Telegraph thanks hackers for site breach
By Stuart Turton
Posted on 9 Mar 2009 at 12:41
The Telegraph has thanked HackersBlog for exposing a flaw in its database that could have exposed thousands of subscriber passwords and personal details.
Hackersblog posted proof of a SQL injection attack on the Telegraph over the weekend, laying bare subscriber email addresses and unencrypted passwords.
In a message on the site, the hackers behind the attack claim: "Besides numerous interesting tables there is one that contains email addresses of those receiving the newsletter. A real treasure for spammers."
The Telegraph says the issue is being investigated and thanked the site for bringing the issue to its attention. "The hack interrogated database tables behind one of our partner sites and exposed a weakness in the way that particular site had been coded," says Paul Cheesbrough, chief information officer for Telegraph Media Group.
"We immediately took the impacted site down on Friday, and the two-year-old third party code is being re-written to eliminate the issues that hackersblog.org brought to our attention."
"Hackers are rarely embraced as being friends but in this instance it's important to thank the team at hackersblog.org for bringing these issues to our attention. We've listened, and we're working with the partner site to sort out the cause of the problem."
Hackersblog is making a name for itself by exposing exploits on high-profile targets, and has already embarrassed a number of security companies including Kaspersky and F-Secure.
From around the web
advertisement
- Laptop bag reviews: nine tested
- Sony VAIO T Series Ultrabook review: first look
- Revealed: the military standards and robots HP uses to test its laptops
- Windows 8: multi-monitors and double standards?
- Why is TalkTalk's year-old porn filter suddenly big news?
- Why are laptop screens so far behind mobiles?
- HP EliteBook Folio review: first look
- The shoebox-sized all-in-one printer
- Forget the Ultrabook: here comes the HP Sleekbook
- HP Spectre XT review: first look
- Why you have to be left in the dark on OS patches
- Is Microsoft mismanaging Windows on ARM?
- Dealing with spam surrogates
- Why 3G broadband can be better and cheaper than ADSL
- Is Twitter bad for business?
- Publishing your email address isn't a security disaster
- Why you'll need a fax machine to develop iOS apps
- Learning to adapt to the mobile web
- Why you shouldn't use WPS on your Wi-Fi network
- Disabled users suffer when software breaks the rules
advertisement
