Tuesday, February 26, 2008

Hacker Steals Data on 18M Customers in South Korea Using CSRF

Via DarkReading -

South Korea’s largest online shopping site earlier this month was attacked by a Chinese hacker who made off with the user information on 18 million members and a large amount of financial data.

According to reports on Hack in the Box and the Web Application Security Consortium Incident Report, Auction.co.kr has disclosed the theft of data from some 18 million buyers and sellers.
The attack was launched from China's internet. After the incident, Auction.co.kr received a phone call offering to exchange the user information for money, the reports said.


According to a report on Dark Visitor, a security blog site, the Chinese hacker did not directly attack the server. The hacker sent out bulk emailings to the auction staff containing “hacker procedures" that may have contained malware. When the staff members confirmed the emails, the hacker was able to gain their IDs. The hacker was then able to log into the Auction server using the staffer’s ID.

The WASC report categorizes the exploit as a cross-site request forgery attack. "The attack description is vague, but can be best described as session hijacking," the organization said.

Auction.co.kr waited 20 hours after the attack before confirming the loss of information, according to the Korean site
Hackbase.com. Korean users rebuked the Website for being too slow to act, the reports said.

------------------------------------

Are PMs and programmers trying to tell you that CSRF isn't a big deal??

Well, here is your ammo...

No comments:

Post a Comment