Contributors

Jeremiah Grossman
(WhiteHat Security)

Ofer Shezaf
(Breach Security) [Project Leader]

The Web Hacking Incidents Database
Last update:17 February 2008

List of Incidents for a Year

Select Year: 1999, 2000, 2001, 2002, 2003, 2004, 2005, 2006, 2007, 2008


List of incidents for the year 2003
9 incidents listed
WHID 2003-2: UT Austin hack yields personal info on thousands
Reported: 04 April 2006
Occurred: 06 March 2003

Classifications:

  • Attack Method: Brute Force

While an old incident, further research into it suggest that it was a web hack. While the initial reports talk about a database break in, a report in the Register identify the database as txClass, which is a web based system. 55,200 social security numbers where stolen, though the hacker claimed that he did not perform the act for profit. He was caught and sentenced to 5 years probation.

References:

WHID 2003-6: Mississippi man blackmails Best Buy
Reported: 26 February 2006
Occurred: 01 October 2003

Classifications:

  • Attack Method: Unknown

A person convicted of blackmailing Best Buy. He threatened to expose a breach in the company's web site if not paid $2.5 million.

References:

WHID 2003-9: Defenses lacking at social network sites
Reported:
Occurred: 31 December 2003

Classifications:

  • Attack Method: SQL Injection
  • Attack Method: Cross Site Scripting (XSS)

References:

WHID 2003-1: FTD.com hole leaks personal information
Reported:
Occurred: 13 February 2003

Classifications:

  • Attack Method: Credential/Session Prediction
  • Outcome: Disclosure Only

View other customers information by modifying a cookie

References:

WHID 2003-3: User passwords could be stolid in Microsoft's Passport service
Reported:
Occurred: 08 May 2003

Classifications:

  • Attack Method: Weak Password Recovery Validation
  • Outcome: Disclosure Only

References:

WHID 2003-4: SQL injection on Guess site triggers an FTC inquiry
Reported:
Occurred: 18 June 2003

Classifications:

  • Attack Method: SQL Injection
  • Outcome: Disclosure Only

References:

WHID 2003-5: Car shoppers' credit details exposed in bulk
Reported:
Occurred: 25 September 2003

Classifications:

  • Attack Method: Predictable Resource Location
  • Outcome: Leakage of Information

User submitted information was being stored in a publicly available location. The URL found in the source code of a publicly available web page.

References:

WHID 2003-7: Victoria's Secret reveals far too much
Reported:
Occurred: 24 October 2003

Classifications:

  • Attack Method: Insufficient Authorization
  • Outcome: Disclosure Only

View other customers orders by changing a sequential number within a URL parameter

References:

WHID 2003-8: SQL Injection in PetCo.com leads to FTC investigation
Reported:
Occurred: 05 December 2003

Classifications:

  • Attack Method: SQL Injection
  • Outcome: Disclosure Only

References:



This work is licensed under the Creative Commons Attribution License. To view a copy of this license, visit http://creativecommons.org/licenses/by/2.5/ or send a letter to Creative Commons, 559 Nathan Abbott Way, Stanford, California 94305, USA.

 
© Copyright 2005, Web Application Security Consortium. All rights reserved.