Contributors

Jeremiah Grossman
(WhiteHat Security)

Ofer Shezaf
(Breach Security) [Project Leader]

The Web Hacking Incidents Database
Last update:17 February 2008

List of Incidents for a Classification

Please note that classifications are a new feature and not all entries in WHID are already classified, so when you get a certain number of entries for a classification, WHID might have more records matching that classification that we did not classify yet. We hope to complete the classification process soon.

Select classification:
Attack Method, Country, Location, Origin, Outcome, Software, Vertical

Select criteria for classification "Outcome":
Blackmail, Chaos, Deceit, Defacement, Disclosure Only, Downtime, Extortion, Identity Theft, Information Warfare, Leakage of Information, Link Spam, Loss of Sales, Monetary Loss, Phishing, Planting of Malware, Political Defacement, Spam, Worm


List of incidents for which Outcome is Link Spam
2 incidents listed
WHID 2007-67: The Day My Web Site Was Hacked
Reported: 19 December 2007
Occurred: 17 December 2007

Classifications:

  • Attack Method: Known Vulnerability
  • Country: UK
  • Outcome: Link Spam
  • Software: WordPress
  • Vertical: Media

In an incident very similar to the Al Gore Hack, the personal blog of IT journalist Tim Anderson was also hacked. Unlike Mr. Gore, Tim discusses the breach and its origins.

References:

WHID 2007-61: Another inconvenient truth: Al Gore's Web site hacked
Reported: 19 December 2007
Occurred: 26 November 2007

Classifications:

  • Attack Method: Known Vulnerability
  • Country: USA
  • Outcome: Link Spam
  • Software: WordPress
  • Vertical: Politics

Whether comment spam by itself is an application failure or a necessary evil for site allowing rich comments is an open question. However it is reported that in this case vulnerability in WordPress allowed the spammers to actually penetrate the site and modify pages and not just abuse comments.

References:



This work is licensed under the Creative Commons Attribution License. To view a copy of this license, visit http://creativecommons.org/licenses/by/2.5/ or send a letter to Creative Commons, 559 Nathan Abbott Way, Stanford, California 94305, USA.

 
© Copyright 2005, Web Application Security Consortium. All rights reserved.