Contributors

Jeremiah Grossman
(WhiteHat Security)

Ofer Shezaf
(Breach Security) [Project Leader]

The Web Hacking Incidents Database
Last update:17 February 2008

List of Incidents for a Year

Select Year: 1999, 2000, 2001, 2002, 2003, 2004, 2005, 2006, 2007, 2008


List of incidents for the year 2005
64 incidents listed
WHID 2005-65: LexisNexis Data Breach
Reported: 17 February 2008
Occurred: 09 March 2005

Classifications:

  • Attack Method: Insufficient Anti-automation
  • Country: USA
  • Outcome: Leakage of Information
  • Vertical: Information Services

The LexisNexis data breach is not new, but we have recently decided to start tracking abuse of insufficient automation measures and are adding historical incidents.

In this incident a group of people opened accounts at data broker LexisNexis and used automated tools to extract a large amount of personal information provided by the service.

As usual in such cases there is a question of whether the attack was a criminal activity, violation of the license agreement of the information provider or plainly legal. In this regard it is interesting to note that the group arrested in the incident was also responsible for the hacking to Paris Hilton Vodafone account, which was clearly an unlawful act.

Back in 2005 this data breach was one of the first such incidents, generated a lot of media interest, and led to more regulation regarding information aggregators. Interestingly, the excuse given by the company was that the incident was that there was no security failure in the web site, but that the procedures where lacking. We accepted this story at the time, but today we believe that such automation and scraping attacks are among the most dangerous attacks.

References:

WHID 2005-64: Woman scammed QVC for $400,000+ in Internet glitch
Reported: 20 November 2007
Occurred: 01 March 2005

Classifications:

  • Attack Method: Abuse of Functionality
  • Country: USA
  • Outcome: Monetary Loss

A woman exploited a bug in QVC shopping network web site to get, without paying, more than 1800 items worth $412,000 items from the March to November 2005. The glitch enabled her to cancel orders she placed at a specific time and still get the product.

References:

WHID 2005-63: Web designer sentenced for hacking competitor's site
Reported: 14 August 2007
Occurred: 31 December 2005

Classifications:

While lacking in technical details, this story is certainly juicy. It demonstrates well the business use of web site hacking. The downside is that the hacker got only a minimal punishment, which unless the incident itself is overrated in the media, is a very bad sign on how courts view computer crime.

References:

WHID 2007-18: Microsoft.com defaced
Reported: 06 May 2007
Occurred: 03 May 2005

Classifications:

  • Attack Method: SQL Injection
  • Country: USA
  • Origin: Saudi Arabia
  • Outcome: Defacement
  • Vertical: Technology

This incredible story from our friends at Zone-H shed light on one of those defacement attacks, which usually go unexplained. This time an infamous Saudi-Arabian hacker abused SQL injection vulnerability in Internet Explorer Administration Kit web site. And guess what type of SQL injection: A login form SQL injection!

References:

WHID 2005-62: Guidance Software
Reported: 18 April 2007
Occurred: 01 November 2005

Classifications:

  • Attack Method: SQL Injection

3,800 customer credit-card numbers were stolen in the attack on Guidance Software web site. This incident is made more severe since Guidance software is a provider of software for investigating security breaches and many of its clients are security and law enforcement agencies, some of them known to be affected.

As usual in such cases the actual way in which the information was stolen was not disclosed. A federal trade commission report on the incident, published only in 2007, revealed that the incident was a result on an SQL injection attack on Guidance servers. In a settlement with the FTC, Guidance agreed to implement a comprehensive information security program, including independent, third-party audits every other year for the next ten years.

References:

WHID 2005-61: Gmail session management bug
Reported: 12 April 2006
Occurred: 18 October 2005

Classifications:

  • Attack Method: Credential/Session Prediction
  • Outcome: Disclosure Only

A bug in Gmail's authentication and session management allows direct login to anybodies account without requiring any involvement of the victim.

References:

WHID 2005-55: Yahoo RSS XSS Vulnerability
Reported: 28 February 2006
Occurred: 18 December 2005

Classifications:

  • Attack Method: Cross Site Scripting (XSS)
  • Outcome: Disclosure Only

A malicious site can offer users a malformed RSS XML file to be included Yahoo RSS aggregation that would enable stealing Yahoo cookies

References:

WHID 2005-58: Yahoo mail Cross Site Scripting
Reported: 28 February 2006
Occurred: 22 December 2005

Classifications:

  • Attack Method: Cross Site Scripting (XSS)
  • Outcome: Disclosure Only

An attacker can send an e-mail with a malicious script to a victim which is perform its actions immediately when the e-mail is read.

References:

WHID 2005-51: Critical MySpace Vulnerabilities Leave Every Active Account Exploitable
Reported: 28 February 2006
Occurred: 05 December 2005

Classifications:

  • Attack Method: Abuse of Functionality
  • Attack Method: Cross Site Scripting (XSS)
  • Outcome: Disclosure Only

An XSS when receiving notification of an incoming IM message. Additionally it is possible to send an IM message to somebody who has blocked such messages by pretending to be answering a message from him.

References:

WHID 2005-59: Vote Someone Else's Shares
Reported: 28 February 2006
Occurred: 24 December 2005

Classifications:

  • Attack Method: Credential/Session Prediction
  • Attack Method: Insufficient Authentication
  • Outcome: Disclosure Only

Janus mutual fund uses predictable identifier to authenticate its share holders enabling them to vote for others.

References:

WHID 2005-50: XSS on Yahoo Mail
Reported: 28 February 2006
Occurred: 23 November 2005

Classifications:

  • Attack Method: Cross Site Scripting (XSS)
  • Outcome: Disclosure Only

Inserting code in an HTML attachments enables changing the user interface of Yahoo mail, which may enable fraud.

References:

WHID 2005-49: Google Base launched with security hole
Reported: 28 February 2006
Occurred: 21 November 2005

Classifications:

  • Attack Method: Cross Site Scripting (XSS)
  • Outcome: Disclosure Only

XSS in Google Base search function

References:

WHID 2005-56: XSS vulnerabilities in Google.com
Reported: 28 February 2006
Occurred: 21 December 2005

Classifications:

  • Attack Method: Cross Site Scripting (XSS)
  • Outcome: Disclosure Only

A redirection to an error page on Google.com includes values sent by the the user. This vulnerability allows phishers to send an e-mail with links to Google that will include their attack page.

References:

WHID 2005-46: Teen uses SQL injection to break to a security magazine web site
Reported: 26 February 2006
Occurred: 01 November 2005

Classifications:

  • Attack Method: SQL Injection

A high school student used SQL injection to break into the site of a Taiwanese information security magazine from the Tech Target group and steal customer's information.

References:

WHID 2005-20: Security gaps found in EPA contracting system
Reported: 26 February 2006
Occurred: 01 July 2005

Classifications:

  • Attack Method: Known Vulnerability
  • Outcome: Disclosure Only

An audit of a major Environmental Protection Agency contract management system uncovered significant security lapses that, if exploited by hackers, could have serious consequences for the agency's operations, assets and personnel. The audit focused on lack of monitoring for known vulnerabilities on these systems.

References:

WHID 2005-60: KU shuts down housing application Web site
Reported: 26 February 2006
Occurred: 27 December 2005

Classifications:

  • Attack Method: Unknown
  • Outcome: Disclosure Only

Web site used to file online for housing at KU was shutdown for lack of proper security measures to prevent visitors from viewing personal information about others

References:

WHID 2005-57: RPG site bit by hackers
Reported: 26 February 2006
Occurred: 21 December 2005

Classifications:

  • Attack Method: Unknown

User data stolen from an online game web site. The hacker tried to extort RPG by threatening to publish the users' data. The news item states that the hack was a result of a flaw in custom web site software.

References:

WHID 2005-54: XSS vulnerability in NIST web site
Reported: 26 February 2006
Occurred: 14 December 2005

Classifications:

  • Attack Method: Cross Site Scripting (XSS)
  • Outcome: Disclosure Only

Netcraft discovered an XSS vulnerability in NIST web site, which ironically hosts the U.S. National Vulnerability Database.

References:

WHID 2005-53: Charity Web Site Hacked
Reported: 26 February 2006
Occurred: 09 December 2005

Classifications:

  • Attack Method: Unknown

A UK Church charity web site was hacked and at least 3000 credit card numbers where stolen. Credit card information is known to have been used by the hackers. While no specific details are given, the article indicates that the way site was hacked.

References:

WHID 2005-41: XSS on Google's AdWords enables phishing
Reported: 10 November 2005
Occurred: 10 October 2005

Classifications:

  • Attack Method: Other
  • Attack Method: Cross Site Scripting (XSS)
  • Outcome: Disclosure Only

References:

WHID 2005-48: Insufficient authorization on Papa John's Pizza chain web site
Reported: 10 November 2005
Occurred: 07 November 2005

Classifications:

  • Attack Method: Insufficient Authorization
  • Outcome: Disclosure Only

References:

WHID 2005-43: XSS in Yahoo's Web mail enables phishing
Reported: 10 November 2005
Occurred: 21 October 2005

Classifications:

  • Attack Method: Cross Site Scripting (XSS)
  • Outcome: Disclosure Only

XSS in Yahoo mail, Allows phishing

References:

WHID 2005-42: Default password in a common application used by schools
Reported: 10 November 2005
Occurred: 21 October 2005

Classifications:

  • Attack Method: Insufficient Authentication
  • Outcome: Disclosure Only

The software has a default password for teachers, enabling anyone to access the system with teachers privileges.

References:

WHID 2005-40: Defacement of several Novell websites
Reported: 08 November 2005
Occurred: 04 October 2005

Classifications:

  • Attack Method: Other

Script upload due to a scoop known vulnerability

References:

WHID 2005-11: XSS Worm Hits MySpace
Reported: 08 November 2005
Occurred: 10 April 2005

Classifications:

  • Attack Method: Cross Site Scripting (XSS)
  • Outcome: Worm

The Samy worm at my space is now a classic, both a sophisticated attack and a well documented one, it became a case study in the web application security field. Recently Robert Hansen (RSnake) wrote a very interesting blog entry about Samy and what happened to him since.

References:

WHID 2005-44: Xoops web site hacked
Reported: 08 November 2005
Occurred: 28 October 2005

Classifications:

  • Attack Method: Other
  • Attack Method: Insufficient Authorization

Configuration mistake left an unprotected unused virtual host. No details on the configuration problems given.

References:

WHID 2005-47: SEC Vs. The Estonian Spiders
Reported: 08 November 2005
Occurred: 02 November 2005

Classifications:

  • Attack Method: Insufficient Authorization

Business wire allowed access to non published press releases.

References:

WHID 2005-14: XSS on Microsoft Xbox site allowed phishing
Reported: 08 November 2005
Occurred: 25 May 2005

Classifications:

  • Attack Method: Cross Site Scripting (XSS)
  • Outcome: Disclosure Only

References:

WHID 2005-10: Indian SATs results leaking
Reported: 08 November 2005
Occurred: 10 March 2005

Classifications:

  • Attack Method: Insufficient Authorization

References:

WHID 2005-39: Promotional Firefox community site hacked (again)
Reported: 08 November 2005
Occurred: 04 October 2005

Classifications:

  • Attack Method: OS Commanding

Exploited unpatched Twiki

References:

WHID 2005-38: Massachusetts Teen Convicted for Hacking into Internet and Telephone Service Providers
Reported: 12 September 2005
Occurred: 08 September 2005

Classifications:

  • Attack Method: Unknown
  • Attack Method: Denial of Service

Teen convicted of threatening an ISP with DOS attack, among other computer hacking activities

References:

WHID 2005-37: A 12 years old hacked an online game and stole game items
Reported: 12 September 2005
Occurred: 07 September 2005

Classifications:

  • Attack Method: Unknown

A 12 years old guess login information of a woman and abused her account, stealing game items from her.

References:

WHID 2005-36: Predictable delay in an online poker game enabled users to beat the casino
Reported: 04 September 2005
Occurred: 29 August 2005

Classifications:

  • Attack Method: Abuse of Functionality

A player of an online game discovered that considerable delay hinted on the cards the dealer holds.

References:

WHID 2005-35: Stanford University web sites defaced using XMLRPC bug
Reported: 23 August 2005
Occurred: 21 August 2005

Classifications:

  • Attack Method: OS Commanding

Sites where defaced by utilizing an issue in an XMLRPC library used by PHP

References:

WHID 2005-33: Insufficient authorization on Verizon's MyAccount feature
Reported: 22 August 2005
Occurred: 12 August 2005

Classifications:

  • Attack Method: Insufficient Authentication
  • Attack Method: Credential/Session Prediction
  • Outcome: Disclosure Only

A web site flaw could have allowed a user to view another subscriber's balance of remaining airtime minutes and the number of minutes that customer had used in the current billing cycle

References:

WHID 2005-34: Man logs into dabs.com misc customer account
Reported: 22 August 2005
Occurred: 18 August 2005

Classifications:

  • Attack Method: Insufficient Authentication

References:

WHID 2005-32: Weak password recovery on Citrix's site
Reported: 08 August 2005
Occurred: 03 August 2005

Classifications:

  • Attack Method: Weak Password Recovery Validation
  • Outcome: Disclosure Only

Weak password recovery procedure at Citrix

References:

WHID 2005-27: Phishers hack eBay
Reported: 08 August 2005
Occurred: 29 July 2005

Classifications:

  • Attack Method: Unknown

A bug in an eBay site allowed Phishers to redirect users to their own servers after feeling details at the genuine eBay site

References:

WHID 2005-30: "Blogger Developers Network" Blog, Cracked
Reported: 04 August 2005
Occurred: 31 July 2005

Classifications:

  • Attack Method: Unknown

Official answer from Blogger. "This was not the result of a hack attempt but of a subtle bug that occurred because our Developer's Network blog is a special case [it's got two names, 'code.blogger.com' and 'code.blogspot.com'].

References:

WHID 2005-31: Hacker forced new planet discovery out of the closet
Reported: 04 August 2005
Occurred: 01 August 2005

Classifications:

  • Attack Method: Unknown

References:

WHID 2005-29: Security issues in interactive hotel TVs
Reported: 31 July 2005
Occurred: 30 July 2005

Classifications:

  • Attack Method: Insufficient Authentication
  • Attack Method: Credential/Session Prediction
  • Outcome: Disclosure Only

While not strictly web security, this discussion of hotel rooms TV application security is a very good example of the dangers of our networked society

References:

WHID 2005-25: No Charges Filed Yet Against South Charlotte Computer Hacker
Reported: 31 July 2005
Occurred: 26 July 2005

Classifications:

  • Attack Method: Unknown

A man hacked into a competing web site

References:

WHID 2005-26: NISCC reveals SAP R/3 security flaw
Reported: 31 July 2005
Occurred: 28 July 2005

Classifications:

  • Attack Method: Path Traversal
  • Outcome: Disclosure Only

References:

WHID 2005-24: Firefox marketing site hacked
Reported: 15 July 2005
Occurred: 15 July 2005

Classifications:

  • Attack Method: Unknown

References:

WHID 2005-1: Gmail Bug Exposes E-mails messages of other users
Reported: 11 July 2005
Occurred: 12 January 2005

Classifications:

  • Attack Method: Unknown
  • Outcome: Disclosure Only

Parameter tampering enabled exposing sensitive information in G-Mail

References:

WHID 2005-2: Froogle XSS
Reported: 11 July 2005
Occurred: 14 January 2005

Classifications:

  • Attack Method: Cross Site Scripting (XSS)
  • Outcome: Disclosure Only

An XSS was found in Froogle

References:

WHID 2005-5: Paris Hilton's T-Mobile online account hacked
Reported: 11 July 2005
Occurred: 22 February 2005

Classifications:

  • Attack Method: OS Commanding
  • Attack Method: Weak Password Recovery Validation
  • Attack Method: Insufficient Authentication

Details remain sketchy, but news reports include social engineering, a guessable secret question for password recovery, and a known vulnerability is BEA WebLogic

References:

WHID 2005-22: MS UK defaced in hacking attack
Reported: 11 July 2005
Occurred: 06 July 2005

Classifications:

  • Attack Method: Unknown

Microsoft UK site defaced due to server misconfiguration

References:

WHID 2005-23: Chinese hacker held in Web data theft
Reported: 11 July 2005
Occurred: 07 July 2005

Classifications:

  • Attack Method: SQL Injection

The hacker who penetrated Kakaku.com was arrested after breaking into Club Tourism International Inc. Hacking was done in order to earn money to pay for tuition.

References:

WHID 2005-9: Undisclosed application security issue on Cisco's site forces global passwords reset
Reported: 08 April 2005
Occurred: 08 March 2005

Classifications:

  • Attack Method: Unknown
  • Outcome: Disclosure Only

An undisclosed application security issue on Cisco web site required resetting passwords for all registered users.

References:

WHID 2005-13: Hacker attacked weak point on Kakaku.com's Web Site
Reported:
Occurred: 18 May 2005

Classifications:

  • Attack Method: SQL Injection

References:

WHID 2005-28: Phishers Steal Trust from eBay Sign In Pages
Reported:
Occurred: 29 July 2005

Classifications:

  • Attack Method: Unknown

References:

WHID 2005-4: An Israeli debate site vulnerable to XSS
Reported:
Occurred: 16 February 2005

Classifications:

  • Attack Method: Cross Site Scripting (XSS)
  • Outcome: Disclosure Only

An Israeli public debates site called Hyde Park has an XSS vulnerability that exposes session cookies.

References:

WHID 2005-7: Hacker Tips Off B-School Applicants
Reported:
Occurred: 02 March 2005

Classifications:

  • Attack Method: Credential/Session Prediction

Parameter tampering to jump into someone else's account data

References:

WHID 2005-8: eBay Redirect Becomes Phishing Tool
Reported:
Occurred: 03 March 2005

Classifications:

  • Attack Method: Cross Site Scripting (XSS)
  • Attack Method: Content Spoofing

References:

WHID 2005-21: Insufficient authentication on USC admissions site allowed access to applicants data
Reported:
Occurred: 05 July 2005

Classifications:

  • Attack Method: SQL Injection
  • Attack Method: OS Commanding
  • Attack Method: Insufficient Authorization
  • Outcome: Disclosure Only

A person who discovered an SQL injection vulnerability in a USC system and informed security focus about the flaw was criminally charged with breaking into the system.

References:

WHID 2005-19: Privacy Fears due to insufficient authentication on CVS drugstore chain web site
Reported:
Occurred: 27 June 2005

Classifications:

  • Attack Method: Credential/Session Prediction
  • Outcome: Disclosure Only

References:

WHID 2005-15: Unprotected information on the University of Chicago web site
Reported:
Occurred: 27 May 2005

Classifications:

  • Attack Method: Insufficient Authorization
  • Outcome: Disclosure Only

Files containing sensitive information left unprotected on the web server

References:

WHID 2005-12: Insufficient authentication on Arbela mutual insurance allowed access to private data
Reported:
Occurred: 05 May 2005

Classifications:

  • Attack Method: Insufficient Authentication
  • Outcome: Disclosure Only

Extranet system accessible to the public

References:

WHID 2005-6: Tampering with parameters allows access to others account data on PayMaxx Inc. site
Reported:
Occurred: 23 February 2005

Classifications:

  • Attack Method: Credential/Session Prediction
  • Outcome: Disclosure Only

Parameter tampering enabled jumping into someone else's account data on PayMaxx Inc. site

References:

WHID 2005-3: Misconfiguration issues in paid wireless access and billing applications
Reported:
Occurred: 01 February 2005

Classifications:

  • Attack Method: Directory Indexing
  • Attack Method: Insufficient Authentication
  • Outcome: Leakage of Information

Multiple misconfiguration problems such as browsable directories, physical path revealing and default or weak passwords

References:

WHID 2005-16: MSN site hacked in South Korea
Reported:
Occurred: 03 June 2005

Classifications:

  • Attack Method: Unknown

The web site was modified to include password stealing code

References:

WHID 2005-18: Hacker hits Duke system
Reported:
Occurred: 05 June 2005

Classifications:

  • Attack Method: Unknown

References:

WHID 2005-17: Leakage of information due to XSS in Hotmail
Reported:
Occurred: 04 June 2005

Classifications:

  • Attack Method: Cross Site Scripting (XSS)
  • Outcome: Disclosure Only

References:



This work is licensed under the Creative Commons Attribution License. To view a copy of this license, visit http://creativecommons.org/licenses/by/2.5/ or send a letter to Creative Commons, 559 Nathan Abbott Way, Stanford, California 94305, USA.

 
© Copyright 2005, Web Application Security Consortium. All rights reserved.