Telco denies cracker SQLi raid

By

Group claims in vid it stole $100,000 from accounts.

A US telco and TV service provider has denied claims a hacker group used a SQL injection attack to steal usernames and passwords and subsequently applied the logins to raid US$100,000 from bank accounts.

Telco denies cracker SQLi raid

A spokesman for Sebastian said it found no evidence of attack. 

The hacker group claimed to have harvested plaintext credentials held by the company and created a 20-minute video it said chronicled the attack.

The attacker appeared to access Gmail accounts and bank accounts contained in PayPal.

Attackers then emptied Citibank accounts and set up illegal fund transfers.

The video was plausible but hacking crews were notorious for fabricating attacks.

SQL injection typically involves an attacker inputting SQL statements into an entry field that will force the system to execute potentially malicious commands.

A successful SQL injection exploit can read sensitive data from a database, modify that data, execute administration operations on a database or, in some cases, issue commands to an operating system, according to the Open Web Application Security Project (OWASP).

In July, cyber crooks were charged with hacking more than a dozen companies and using SQL injection to steal 160 million card numbers, causing hundreds of millions of dollars in financial losses.

This article originally appeared at scmagazineus.com

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © SC Magazine, US edition
Tags:

Most Read Articles

Travel eSIMs secretly route traffic over Chinese and undisclosed networks: study

Travel eSIMs secretly route traffic over Chinese and undisclosed networks: study

"Widespread data theft" hits Salesforce customers via third party

"Widespread data theft" hits Salesforce customers via third party

Attackers weaponise Linux file names as malware vectors

Attackers weaponise Linux file names as malware vectors

Home Affairs adds SecOps to new cyber risk overhaul

Home Affairs adds SecOps to new cyber risk overhaul

Log In

  |  Forgot your password?