wasc-whid@lists.webappsec.org

WASC Web Hacking Incidents Database

View all threads

WHID 2011-67: Hackers attack iTunes

WW
WASC Web Hacking Incidents Database
Mon, Apr 25, 2011 1:15 PM

*Entry Title: *WHID 2011-67: Hackers attack iTunes
*WHID ID: *2011-67
*Date Occurred: *April 4, 2011
*Attack Method: *Brute Force
*Application Weakness: *Insufficient Anti-automation
*Outcome: *Fraud
*Attacked Entity Field: *Retail
*Attacked Entity Geography: *
*Incident Description: *Hackers have taken control of the iTunes accounts of
many users, using them to make fraudulent purchases.
Cyber criminals are able to crack the accounts by using brute force attacks,
where an automated system tries thousands of popular passwords with each
account name.
*Mass Attack: *No
*Reference: *
http://www.computing.co.uk/ctg/news/2039945/hackers-attack-itunes
Attack Source Geography:

*Entry Title: *WHID 2011-67: Hackers attack iTunes *WHID ID: *2011-67 *Date Occurred: *April 4, 2011 *Attack Method: *Brute Force *Application Weakness: *Insufficient Anti-automation *Outcome: *Fraud *Attacked Entity Field: *Retail *Attacked Entity Geography: * *Incident Description: *Hackers have taken control of the iTunes accounts of many users, using them to make fraudulent purchases. Cyber criminals are able to crack the accounts by using brute force attacks, where an automated system tries thousands of popular passwords with each account name. *Mass Attack: *No *Reference: * http://www.computing.co.uk/ctg/news/2039945/hackers-attack-itunes *Attack Source Geography:*