wasc-whid@lists.webappsec.org

WASC Web Hacking Incidents Database

View all threads

WHID 2011-73: Royal Navy hacker claims to have broken into space agency site

WW
WASC Web Hacking Incidents Database
Mon, Apr 25, 2011 1:20 PM

*Entry Title: *WHID 2011-73: Royal Navy hacker claims to have broken into
space agency site
*WHID ID: *2011-73
*Date Occurred: *April 18, 2011
*Attack Method: *SQL Injection
*Application Weakness: *Improper Input Handling
*Outcome: *Leakage of Information
*Attacked Entity Field: *Government
*Attacked Entity Geography: *
*Incident Description: *Login credentials for database, email and other key
systems that a poster claims belong to the European Space Agency were posted
on a full disclosure mailing list over the weekend.
*Mass Attack: *No
*Reference: *
http://www.eweekeurope.co.uk/news/european-space-agency-confirms-ftp-server-hack-26976
Attack Source Geography:

*Entry Title: *WHID 2011-73: Royal Navy hacker claims to have broken into space agency site *WHID ID: *2011-73 *Date Occurred: *April 18, 2011 *Attack Method: *SQL Injection *Application Weakness: *Improper Input Handling *Outcome: *Leakage of Information *Attacked Entity Field: *Government *Attacked Entity Geography: * *Incident Description: *Login credentials for database, email and other key systems that a poster claims belong to the European Space Agency were posted on a full disclosure mailing list over the weekend. *Mass Attack: *No *Reference: * http://www.eweekeurope.co.uk/news/european-space-agency-confirms-ftp-server-hack-26976 *Attack Source Geography:*