Contributors

Jeremiah Grossman
(WhiteHat Security)

Ofer Shezaf
(Breach Security) [Project Leader]

The Web Hacking Incidents Database
Last update:17 February 2008

List of Incidents for a Year

Select Year: 1999, 2000, 2001, 2002, 2003, 2004, 2005, 2006, 2007, 2008


List of incidents for the year 2002
4 incidents listed
WHID 2002-2: Advogato XSS virus account
Reported: 11 July 2005
Occurred: 21 September 2002

Classifications:

  • Attack Method: Insufficient Authorization
  • Attack Method: Predictable Resource Location

References:

WHID 2002-3: Reuters accused of hacking
Reported:
Occurred: 29 November 2002

Classifications:

  • Attack Method: Unknown

A company put its earnings report on site before its official release, but did not linked to it. Reuters found the document and published it.

References:

WHID 2002-4: Tower Records settles charges over hack attacks
Reported:
Occurred: 05 December 2002

Classifications:

  • Attack Method: Credential/Session Prediction

View other customers orders by changing a guessable number within a URL parameter

References:

WHID 2002-1: Flawed authentication at BN.com exposes personal information
Reported:
Occurred: 09 July 2002

Classifications:

  • Attack Method: Credential/Session Prediction
  • Outcome: Disclosure Only

Opening an account with a discontinued e-mail address exposes all the information of the discontinues account

References:



This work is licensed under the Creative Commons Attribution License. To view a copy of this license, visit http://creativecommons.org/licenses/by/2.5/ or send a letter to Creative Commons, 559 Nathan Abbott Way, Stanford, California 94305, USA.

 
© Copyright 2005, Web Application Security Consortium. All rights reserved.