U.S. says SQL injection hacks used in major breaches
Computerworld - A group of hackers used SQL injection techniques to steal huge amounts of data from Heartland Payment Systems Inc., TJX Companies Inc. and other businesses, according to court papers filed in connection with last week's indictment of the group's alleged ringleader.
A federal grand jury in New Jersey indicted Albert Gonzalez and two unidentified accomplices on charges related to the theft of 130 million credit and debit card numbers from Heartland, Hannaford Bros. Co., 7-Eleven Inc. and three other retailers not identified by prosecutors.
Gonzalez had been indicted earlier by grand juries in Massachusetts and New York on charges related to thefts of data from several other retailers, including TJX, Dave & Buster's Holdings, BJ's Wholesale Club, OfficeMax, Barnes & Noble and The Sports Authority.
The U.S. alleges that the criminal group used SQL injection techniques to exploit poorly coded Web application software. Once they gained access to a corporate system, the hackers planted sophisticated packet-sniffing tools and other malware to detect and steal payment card data flowing over the victim companies' networks, according to court documents.
SQL injection attacks take advantage of a vulnerability that appears when a Web application fails to properly filter or validate data a user enters on a Web page to order a product or communicate with a company. An attacker can send a malformed SQL query to the underlying database to break into it, plant malicious code or access other systems.
"We see SQL injection as the top attack technique on the Web," said Michael Petitti, chief marketing officer at Trustwave, a security firm whose clients include Heartland.
Launching such attacks "doesn't require much expertise at all," said Chris Wysopal, chief technology officer at Veracode Inc., a provider of security services. "It is at the script-kiddie level to do these kinds of attacks."
He added that companies using older versions of Microsoft's SQL Server database are especially vulnerable to SQL injection attacks.
This version of this story originally appeared in Computerworld's print edition.
Read more about Security in Computerworld's Security Topic Center.
- 12 iPhones Apps That Will Make You a Networking Star
- 10 Careers Robots Are Taking From You
- Big Data Gold Isn't Always Where You Would Expect It
- 6 Tips to Build Your Social Media Strategy
- A walking tour: 33 questions to ask about your company's security
- 15 social media scams
- The 7 elements of a successful security awareness program
- IT Certification Study Tips
- Register for this Computerworld Insider Study Tip guide and gain access to hundreds of premium content articles, cheat sheets, product reviews and more.
- Streamlining Information Workflows In order to streamline your workflows effectively, you will need to properly align your file transfer solution with your business requirements.
- Streamlining Information Workflows In order to streamline your workflows effectively, you will need to properly align your file transfer solution with your business requirements.
- Streamlining Information Workflows In order to streamline your workflows effectively, you will need to properly align your file transfer solution with your business requirements.
- Securing Internet File Transfers This solution brief describes the four essential elements of secure Internet transfers.
- Live Webcast
Storage Validation at Go Daddy: Best Practices from the World's #1 Web Hosting Provider - Storage Validation at Go Daddy: Best Practices from the World's #1 Web Hosting Provider
- Live Webcast
MFT and FileXpress - An Overview - Business users and applications exchange files on a regular basis. File transfer is a core part of the flow of business activity.
- Live Webcast
Bridging HTTP and FTP with FileXpress Internet Server - What if you could take an FTP server on your internal network, and allow external users (partners or customers) to securely access it...
- Bridging HTTP and FTP with FileXpress Internet Server What if you could take an FTP server on your internal network, and allow external users (partners or customers) to securely access it...
- MFT and FileXpress - An Overview Business users and applications exchange files on a regular basis. File transfer is a core part of the flow of business activity. All Security White Papers | Webcasts