specific terms — and then hit the sites found in the search return with SQL injection attacks,…

  • Layer 1 attack shuts down Peter Gabriel website

    As reported by thereg Peter Gabriel's website was attacked this morning, this time at layer 1. From www.petergabriel.com "Real World, Peter Gabriel and WOMAD web services are currently off-line. Our servers were stolen from our ISP's data centre on Sunday night – Monday morning. We are working on restoring normal service as soon as possible.…

  • Developers at fault? SQL Injection attacks lead to wide-spread compromise of IIS servers

    "There’s been a lot of noise and violent thrashing over the last couple days regarding a flaw that was originally believed to be a flaw in Microsoft’s IIS (Internet Information Server), but has since been pointed out as simply a well thought out SQL Injection attack. For those of you who aren’t familiar with SQL…

  • Hackers jack thousands of sites, including UN domains

    "Large numbers of legitimate Web sites, including government sites in the U.K. and some operated by the United Nations, have been hacked and are serving up malware, a security researcher said today as massive JavaScript attacks last detected in March resume. "They're using the same techniques as last month, of an SQL injection of some…

  • Hacked: Turning a women’s fashion website into a porn site

    "HACKERS have turned a bitchy blog about the world of women's magazines into a porn site. The blog by a mystery woman who calls herself “MagHag” has become a must-read for industry insiders, due to its salacious gossip about the editors of Madison, Vogue, Harper's Bazaar, Cosmopolitan and Shop Til You Drop. Those magazine editors…

  • Barack Obama site XSSed, redirected to Hillary’s website

    "Yes Cross Site Scripting (XSS) errors are all over the place. And YES they can affect very prominent web sites. The discussion forum area on Barackobama.com is allegedly the victim of a XSS exploit that redirected comments from Obama's site to….HillaryClinton.com. A hacker going by the alias of 'Mox' has claimed responsibility for the exploit.…

  • XSS in ISP ad page allows compromise of any website

    "When users visit a website like Wired.com, the DNS system maps the domain name into an IP address such as 72.246.49.48. But if a particular site does not exist, the DNS server tells the browser that there's no such listing and a simple error message should be displayed. But starting in August 2006, Earthlink instead…

  • Man hacks video game to propose to girlfriend

    "A software developer in the US used his programming skills to propose to his girlfriend by altering a copy of the game she was playing. Bernie Peng spent a month hacking the code in Bejeweled so that when Tammy Li attained a particular score a ring appeared along with the marriage proposal. Li accepted the…

  • Hackers Flood Epilepsy Web Forum With Flashing Lights

    "Unknown miscreants had a good time two weekends ago when they posted hundreds of flashing animated images onto discussion boards hosted by the Landover, Md.-based Epilepsy Foundation. Flashing lights or bold moving patterns can trigger often violent seizures among 3 percent of the estimated 50 million epileptics worldwide. "I was on the phone when it…

  • Paris Hilton pwned via facebook flaw

    "A security lapse on Facebook has allowed its users to gain access to vast libraries of private photographs, including one of Paris Hilton drinking beer with her friends. A Canadian hacker exploited a recent upgrade to the networking site's privacy settings to view pictures that were intended to be private, including some of Paris Hilton…

  • PHPBB flaw used to infect infect 200,000 websites with pr0n, fake trojan codec

    "Hot on the heels of a recent hack in which 10,000 sites were compromised, researchers have disclosed a new large-scale attack.. Researchers at McAfee estimated that the attack has been active for roughly one week, and in that time frame has managed to place itself on roughly 200,000 web pages. Most of the infected pages…

  • Antivirus Vendor TrendMicro Has Website SQL Injected, Malware Uploaded

    TrendMicro had its website sql injected and malware uploaded. A simple google search for 'fuckjp.js' shows trendmicro listed. "A Trend Micro spokesman confirmed that the company's site had been hacked Thursday, saying that the attack took place earlier in the week. "A portion of our site — some pages were attacked," said Mike Sweeny, a…

  • ActiveX Vulnerability Pwns MySpace, Facebook users

    "A buffer overflow enabled hackers to exploit the Aurigma ActiveX image uploading software used by Facebook, MySpace and other social networking sites, " said Rachwald. "The bad news is that this exploit is being used in a hacker toolkit currently being offered for download on several Chinese language sites, meaning that novices have been able…

  • Orkut Worm v2.0

    "The Scrapkut worm uses active code injection to spread between victims and their friends on Orkut. The malicious code appears on a victim’s scrapbook, containing a link to a supposed YouTube video. People who click on the link are redirected to an external site hosting malware that's disguised as a Flash upgrade. Users duped into…

  • Spammers crack Gmail Captcha

    "Captcha (Completely Automated Public Turing test to tell Computers and Humans Apart) challenge-response systems, which are used to prevent accounts being created until a user correctly identifies letters in an image, are designed to ensure requests are made by a human rather than an automated program. The technique has been used to defeat automatic sign-ups…

  • Hackers using rogue DNS servers to pwn you like a noob

    "Mendacious machines controlled by hackers that reroute Internet traffic from infected computers to fraudulent Web sites are increasingly being used to launch attacks, according to a paper published this week by researchers with the Georgia Institute of Technology and Google Inc. The paper estimates roughly 68,000 servers on the Internet are returning malicious Domain Name…

  • Legal Cost of DDOS in Estonia: $1,641 USD

    "Dmitri Galushkevich, 20, of Tallinn, was fined 17,500 Estonian Krooni ($1,641) on Wednesday after he was found guilty of launching an assault on the website of the Reform Party of Prime Minister Andrus Ansip and Estonian government systems. The fine is the equivalent of 350 days' salary, based on the minimum wage set by the…