Symantec Website Hack Exposes User Data

執筆者
Brian Prince
Brian Prince
Published: Nov 25, 2009
Updated: Feb 2, 2021
2 minute read
eWeek のコンテンツおよび製品のおすすめは、編集上の独立性を保っています。パートナーへのリンクをクリックすると、当社が報酬を得る場合があります。 詳細を見る

A Website operated by security firm Symantec was hacked – giving an attacker a sneak peak at sensitive customer data.

The Romanian hacker known as Unu, who earlier this year uncovered a hole in a Website run by Kaspersky Lab, exploited a blind SQL injection problem to get his hands on clear-text passwords associated with customer records and other data.

Unu used sqlmap and Pangolin to demonstrate the vulnerability, and published screenshots to his blog. According to Symantec, the vulnerability was on its pcd.symantec.com site, which is used to facilitate customer support for Symantec’s Norton products in Japanand South Korea.

“At this time, we believe that this incident does not affect Symantec customers anywhere else in the world,” a Symantec spokesperson said Nov. 24. “This incident impacts customer support in Japanand South Koreabut does not affect the safety and usage of Symantec’s Norton-branded consumer products. Symantec is currently in the process of ensuring that the Website is appropriately secured and will bring it back online as soon as possible.”

According to Unu, his goal was not to cause harm, but to create a stir so the problem would be fixed.

“If you remember, in February, Kaspersky faced with a sql injection,” he blogged. “Then they had the courage to admit vulnerability…There was fair play, they quickly secured vulnerable parameter, and even if at first they were very angry at me, finally understood that I did not extract (data), I saved nothing…My goal was, what (it) is still, to warn. To call attention.”

Trend Micro Advanced Threats Researcher Rik Ferguson said the incident serves as a reminder to follow best practices when it comes to securing Web applications. Sensitive data should never be stored in clear text, he blogged, and bounds checking of input data can help avoid buffer overflows and SQL injection attacks.

Brian Prince

Brian Prince

Content Writer
eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

TechnologyAdvice が所有・運営しています。 © 2026 TechnologyAdvice. 無断転載を禁じます

広告主に関する開示:このサイトに掲載されている製品の一部は、TechnologyAdvice が報酬を受け取っている企業のものです。この報酬は、製品がこのサイトのどこにどのように表示されるか(表示される順序など)に影響する場合があります。TechnologyAdvice は、市場で入手可能なすべての企業やすべての種類の製品を掲載しているわけではありません。