Information Age: News, analysis & insight for IT & business leaders

Hackers embarrass Barracuda Networks with web attack

12 April 2011  

In the latest sucssesful attack on a security vendor, hackers use SQL injection to access company email addresses through Barracuda's website

Security vendor Barracuda Networks has confirmed that hackers successfully used a relatively simple technique to access an internal database via its website.

The Malaysian hackers used a SQL injection, in which database querying code is inserted through a web form, on the company's website, gaining access to employee email addresses and sales contacts.

Barracuda Networks, which sells web and email security products, says the web application firewall it uses to protect its website "was unintentionally placed in passive monitoring mode and was offline through a maintenance window" at the time of the attack.

Earlier this year, Barracuda published a report that found that 74% of organisations have been hacked at least once in the last two years through insecure web applications. It found that while website hacks were the number one concern among the surveyed security professionals, few organisations test their web applications for security vulnerabilities.

"The state of web application security is dismal," the company wrote at the time.

Barracuda Networks is the latest in a string of security companies to have suffered sucessful attacks. Last month, RSA Security admitted its website had been compromised in "an extremely aggressive cyber attack", while more recently a hacker was able to steal web security certificates from certification authority Comodo.


Comments 

There are currently no comments on this article

People who read this also read...

 

White Papers

Read article

'Think Lean' When Developing Management System Documentation

Learn how to efficiently and effectively implement a document management system for your organization.

Read article

11 Hiring Trends for 2011

In this document, you'll get the insider info you need to give potential employers what they want and beat your competition in 2011. You'll learn about the most valuable certifications and the game-changing skills that can lead to more job security and stability.

Read article

12 Hiring Manager Secrets to Getting the IT Job You Want

Learn how you can make yourself a more attractive candidate now with PrepLogic's free 12 Hiring Manager Secrets to Getting the Job You Want.

More
Advertisement
div class="banner">