Acunetix 7 makes web application security checking easier and more cost effective
September 1, 2010 – 1:55 pm | One Comment

New scanning engine with improved vulnerability detection AND verification makes finding and fixing security issues in web applications easier.
London, 1st September 2010 – Acunetix, a market leader in web application security scanning technology, today announced …

Read the full story »
releases

Acunetix Web Vulnerability Scanner Product Releases

docs & faq

Acunetix technical documentation how to and FAQ

news

Acunetix Company and Web Security news, & Press Releases

events

Acunetix Webinars, Events and Training around the world

web security zone

Everything you need to know about Web Security

Home » news

SQL Injection hits again; 168,000 personal records exposed

Submitted by Robert Abela on May 18, 2010 – 9:27 pmNo Comment

A hacker, who calls himself “ins3cted”, has demonstrated to Webwereld via video how by exploiting a simple SQL injection, he can retrieve 168,000 personal records from a Dutch website called Experience the OV (http://www.ervaarhetov.nl).

Citizens living in the provinces of Gelderland, Overijssel and Flevoland are being encouraged to use public transport via a campaign that promotes the vulnerable website, from where they can purchase travelling smart cards. “ins3ct3d” also explained that he felt obliged to expose this security vulnerability to warn his fellow citizens as long as the government continues to use such unsafe systems.  ins3cted also stated “This time it’s sensitive personal data, next time your fingerprints or EPD,” which for sure it’s not the kind of data you want falling in the wrong hands!

Till now, there is no confirmation if customers’ banking and payment details were exposed, but there were a number of accessible fields in the databases which stored ID card numbers and payment terms.  At the request of Webwereld, a Dutch website which publishes internet related news, the hacker did not retrieve any more data.  The vulnerable site, at this time is currently unavailable.

At least we can breathe a sigh of relief this time, since the hacker appears to have interest in exposing poor coding security, rather than stealing identities.  Hopefully this incident will raise much needed awareness around the world of the need to ensure secure development and web application penetration tests.  The video is available from the following URL; http://webwereld.nl/nieuws/66012/ov-site-lekt-persoonlijke-data-168-000-reizigers.html

Share and Enjoy:
  • Twitter
  • Reddit
  • Digg
  • del.icio.us
  • LinkedIn
  • StumbleUpon
  • Google Bookmarks
  • Technorati

Leave a comment!

Add your comment below, or trackback from your own site. You can also subscribe to these comments via RSS.

Be nice. Keep it clean. Stay on topic. No spam.

You can use these tags:
<a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

This is a Gravatar-enabled weblog. To get your own globally-recognized-avatar, please register at Gravatar.