by Paul Joseph
May 5, 2011
Featured
Payment gateway, CCAvenue it seems was hacked by hackers via exploiting SQL injection vulnerability. As per this site , Hacker identifying himself as d3hydr8 has shared the hack report with them and it seems that ccAvenue stored the password in plain text! Below is a report belonging to this compromise —————— [ + ] USER () : iusr_ccavenueiusr_ccavenue [ + ] S_USER () : iusr_ccavenue [ + ] DB_NAME () : gateway [ + ] HOST_NAME () : AV-2 [ + ] SERVER_NAME () : AVDB-3 [ + ] SERVER_TYPE () : Apache/2.2.14 (Unix) mod_ssl/2.2.3 OpenSSL/0.9.8e-fips-rhel5 mod_jk/1.2.28 [ + ] X-POWERED-By () : Servlet 2.5; JBoss-5.0/JBossWeb-2.1 [ + ] IP_ADDRESS_INFO : 124.153.83.27 ———————————————————————————————————- [ + ] Displaying list of databases on this MSSQL host ! [ DATABASE: 0 ] : gateway [ DATABASE: 1 ] : master [ DATABASE: 2 ] : tempdb [ DATABASE: 3 ] : model [ DATABASE: 4 ] : msdb [ DATABASE: 5 ] : Reseller – Storing password in plain text – and that too by a payment gateway?
Tagged as:
displaying,
hack,
hackers-via,
password,
payment-gateway,
reseller,
servlet,
shared-the-hack,
user
Read the full article →
by Paul Joseph
May 3, 2011
Featured
[Editorial Notes: Recently, we shared a report on LBS industry and Mobile User Privacy , which raised an important concern regarding how mobile OS companies store location data and the privacy threat associated with it. Arjun Ram, founder of Taazza , a LBS app startup shares his take on this issue.] We felt the need to write this post after the well advertised fiasco for iPhone and the mis-information that is being spread about LBS. Our app is a LBS app and we take privacy very seriously.
Tagged as:
apple,
backup,
indian,
location,
microsoft,
mobile,
opinion,
provider,
time,
user
Read the full article →