<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:ddb="http://dabbledb.com/schema">  <channel>    <title>Default View</title>    <link>https://wasc-whid.dabbledb.com/publish/wasc-whid/e8f99ba9-ee0d-4dae-8f34-fb390418a450/defaultview.html</link>    <description></description>    <item>      <title>WHID 2010-160: Hackers crack e-mail server of Russian Federal Protection Service (gov.ru)</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=58196</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-160: Hackers crack e-mail server of Russian Federal Protection Service (gov.ru)&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;WHID 2010-160&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;August 23, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;Email server of one of Federal Protection Service (FPS) departments was attacked. As a result, for several hours every Internet user was allowed to access FPS e-mail archive.&lt;br&gt;Successful attack was conducted because of available outbound access and also because of administrators failure – they did not modify default settings, including passwords for accounts used to access the system with administrative privileges.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Government&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;Russia&lt;br&gt;&lt;b&gt;Attacked System Technology: &lt;/b&gt;Dozor&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://www.securitylab.ru/news/397019.php&quot;&gt;http://www.securitylab.ru/news/397019.php&lt;/a></description>      <pubDate>Tue, 24 Aug 2010 11:12:19 -0400</pubDate>      <ddb:attackedentityfield>Government</ddb:attackedentityfield>      <ddb:attackedentitygeography>Russia</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology>Dozor</ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>August 23, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-160: Hackers crack e-mail server of Russian Federal Protection Service (gov.ru)</ddb:entrytitle>      <ddb:incidentdescription>Email server of one of Federal Protection Service (FPS) departments was attacked. As a result, for several hours every Internet user was allowed to access FPS e-mail archive.&#13;&#10;&#13;&#10;Successful attack was conducted because of available outbound access and also because of administrators failure – they did not modify default settings, including passwords for accounts used to access the system with administrative privileges.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference>http://www.securitylab.ru/news/397019.php</ddb:reference>      <ddb:whidid>WHID 2010-160</ddb:whidid>    </item>    <item>      <title>WHID 2010-159: 500 000 websites hacked, including Apple</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=58168</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-159: 500 000 websites hacked, including Apple&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;WHID 2010-159&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;August 17, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Worm&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;As reported by The Register IT news portal, a number of smaller websites have been hacked using an SQL injection attack method that attempts to obfuscate links to malware infected pages. The hack apparently also affected two Apple websites that are used to promote its iTunes podcasts.&lt;br&gt;Other than the Apple sites, the news service says that at least 538 000 “mom-and-pop” websites have been victimized by the hack, in addition to 500 000 more that appear quite similar but lead to different domains. &lt;br&gt;The attack takes advantage of web-based application vulnerabilities, which often do not differentiate between legitimate search queries and intentional attacks via malicious code. &lt;br&gt;The Register reported that the malware-infected links have been removed from the Apple pages since Google last indexed its search page earlier this month. &lt;br&gt;The attack underlines the need for companies to go the extra mile and secure external web-facing applications said Rob Horton, the operational director of security testing consultant NCC Group.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://www.infosecurity-us.com/view/11870/500-000-websites-hacked-including-apple/&quot;&gt;http://www.infosecurity-us.com/view/11870/500-000-websites-hacked-including-apple/&lt;/a></description>      <pubDate>Wed, 18 Aug 2010 21:23:33 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>August 17, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-159: 500 000 websites hacked, including Apple</ddb:entrytitle>      <ddb:incidentdescription>As reported by The Register IT news portal, a number of smaller websites have been hacked using an SQL injection attack method that attempts to obfuscate links to malware infected pages. The hack apparently also affected two Apple websites that are used to promote its iTunes podcasts.&#13;&#10;&#13;&#10;Other than the Apple sites, the news service says that at least 538 000 “mom-and-pop” websites have been victimized by the hack, in addition to 500 000 more that appear quite similar but lead to different domains. &#13;&#10;&#13;&#10;The attack takes advantage of web-based application vulnerabilities, which often do not differentiate between legitimate search queries and intentional attacks via malicious code. &#13;&#10;&#13;&#10;The Register reported that the malware-infected links have been removed from the Apple pages since Google last indexed its search page earlier this month. &#13;&#10;&#13;&#10;The attack underlines the need for companies to go the extra mile and secure external web-facing applications said Rob Horton, the operational director of security testing consultant NCC Group.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Worm</ddb:outcome>      <ddb:reference>http://www.infosecurity-us.com/view/11870/500-000-websites-hacked-including-apple/</ddb:reference>      <ddb:whidid>WHID 2010-159</ddb:whidid>    </item>    <item>      <title>WHID 2010-158: National Space Agency of the Republic of Kazakhstan was hacked</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=58041</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-158: National Space Agency of the Republic of Kazakhstan was hacked&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;WHID 2010-158&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;July 18, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Death&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;On the 18th of July the hack-world.org group using an SQL Injection attack obtained access to the administration section of the National Space Agency of the Republic of Kazakhstan. Obtaining access to the administration system of the site was facilitated by the fact that administrators used weak passwords that allowed local recovery using MD5 hash. Currently, the site is under reconstruction.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;Russia&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Government&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;Kazahtan&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://habrahabr.ru/blogs/infosecurity/99736/&quot;&gt;http://habrahabr.ru/blogs/infosecurity/99736/&lt;/a></description>      <pubDate>Thu, 22 Jul 2010 08:51:50 -0400</pubDate>      <ddb:attackedentityfield>Government</ddb:attackedentityfield>      <ddb:attackedentitygeography>Kazahtan</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography>Russia</ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>July 18, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-158: National Space Agency of the Republic of Kazakhstan was hacked</ddb:entrytitle>      <ddb:incidentdescription>On the 18th of July the hack-world.org group using an SQL Injection attack obtained access to the administration section of the National Space Agency of the Republic of Kazakhstan. Obtaining access to the administration system of the site was facilitated by the fact that administrators used weak passwords that allowed local recovery using MD5 hash. Currently, the site is under reconstruction.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Death</ddb:outcome>      <ddb:reference>http://habrahabr.ru/blogs/infosecurity/99736/</ddb:reference>      <ddb:whidid>WHID 2010-158</ddb:whidid>    </item>    <item>      <title>WHID 2010-157: Facebook Full Disclosure</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=58003</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-157: Facebook Full Disclosure&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;WHID 2010-157&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;July 20, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Disclosure Only&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;apps.facebook.com website hacked via SQL Injection.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Internet&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://sla.ckers.org/forum/read.php?16,35138,35138#msg-35138&quot;&gt;http://sla.ckers.org/forum/read.php?16,35138,35138#msg-35138&lt;/a></description>      <pubDate>Wed, 21 Jul 2010 16:15:59 -0400</pubDate>      <ddb:attackedentityfield>Internet</ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>July 20, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-157: Facebook Full Disclosure</ddb:entrytitle>      <ddb:incidentdescription>apps.facebook.com website hacked via SQL Injection.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Disclosure Only</ddb:outcome>      <ddb:reference>http://sla.ckers.org/forum/read.php?16,35138,35138#msg-35138</ddb:reference>      <ddb:whidid>WHID 2010-157</ddb:whidid>    </item>    <item>      <title>WHID 2010-156: The Russian Railways tickets site was hacked</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=57983</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-156: The Russian Railways tickets site was hacked&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;WHID 2010-156&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;July 21, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Defacement&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;Unknown attackers hack the official site of &quot;Russian Railways&quot; company. As a result, web pages were replaced by hackers’ messages. The site was temporary blocked; now it is resumed but some pages are still unavailable, &quot;Buying Train Tickets&quot; web page is among them (ticket.rzd.ru). No details about personal data leakage is now available.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Transport&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;Russia&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://www.uinc.ru/news/sn14165.html&quot;&gt;http://www.uinc.ru/news/sn14165.html&lt;/a></description>      <pubDate>Wed, 21 Jul 2010 14:07:23 -0400</pubDate>      <ddb:attackedentityfield>Transport</ddb:attackedentityfield>      <ddb:attackedentitygeography>Russia</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>July 21, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-156: The Russian Railways tickets site was hacked</ddb:entrytitle>      <ddb:incidentdescription>Unknown attackers hack the official site of &quot;Russian Railways&quot; company. As a result, web pages were replaced by hackers’ messages. The site was temporary blocked; now it is resumed but some pages are still unavailable, &quot;Buying Train Tickets&quot; web page is among them (ticket.rzd.ru). No details about personal data leakage is now available.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Defacement</ddb:outcome>      <ddb:reference>http://www.uinc.ru/news/sn14165.html</ddb:reference>      <ddb:whidid>WHID 2010-156</ddb:whidid>    </item>    <item>      <title>WHID 2010-155: S. Korean Gov't Websites Hit by Hacker Attacks</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=57956</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-155: S. Korean Gov't Websites Hit by Hacker Attacks&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-155&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;July 7, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Downtime&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;Official websites of South Korean government agencies, including the presidential office and the foreign ministry, came under hacker attacks Wednesday, a national telecom regulator said. &lt;br&gt;According to the state-run Korean Communications Commission ( KCC), the websites of government agencies, such as the presidential office Cheong Wa Dae, the Ministry of Foreign Affairs and Trade, and private firms, including the leading Internet search engine Naver, Nonghyup Bank and the Korean Exchange Bank, were hit by the so-called distributed denial-of-service (DDoS) attacks from around local time 6:00 p.m. (0900 GMT) Wednesday. &lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Government&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;South Korea&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://english.cri.cn/6966/2010/07/07/1461s581567.htm&quot;&gt;http://english.cri.cn/6966/2010/07/07/1461s581567.htm&lt;/a></description>      <pubDate>Fri, 09 Jul 2010 14:02:57 -0400</pubDate>      <ddb:attackedentityfield>Government</ddb:attackedentityfield>      <ddb:attackedentitygeography>South Korea</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>July 7, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-155: S. Korean Gov't Websites Hit by Hacker Attacks</ddb:entrytitle>      <ddb:incidentdescription>Official websites of South Korean government agencies, including the presidential office and the foreign ministry, came under hacker attacks Wednesday, a national telecom regulator said. &#13;&#10;&#13;&#10;According to the state-run Korean Communications Commission ( KCC), the websites of government agencies, such as the presidential office Cheong Wa Dae, the Ministry of Foreign Affairs and Trade, and private firms, including the leading Internet search engine Naver, Nonghyup Bank and the Korean Exchange Bank, were hit by the so-called distributed denial-of-service (DDoS) attacks from around local time 6:00 p.m. (0900 GMT) Wednesday. </ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Downtime</ddb:outcome>      <ddb:reference>http://english.cri.cn/6966/2010/07/07/1461s581567.htm</ddb:reference>      <ddb:whidid>2010-155</ddb:whidid>    </item>    <item>      <title>WHID 2010-154: Justin Bieber My World Tour Contest Hacked</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=57943</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-154: Justin Bieber My World Tour Contest Hacked&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-154&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;July 2, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Disinformation&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;That was but a preliminary skirmish – they’ve come up with a much more damaging plan – to send Bieber to North Korea. Foolish, foolish Bieber has started a competition for countries to vote for him to come and tour them. Called the Justin Bieber My World Tour Contest, it has now been thoroughly highjacked by Anonymous – at the time of writing, North Korea is in second place by only a few thousand votes. Unless the current leader Israel can get its act together, it should be overtaken by lunchtime.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Entertainment&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://blogs.independent.co.uk/2010/07/02/the-plot-to-send-justin-bieber-to-north-korea/&quot;&gt;http://blogs.independent.co.uk/2010/07/02/the-plot-to-send-justin-bieber-to-north-korea/&lt;/a></description>      <pubDate>Fri, 09 Jul 2010 13:37:22 -0400</pubDate>      <ddb:attackedentityfield>Entertainment</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>July 2, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-154: Justin Bieber My World Tour Contest Hacked</ddb:entrytitle>      <ddb:incidentdescription>That was but a preliminary skirmish – they’ve come up with a much more damaging plan – to send Bieber to North Korea. Foolish, foolish Bieber has started a competition for countries to vote for him to come and tour them. Called the Justin Bieber My World Tour Contest, it has now been thoroughly highjacked by Anonymous – at the time of writing, North Korea is in second place by only a few thousand votes. Unless the current leader Israel can get its act together, it should be overtaken by lunchtime.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Disinformation</ddb:outcome>      <ddb:reference>http://blogs.independent.co.uk/2010/07/02/the-plot-to-send-justin-bieber-to-north-korea/</ddb:reference>      <ddb:whidid>2010-154</ddb:whidid>    </item>    <item>      <title>WHID 2010-153: App Store, Hacked.</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=57930</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-153: App Store, Hacked.&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-153&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;July 4, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Monetary Loss&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;This article began with details of one specific app developer hacking iTunes users accounts and purchasing their own apps using those accounts – making it to the top of the iTunes charts. As the story has developed it appears to be far more widespread than just that one particular developer and his apps…the Apple App store is filled with App Farms being used to steal. We’ve put together a complete list of all the facts and updates to this story here which we high recommend you read instead of this article. Apple has also now released a statement about the matter.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Retail&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://thenextweb.com/apple/2010/07/04/app-store-hacked/&quot;&gt;http://thenextweb.com/apple/2010/07/04/app-store-hacked/&lt;/a></description>      <pubDate>Fri, 09 Jul 2010 13:33:05 -0400</pubDate>      <ddb:attackedentityfield>Retail</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>July 4, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-153: App Store, Hacked.</ddb:entrytitle>      <ddb:incidentdescription>This article began with details of one specific app developer hacking iTunes users accounts and purchasing their own apps using those accounts – making it to the top of the iTunes charts. As the story has developed it appears to be far more widespread than just that one particular developer and his apps…the Apple App store is filled with App Farms being used to steal. We’ve put together a complete list of all the facts and updates to this story here which we high recommend you read instead of this article. Apple has also now released a statement about the matter.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Monetary Loss</ddb:outcome>      <ddb:reference>http://thenextweb.com/apple/2010/07/04/app-store-hacked/</ddb:reference>      <ddb:whidid>2010-153</ddb:whidid>    </item>    <item>      <title>WHID 2010-152: The Pirate Bay hacked</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=57879</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-152: The Pirate Bay hacked&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-152&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;July 5, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Disclosure Only&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;According to an advisory posted on the web site of Argentinian group of security researchers, they were able to obtain access to the Pirate Bay’s administration panel, by discovering multiple SQL injections, leading to the exposure of emails, MD5 hashes for passwords, and the IP address for any particular Pirate Bay user.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;Argentina&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Internet&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;Sweden&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://krebsonsecurity.com/2010/07/pirate-bay-hack-exposes-user-booty/&quot;&gt;KrebsOnSecurity.com&lt;/a></description>      <pubDate>Fri, 09 Jul 2010 09:41:37 -0400</pubDate>      <ddb:attackedentityfield>Internet</ddb:attackedentityfield>      <ddb:attackedentitygeography>Sweden</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography>Argentina</ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>July 5, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-152: The Pirate Bay hacked</ddb:entrytitle>      <ddb:incidentdescription>According to an advisory posted on the web site of Argentinian group of security researchers, they were able to obtain access to the Pirate Bay’s administration panel, by discovering multiple SQL injections, leading to the exposure of emails, MD5 hashes for passwords, and the IP address for any particular Pirate Bay user.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Disclosure Only</ddb:outcome>      <ddb:reference>KrebsOnSecurity.com</ddb:reference>      <ddb:whidid>2010-152</ddb:whidid>    </item>    <item>      <title>WHID 2010-151: YouTube Hacked</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=57847</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-151: YouTube Hacked&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-151&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;July 4, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Defacement&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;Today, members of the Internet communities 4chan and other enterprising computer whizzes hacked YouTube using a vulnerability in the site’s comment system. While the hack was used on a variety of videos, striking music videos featuring teen pop idol Justin Bieber was the most popular activity.&lt;br&gt;Twitter lit up with complaints about the problem, Google support got some concerned posts on its forum, and we received tips in our inbox. The event caused quite a Sunday-morning stir.&lt;br&gt;The bug allowed users to inject HTML (the code that most websites are built with) that could be executed on the site, whereas HTML within comments is supposed to be restricted. The hackers did everything from force pop-up messages to appear over the site declaring that it had been hacked to redirecting Bieber video pages to sites hosting pornography and malware.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Web 2.0&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://www.acunetix.com/blog/web-security-zone/articles/dangerous-xss-vulnerability-found-on-youtube-the-vulnerability-explained/&quot;&gt;http://www.acunetix.com/blog/web-security-zone/articles/dangerous-xss-vulnerability-found-on-youtube-the-vulnerability-explained/&lt;/a></description>      <pubDate>Wed, 07 Jul 2010 23:06:17 -0400</pubDate>      <ddb:attackedentityfield>Web 2.0</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>July 4, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-151: YouTube Hacked</ddb:entrytitle>      <ddb:incidentdescription>Today, members of the Internet communities 4chan and other enterprising computer whizzes hacked YouTube using a vulnerability in the site’s comment system. While the hack was used on a variety of videos, striking music videos featuring teen pop idol Justin Bieber was the most popular activity.&#13;&#10;&#13;&#10;Twitter lit up with complaints about the problem, Google support got some concerned posts on its forum, and we received tips in our inbox. The event caused quite a Sunday-morning stir.&#13;&#10;&#13;&#10;The bug allowed users to inject HTML (the code that most websites are built with) that could be executed on the site, whereas HTML within comments is supposed to be restricted. The hackers did everything from force pop-up messages to appear over the site declaring that it had been hacked to redirecting Bieber video pages to sites hosting pornography and malware.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Defacement</ddb:outcome>      <ddb:reference>http://www.acunetix.com/blog/web-security-zone/articles/dangerous-xss-vulnerability-found-on-youtube-the-vulnerability-explained/</ddb:reference>      <ddb:whidid>2010-151</ddb:whidid>    </item>    <item>      <title>WHID 2010-150: At least four Armenian websites were attacked by Azerbaijani hackers</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=57834</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-150: At least four Armenian websites were attacked by Azerbaijani hackers&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-150&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;July 3, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Defacement&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;At least four Armenian websites were attacked by Azerbaijani hackers during a week.&lt;br&gt;On July 2, the websites of Henaran.am press club (Henaran.am) and Armenia's Sambo Federation (sambo.am) were hacked to place Azerbaijan's flag and references to Azerbaijani media on them. Meanwhile, the websites' operation has already been resumed.&lt;br&gt;Besides, on June 29, hackers attacked Azdagir.am site of announcements again to place the Azerbaijani flag on it, as well as information on the January 20, 1990, events in Baku. On June 30, the owner of psyarmenia.com website told PanARMENIAN.Net that the site on psychology was hacked and a poster on &quot;Armenian terror&quot; was placed on it. Currently, the two websites do not operate.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Government&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;Armenia&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://www.panarmenian.net/eng/it_telecom/news/50897/At_least_four_Armenian_websites_were_attacked_by_Azerbaijani_hackers&quot;&gt;http://www.panarmenian.net/eng/it_telecom/news/50897/At_least_four_Armenian_websites_were_attacked_by_Azerbaijani_hackers&lt;/a></description>      <pubDate>Wed, 07 Jul 2010 22:51:12 -0400</pubDate>      <ddb:attackedentityfield>Government</ddb:attackedentityfield>      <ddb:attackedentitygeography>Armenia</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>July 3, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-150: At least four Armenian websites were attacked by Azerbaijani hackers</ddb:entrytitle>      <ddb:incidentdescription>At least four Armenian websites were attacked by Azerbaijani hackers during a week.&#13;&#10;&#13;&#10;On July 2, the websites of Henaran.am press club (Henaran.am) and Armenia's Sambo Federation (sambo.am) were hacked to place Azerbaijan's flag and references to Azerbaijani media on them. Meanwhile, the websites' operation has already been resumed.&#13;&#10;&#13;&#10;Besides, on June 29, hackers attacked Azdagir.am site of announcements again to place the Azerbaijani flag on it, as well as information on the January 20, 1990, events in Baku. On June 30, the owner of psyarmenia.com website told PanARMENIAN.Net that the site on psychology was hacked and a poster on &quot;Armenian terror&quot; was placed on it. Currently, the two websites do not operate.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Defacement</ddb:outcome>      <ddb:reference>http://www.panarmenian.net/eng/it_telecom/news/50897/At_least_four_Armenian_websites_were_attacked_by_Azerbaijani_hackers</ddb:reference>      <ddb:whidid>2010-150</ddb:whidid>    </item>    <item>      <title>WHID 2010-149: Identity Stolen Through X-Box Live</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=57821</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-149: Identity Stolen Through X-Box Live&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-149&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;July 3, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Monetary Loss&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;Rosalinda Gonzalez's bought the X-Box 360 console for her sons. They enjoy playing the video games and using the live service where they can connect with players from around the world.&lt;br&gt;In order to purchase the monthly live membership, Gonzalez entered her credit card information to her son's online profile. It is suppose to be kept private but Gonzalez says her son's profile was hacked by a computer whiz.&lt;br&gt;The man changed her son's password, stole game points and started making purchases using her credit card information. She says her boys actually spoke to the hacker through X-Box live. The man admitted to stealing other people's personal information too. &lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Entertainment&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://www.krgv.com/content/news/story/Identity-Stolen-Through-X-Box-Live/vKZIV1Rboki6lngI78Qf_w.cspx&quot;&gt;http://www.krgv.com/content/news/story/Identity-Stolen-Through-X-Box-Live/vKZIV1Rboki6lngI78Qf_w.cspx&lt;/a></description>      <pubDate>Wed, 07 Jul 2010 22:45:29 -0400</pubDate>      <ddb:attackedentityfield>Entertainment</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>July 3, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-149: Identity Stolen Through X-Box Live</ddb:entrytitle>      <ddb:incidentdescription>Rosalinda Gonzalez's bought the X-Box 360 console for her sons. They enjoy playing the video games and using the live service where they can connect with players from around the world.&#13;&#10;&#13;&#10;In order to purchase the monthly live membership, Gonzalez entered her credit card information to her son's online profile. It is suppose to be kept private but Gonzalez says her son's profile was hacked by a computer whiz.&#13;&#10;&#13;&#10;The man changed her son's password, stole game points and started making purchases using her credit card information. She says her boys actually spoke to the hacker through X-Box live. The man admitted to stealing other people's personal information too. </ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Monetary Loss</ddb:outcome>      <ddb:reference>http://www.krgv.com/content/news/story/Identity-Stolen-Through-X-Box-Live/vKZIV1Rboki6lngI78Qf_w.cspx</ddb:reference>      <ddb:whidid>2010-149</ddb:whidid>    </item>    <item>      <title>WHID 2010-148: AsSeenOnTV SQL injection into corporate web server exposed credit card information of customers</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=57606</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-148: AsSeenOnTV SQL injection into corporate web server exposed credit card information of customers&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-148&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;June 29, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Planting of Malware&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;AsSeenOnTV website hacked via SQL Injection and planted malware.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Retail&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://datalossdb.org/incidents/2953&quot;&gt;http://datalossdb.org/incidents/2953&lt;/a></description>      <pubDate>Tue, 29 Jun 2010 14:23:56 -0400</pubDate>      <ddb:attackedentityfield>Retail</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>June 29, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-148: AsSeenOnTV SQL injection into corporate web server exposed credit card information of customers</ddb:entrytitle>      <ddb:incidentdescription>AsSeenOnTV website hacked via SQL Injection and planted malware.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Planting of Malware</ddb:outcome>      <ddb:reference>http://datalossdb.org/incidents/2953</ddb:reference>      <ddb:whidid>2010-148</ddb:whidid>    </item>    <item>      <title>WHID 2010-147: Biggest blog company Skyblog hacked 32,000,000 accounts stolen</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=57579</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-147: Biggest blog company Skyblog hacked 32,000,000 accounts stolen&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-147&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;May 19, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;Earlier this week, IT staff Skyrock / Skyblog audit its servers, an old classic that can trace bugs and small technical malfunctions. Except this time, the &quot;bug&quot; seems to be much more serious. A filenamed &quot;hello&quot;and some scripts are discovered on a server. Neither one, nor two, the alert is triggered. A more complete audit is implemented. It is then discovered that an intrusion has been orchestrated from a backdoor downloaded via a service misconfigured (Waka) &quot;Download&quot;. From this facility, malicious, or the pirates have certainly got their hands on more than 32 million accounts skyblogueurs. It seems that the intruder will be difficult to trace. He crushed the logs after its passage. A ip appears, however, it resulted in a proxy, based in England. The drafting of ZATAZ.COM could know the exact date of the intrusion.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Blogs&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;France&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://datalossdb.org/incidents/2948&quot;&gt;http://datalossdb.org/incidents/2948&lt;/a></description>      <pubDate>Tue, 29 Jun 2010 14:17:00 -0400</pubDate>      <ddb:attackedentityfield>Blogs</ddb:attackedentityfield>      <ddb:attackedentitygeography>France</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>May 19, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-147: Biggest blog company Skyblog hacked 32,000,000 accounts stolen</ddb:entrytitle>      <ddb:incidentdescription>Earlier this week, IT staff Skyrock / Skyblog audit its servers, an old classic that can trace bugs and small technical malfunctions. Except this time, the &quot;bug&quot; seems to be much more serious. A filenamed &quot;hello&quot;and some scripts are discovered on a server. Neither one, nor two, the alert is triggered. A more complete audit is implemented. It is then discovered that an intrusion has been orchestrated from a backdoor downloaded via a service misconfigured (Waka) &quot;Download&quot;. From this facility, malicious, or the pirates have certainly got their hands on more than 32 million accounts skyblogueurs. It seems that the intruder will be difficult to trace. He crushed the logs after its passage. A ip appears, however, it resulted in a proxy, based in England. The drafting of ZATAZ.COM could know the exact date of the intrusion.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference>http://datalossdb.org/incidents/2948</ddb:reference>      <ddb:whidid>2010-147</ddb:whidid>    </item>    <item>      <title>WHID 2010-146: Hacking ring busted over test scores</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=57566</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-146: Hacking ring busted over test scores&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-146&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;June 29, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Disinformation&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;Police in Jinan, Shandong Province arrested several members of a ring that hacked into education websites to change test scores and forge credentials for cash.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;China&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Education&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;China&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://english.people.com.cn/90001/90776/90882/7044956.html&quot;&gt;http://english.people.com.cn/90001/90776/90882/7044956.html&lt;/a></description>      <pubDate>Tue, 29 Jun 2010 14:07:03 -0400</pubDate>      <ddb:attackedentityfield>Education</ddb:attackedentityfield>      <ddb:attackedentitygeography>China</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography>China</ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>June 29, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-146: Hacking ring busted over test scores</ddb:entrytitle>      <ddb:incidentdescription>Police in Jinan, Shandong Province arrested several members of a ring that hacked into education websites to change test scores and forge credentials for cash.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Disinformation</ddb:outcome>      <ddb:reference>http://english.people.com.cn/90001/90776/90882/7044956.html</ddb:reference>      <ddb:whidid>2010-146</ddb:whidid>    </item>    <item>      <title>WHID 2010-145: Hacker tries to manipulate Maine's legislative website</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=57547</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-145: Hacker tries to manipulate Maine's legislative website&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-145&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;June 29, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Planting of Malware&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;The state's online database of legislative activity has been taken offline because of an attempt by an unknown hacker to manipulate the website's coding.&lt;br&gt;On Thursday, the Legislature's information technology officials shut down the website's bill status function, which allows users to follow legislation such as roll calls, committee votes, amendments and fiscal notes.&lt;br&gt;The manipulated code inserted the addresses of extraneous websites that could have exposed users' computers to harm if they clicked on the links, said Scott Clark, director of information technology for the Legislature.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Government&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;Maine&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://www.pressherald.com/news/hacker-tries-to-manipulate-legislative-website-_2010-06-29.html&quot;&gt;http://www.pressherald.com/news/hacker-tries-to-manipulate-legislative-website-_2010-06-29.html&lt;/a></description>      <pubDate>Tue, 29 Jun 2010 14:01:39 -0400</pubDate>      <ddb:attackedentityfield>Government</ddb:attackedentityfield>      <ddb:attackedentitygeography>Maine</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>June 29, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-145: Hacker tries to manipulate Maine's legislative website</ddb:entrytitle>      <ddb:incidentdescription>The state's online database of legislative activity has been taken offline because of an attempt by an unknown hacker to manipulate the website's coding.&#13;&#10;&#13;&#10;On Thursday, the Legislature's information technology officials shut down the website's bill status function, which allows users to follow legislation such as roll calls, committee votes, amendments and fiscal notes.&#13;&#10;&#13;&#10;The manipulated code inserted the addresses of extraneous websites that could have exposed users' computers to harm if they clicked on the links, said Scott Clark, director of information technology for the Legislature.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Planting of Malware</ddb:outcome>      <ddb:reference>http://www.pressherald.com/news/hacker-tries-to-manipulate-legislative-website-_2010-06-29.html</ddb:reference>      <ddb:whidid>2010-145</ddb:whidid>    </item>    <item>      <title>WHID 2010-144: Hackers Steal $465,000 from Escrow Firm</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=57534</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-144: Hackers Steal $465,000 from Escrow Firm&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-144&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;June 29, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Monetary Loss&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;A total of $465,000 was recently stolen from California-based Village View Escrow via 26 consecutive wire transfers.&lt;br&gt;&quot;Owner Michelle Marisco said her financial institution at the time -- Professional Business Bank of Pasadena, Calif. -- normally notified her by e-mail each time a new wire was sent out of the company’s escrow account,&quot; writes Krebs on Security's Brian Krebs. &quot;But the attackers apparently disabled that feature before initiating the fraudulent wires.&quot;&lt;br&gt;&quot;Marisco said that a few days before the theft, she opened an e-mail informing her that a UPS package she had been sent was lost, and urging her to open the attached invoice,&quot; Krebs writes. &quot;Nothing happened when she opened the attached file, so she forwarded it on to her assistant who also tried to view it. The invoice was in fact a Trojan horse program that let the thieves break in and set up shop and plant a password-stealing virus on Marisco’s computer, and on the PC belonging to her assistant -- the second person needed to approve transfers.&quot;&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Finance&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;California&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://www.esecurityplanet.com/headlines/article.php/3890291/article.htm&quot;&gt;http://www.esecurityplanet.com/headlines/article.php/3890291/article.htm&lt;/a></description>      <pubDate>Tue, 29 Jun 2010 13:58:33 -0400</pubDate>      <ddb:attackedentityfield>Finance</ddb:attackedentityfield>      <ddb:attackedentitygeography>California</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>June 29, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-144: Hackers Steal $465,000 from Escrow Firm</ddb:entrytitle>      <ddb:incidentdescription>A total of $465,000 was recently stolen from California-based Village View Escrow via 26 consecutive wire transfers.&#13;&#10;&#13;&#10;&quot;Owner Michelle Marisco said her financial institution at the time -- Professional Business Bank of Pasadena, Calif. -- normally notified her by e-mail each time a new wire was sent out of the company’s escrow account,&quot; writes Krebs on Security's Brian Krebs. &quot;But the attackers apparently disabled that feature before initiating the fraudulent wires.&quot;&#13;&#10;&#13;&#10;&quot;Marisco said that a few days before the theft, she opened an e-mail informing her that a UPS package she had been sent was lost, and urging her to open the attached invoice,&quot; Krebs writes. &quot;Nothing happened when she opened the attached file, so she forwarded it on to her assistant who also tried to view it. The invoice was in fact a Trojan horse program that let the thieves break in and set up shop and plant a password-stealing virus on Marisco’s computer, and on the PC belonging to her assistant -- the second person needed to approve transfers."</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Monetary Loss</ddb:outcome>      <ddb:reference>http://www.esecurityplanet.com/headlines/article.php/3890291/article.htm</ddb:reference>      <ddb:whidid>2010-144</ddb:whidid>    </item>    <item>      <title>WHID 2010-143: Whirlpool Repeatedly Hit by DDoS Attacks</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=57521</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-143: Whirlpool Repeatedly Hit by DDoS Attacks&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-143&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;June 29, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Downtime&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;Australian broadband news website Whirlpool.net.au was the target of several Distributed Denial of Service (DDoS) attacks this morning. The hosting provider moved quickly to mitigate, but attackers evaded the restrictions, causing an aggregated downtime of around ten hours.&lt;br&gt;Whirlpool.net.au is one of the most trafficked Australian websites, housing a community of over 350,000 registered users. It was started twelve years ago as a place to discuss Internet broadband services in the country, but has since evolved into a full-blown news website covering the telecommunications industry.&lt;br&gt;&quot;Bulletproof received monitoring alerts of packet loss at 12:45 am. We identified it as a classic denial-of-service attack being targeted at Whirlpool. We immediately blocked Whirlpool IP addresses to observe it better and then we were able to track down that it was originating from Denmark and the United States,&quot; Lorenzo Modesto, chief operating officer at Bulletproof Networks, the company hosting Whirlpool, commented for ZDNet Australia.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;Denmark&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Media&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;Australia&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://news.softpedia.com/news/Whirlpool-Repeatedly-Hit-by-DDoS-Attacks-145629.shtml&quot;&gt;http://news.softpedia.com/news/Whirlpool-Repeatedly-Hit-by-DDoS-Attacks-145629.shtml&lt;/a></description>      <pubDate>Tue, 29 Jun 2010 13:42:23 -0400</pubDate>      <ddb:attackedentityfield>Media</ddb:attackedentityfield>      <ddb:attackedentitygeography>Australia</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography>Denmark</ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>June 29, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-143: Whirlpool Repeatedly Hit by DDoS Attacks</ddb:entrytitle>      <ddb:incidentdescription>Australian broadband news website Whirlpool.net.au was the target of several Distributed Denial of Service (DDoS) attacks this morning. The hosting provider moved quickly to mitigate, but attackers evaded the restrictions, causing an aggregated downtime of around ten hours.&#13;&#10;&#13;&#10;Whirlpool.net.au is one of the most trafficked Australian websites, housing a community of over 350,000 registered users. It was started twelve years ago as a place to discuss Internet broadband services in the country, but has since evolved into a full-blown news website covering the telecommunications industry.&#13;&#10;&#13;&#10;&quot;Bulletproof received monitoring alerts of packet loss at 12:45 am. We identified it as a classic denial-of-service attack being targeted at Whirlpool. We immediately blocked Whirlpool IP addresses to observe it better and then we were able to track down that it was originating from Denmark and the United States,&quot; Lorenzo Modesto, chief operating officer at Bulletproof Networks, the company hosting Whirlpool, commented for ZDNet Australia.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Downtime</ddb:outcome>      <ddb:reference>http://news.softpedia.com/news/Whirlpool-Repeatedly-Hit-by-DDoS-Attacks-145629.shtml</ddb:reference>      <ddb:whidid>2010-143</ddb:whidid>    </item>    <item>      <title>WHID 2010-142: Hackers vandalise 200 web sites, cripple 150</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=57490</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-142: Hackers vandalise 200 web sites, cripple 150&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-142&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;June 28, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Downtime&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;The web sites of more than a whopping 200 Australian organisations were hijacked and vandalised in a spate of hacks last week.&lt;br&gt; In the largest single attack, a hacker gained administrative access to the Direct Admin server management system used by a hosting provider, who Computerworld Australia will not name, and suspended 159 accounts rendering their web sites inaccessible to the public.&lt;br&gt;The suspension notification page was then defaced with the hackers’ moniker and religious propaganda.&lt;br&gt;The hack was launched through a flaw created after an automatic patch of the admin system failed to complete.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Hosting Providers&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;Australia&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://www.computerworld.com.au/article/351360/hackers_vandalise_200_web_sites_cripple_150/&quot;&gt;http://www.computerworld.com.au/article/351360/hackers_vandalise_200_web_sites_cripple_150/&lt;/a></description>      <pubDate>Mon, 28 Jun 2010 14:25:26 -0400</pubDate>      <ddb:attackedentityfield>Hosting Providers</ddb:attackedentityfield>      <ddb:attackedentitygeography>Australia</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>June 28, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-142: Hackers vandalise 200 web sites, cripple 150</ddb:entrytitle>      <ddb:incidentdescription>The web sites of more than a whopping 200 Australian organisations were hijacked and vandalised in a spate of hacks last week.&#13;&#10;&#13;&#10; In the largest single attack, a hacker gained administrative access to the Direct Admin server management system used by a hosting provider, who Computerworld Australia will not name, and suspended 159 accounts rendering their web sites inaccessible to the public.&#13;&#10;&#13;&#10;The suspension notification page was then defaced with the hackers’ moniker and religious propaganda.&#13;&#10;&#13;&#10;The hack was launched through a flaw created after an automatic patch of the admin system failed to complete.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Downtime</ddb:outcome>      <ddb:reference>http://www.computerworld.com.au/article/351360/hackers_vandalise_200_web_sites_cripple_150/</ddb:reference>      <ddb:whidid>2010-142</ddb:whidid>    </item>    <item>      <title>WHID 2010-141: Virginia Right! Under Fire Yesterday With DDOS Attack</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=57477</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-141: Virginia Right! Under Fire Yesterday With DDOS Attack&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-141&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;June 27, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Downtime&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;Sorry for the outage yesterday between 8:00 AM and 7:00 PM. Virginia Right! was under attack with a Distributed Denial of Service. Part of the problem in resolving the issue is the fact that Virginia Right! is on a shared hosting server with many hosts using the same IP address. The first thing that has to be determined is which domain is under attack. They do this by temporarily assigning a static IP address to each site hosted on the server (as opposed to all of us sharing the same address). When they were done, everyone came back up except – Virginia Right!. So the attacks were specifically directed at us!&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Blogs&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;Virginia, USA&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://beforeitsnews.com/news/87/162/Virginia_Right_Under_Fire_Yesterday_With_DDOS_Attack.html&quot;&gt;http://beforeitsnews.com/news/87/162/Virginia_Right_Under_Fire_Yesterday_With_DDOS_Attack.html&lt;/a></description>      <pubDate>Mon, 28 Jun 2010 13:57:11 -0400</pubDate>      <ddb:attackedentityfield>Blogs</ddb:attackedentityfield>      <ddb:attackedentitygeography>Virginia, USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>June 27, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-141: Virginia Right! Under Fire Yesterday With DDOS Attack</ddb:entrytitle>      <ddb:incidentdescription>Sorry for the outage yesterday between 8:00 AM and 7:00 PM. Virginia Right! was under attack with a Distributed Denial of Service. Part of the problem in resolving the issue is the fact that Virginia Right! is on a shared hosting server with many hosts using the same IP address. The first thing that has to be determined is which domain is under attack. They do this by temporarily assigning a static IP address to each site hosted on the server (as opposed to all of us sharing the same address). When they were done, everyone came back up except – Virginia Right!. So the attacks were specifically directed at us!</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Downtime</ddb:outcome>      <ddb:reference>http://beforeitsnews.com/news/87/162/Virginia_Right_Under_Fire_Yesterday_With_DDOS_Attack.html</ddb:reference>      <ddb:whidid>2010-141</ddb:whidid>    </item>    <item>      <title>WHID 2010-140: Hackers fleece online poker players</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=57464</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-140: Hackers fleece online poker players&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-140&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;June 28, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Monetary Loss&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;Police arrested 33 hackers who used a “distribution of denial of service” program to cheat online poker players out of 55 million won ($45,265) from last November through May. &lt;br&gt;The hackers, led by 30-year-old Yu and 29-year-old Kim, were booked without detention on charges of gaining illegal profits.&lt;br&gt;The Cyber Terror Response Center in Gyeonggi said the gang used a DDOS attack to infect 11,000 computers at 700 PC rooms across the country.&lt;br&gt;Police said Yu bought the “Netbot Attacker” program from a Chinese hacker last November, then sold copies online to Kim and others. The gang broke into the administrative systems of the PC rooms and installed the virus in their computers to allow them to see the hands of poker opponents.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Entertainment&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;Korea&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://joongangdaily.joins.com/article/view.asp?aid=2922391&quot;&gt;http://joongangdaily.joins.com/article/view.asp?aid=2922391&lt;/a></description>      <pubDate>Mon, 28 Jun 2010 13:47:09 -0400</pubDate>      <ddb:attackedentityfield>Entertainment</ddb:attackedentityfield>      <ddb:attackedentitygeography>Korea</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>June 28, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-140: Hackers fleece online poker players</ddb:entrytitle>      <ddb:incidentdescription>Police arrested 33 hackers who used a “distribution of denial of service” program to cheat online poker players out of 55 million won ($45,265) from last November through May. &#13;&#10;&#13;&#10;The hackers, led by 30-year-old Yu and 29-year-old Kim, were booked without detention on charges of gaining illegal profits.&#13;&#10;&#13;&#10;The Cyber Terror Response Center in Gyeonggi said the gang used a DDOS attack to infect 11,000 computers at 700 PC rooms across the country.&#13;&#10;&#13;&#10;Police said Yu bought the “Netbot Attacker” program from a Chinese hacker last November, then sold copies online to Kim and others. The gang broke into the administrative systems of the PC rooms and installed the virus in their computers to allow them to see the hands of poker opponents.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Monetary Loss</ddb:outcome>      <ddb:reference>http://joongangdaily.joins.com/article/view.asp?aid=2922391</ddb:reference>      <ddb:whidid>2010-140</ddb:whidid>    </item>    <item>      <title>WHID 2010-139: Twitter XSS Vulnerability Possibly Exploited by Turkish Hackers</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=57451</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-139: Twitter XSS Vulnerability Possibly Exploited by Turkish Hackers&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-139&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;June 28, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Defacement&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;Dimitris Pagkalos, one of the founders of the XSSed, a project that maintains an archive of XSS flaws and raises awareness about this type of Web vulnerability, notes that Twitter's security team promptly addressed the bug. However, he suggests the vulnerability might have been used in an earlier attack that made a rogue status reading &quot;Hacked By Turkish Hackers&quot;  appear on almost one thousand Twitter profiles.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;Turkey&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Web 2.0&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA&lt;br&gt;&lt;b&gt;Attacked System Technology: &lt;/b&gt;Twitter&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://news.softpedia.com/news/Twitter-XSS-Vulnerability-Possibly-Exploited-by-Turkish-Hackers-145594.shtml&quot;&gt;http://news.softpedia.com/news/Twitter-XSS-Vulnerability-Possibly-Exploited-by-Turkish-Hackers-145594.shtml&lt;/a></description>      <pubDate>Mon, 28 Jun 2010 13:32:57 -0400</pubDate>      <ddb:attackedentityfield>Web 2.0</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology>Twitter</ddb:attackedsystemtechnology>      <ddb:attacksourcegeography>Turkey</ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>June 28, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-139: Twitter XSS Vulnerability Possibly Exploited by Turkish Hackers</ddb:entrytitle>      <ddb:incidentdescription>Dimitris Pagkalos, one of the founders of the XSSed, a project that maintains an archive of XSS flaws and raises awareness about this type of Web vulnerability, notes that Twitter's security team promptly addressed the bug. However, he suggests the vulnerability might have been used in an earlier attack that made a rogue status reading &quot;Hacked By Turkish Hackers&quot;  appear on almost one thousand Twitter profiles.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Defacement</ddb:outcome>      <ddb:reference>http://news.softpedia.com/news/Twitter-XSS-Vulnerability-Possibly-Exploited-by-Turkish-Hackers-145594.shtml</ddb:reference>      <ddb:whidid>2010-139</ddb:whidid>    </item>    <item>      <title>WHID 2010-138: Personal data accessed on Blue Cross website</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=57432</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-138: Personal data accessed on Blue Cross website&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-138&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;June 23, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;In a written statement, Anthem Blue Cross explained how the breach occurred:&lt;br&gt;&quot;The ability to manipulate the web address (URL) was available for a relatively short period of time following an upgrade to the system. After the upgrade was completed, a third party vendor validated that all security measures were in place, when in fact they were not. As soon as the situation was discovered, we made the necessary security changes to prevent it from happening again.&quot;&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Health&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://www.ocregister.com/articles/information-254735-security-anthem.html&quot;&gt;http://www.ocregister.com/articles/information-254735-security-anthem.html&lt;/a></description>      <pubDate>Thu, 24 Jun 2010 18:57:42 -0400</pubDate>      <ddb:attackedentityfield>Health</ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>June 23, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-138: Personal data accessed on Blue Cross website</ddb:entrytitle>      <ddb:incidentdescription>In a written statement, Anthem Blue Cross explained how the breach occurred:&#13;&#10;&quot;The ability to manipulate the web address (URL) was available for a relatively short period of time following an upgrade to the system. After the upgrade was completed, a third party vendor validated that all security measures were in place, when in fact they were not. As soon as the situation was discovered, we made the necessary security changes to prevent it from happening again."</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference>http://www.ocregister.com/articles/information-254735-security-anthem.html</ddb:reference>      <ddb:whidid>2010-138</ddb:whidid>    </item>    <item>      <title>WHID 2010-137: Persistent XSS on Twitter.com</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=57413</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-137: Persistent XSS on Twitter.com&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-137&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;June 24, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Defacement&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;Twitter user 0wn3d_5ys has demonstrated a persistent cross site scripting (XSS) vulnerability on Twitter he found on June 21st using his own Twitter account (visit at your own risk) that appears to be due to a lack of input validation of the application name field when accepting new requests for Twitter applications. Visiting his account on Twitter results in a pair of classic cross site scripting alert boxes, then your browser is manipulated, finally you enter the matrix (see below), and get messages from the researcher who found the vulnerability. &lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Web 2.0&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA&lt;br&gt;&lt;b&gt;Attacked System Technology: &lt;/b&gt;Twitter&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://praetorianprefect.com/archives/2010/06/persistent-xss-on-twitter-com/&quot;&gt;http://praetorianprefect.com/archives/2010/06/persistent-xss-on-twitter-com/&lt;/a></description>      <pubDate>Thu, 24 Jun 2010 13:07:41 -0400</pubDate>      <ddb:attackedentityfield>Web 2.0</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology>Twitter</ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>June 24, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-137: Persistent XSS on Twitter.com</ddb:entrytitle>      <ddb:incidentdescription>Twitter user 0wn3d_5ys has demonstrated a persistent cross site scripting (XSS) vulnerability on Twitter he found on June 21st using his own Twitter account (visit at your own risk) that appears to be due to a lack of input validation of the application name field when accepting new requests for Twitter applications. Visiting his account on Twitter results in a pair of classic cross site scripting alert boxes, then your browser is manipulated, finally you enter the matrix (see below), and get messages from the researcher who found the vulnerability. </ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Defacement</ddb:outcome>      <ddb:reference>http://praetorianprefect.com/archives/2010/06/persistent-xss-on-twitter-com/</ddb:reference>      <ddb:whidid>2010-137</ddb:whidid>    </item>    <item>      <title>WHID 2010-136: Hotel account hacked, card info stolen</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=57400</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-136: Hotel account hacked, card info stolen&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-136&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;June 23, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Credit Card Leakage&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;Dozens of Driskill Hotel customers' credit card information has been stolen. Hackers in Europe were able to break into the hotel's parent company's website and steal the information. There are more than 700 victims nationwide.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Hospitality&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;Austin, TX&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://www.kxan.com/dpp/news/hotel-account-hacked,-card-info-stolen&quot;&gt;http://www.kxan.com/dpp/news/hotel-account-hacked,-card-info-stolen&lt;/a></description>      <pubDate>Thu, 24 Jun 2010 13:03:00 -0400</pubDate>      <ddb:attackedentityfield>Hospitality</ddb:attackedentityfield>      <ddb:attackedentitygeography>Austin, TX</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>June 23, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-136: Hotel account hacked, card info stolen</ddb:entrytitle>      <ddb:incidentdescription>Dozens of Driskill Hotel customers' credit card information has been stolen. Hackers in Europe were able to break into the hotel's parent company's website and steal the information. There are more than 700 victims nationwide.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Credit Card Leakage</ddb:outcome>      <ddb:reference>http://www.kxan.com/dpp/news/hotel-account-hacked,-card-info-stolen</ddb:reference>      <ddb:whidid>2010-136</ddb:whidid>    </item>    <item>      <title>WHID 2010-135: Another round of Asprox SQL injection attacks</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=57381</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-135: Another round of Asprox SQL injection attacks&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-135&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;June 23, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Planting of Malware&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;Earlier this month, we reported on a new variant of Asprox malware which was being spammed out by the Pushdo botnet. At that time, the Asprox executables we analyzed were purely sending spam. However, a few days after our post, we noticed reports of mass infections of IIS/ASP websites. The nature of these attacks reminded us of SQL injection attacks back in 2008 where Asprox was clearly involved. We suspected that the re-emergence of Asprox and these new mass website infections were not merely a coincidence. Well, this week our suspicions were confirmed when we came across another version of Asprox which started to launch both spam and SQL injection attacks.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://www.m86security.com/labs/i/Another-round-of-Asprox-SQL-injection-attacks,trace.1366~.asp&quot;&gt;http://www.m86security.com/labs/i/Another-round-of-Asprox-SQL-injection-attacks,trace.1366~.asp&lt;/a></description>      <pubDate>Thu, 24 Jun 2010 13:00:14 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>June 23, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-135: Another round of Asprox SQL injection attacks</ddb:entrytitle>      <ddb:incidentdescription>Earlier this month, we reported on a new variant of Asprox malware which was being spammed out by the Pushdo botnet. At that time, the Asprox executables we analyzed were purely sending spam. However, a few days after our post, we noticed reports of mass infections of IIS/ASP websites. The nature of these attacks reminded us of SQL injection attacks back in 2008 where Asprox was clearly involved. We suspected that the re-emergence of Asprox and these new mass website infections were not merely a coincidence. Well, this week our suspicions were confirmed when we came across another version of Asprox which started to launch both spam and SQL injection attacks.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Planting of Malware</ddb:outcome>      <ddb:reference>http://www.m86security.com/labs/i/Another-round-of-Asprox-SQL-injection-attacks,trace.1366~.asp</ddb:reference>      <ddb:whidid>2010-135</ddb:whidid>    </item>    <item>      <title>WHID 2010-134: Major hack of Israeli Twitter accounts</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=57317</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-134: Major hack of Israeli Twitter accounts&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-134&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;June 22, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Defacement&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;According to Mikko Hyponnen, chief research officer with F-Secure, more than 1000 accounts on the microblogging social networking service were hacked within the space of 12 hours, each of them broadcasting the message: &quot;Hacked by Turkish Hackers.&quot;&lt;br&gt;In a security blog posting made last night, Hyponnen said that, although the exploit mechanism is unclear, most of the compromised accounts &quot;seem to seem to belong to Israeli Twitter users.&quot;&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;Turkey&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Web 2.0&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;Israel&lt;br&gt;&lt;b&gt;Attacked System Technology: &lt;/b&gt;Twitter&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://www.infosecurity-magazine.com/view/10426/major-hack-of-israeli-twitter-accounts-/&quot;&gt;http://www.infosecurity-magazine.com/view/10426/major-hack-of-israeli-twitter-accounts-/&lt;/a></description>      <pubDate>Tue, 22 Jun 2010 23:49:57 -0400</pubDate>      <ddb:attackedentityfield>Web 2.0</ddb:attackedentityfield>      <ddb:attackedentitygeography>Israel</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology>Twitter</ddb:attackedsystemtechnology>      <ddb:attacksourcegeography>Turkey</ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>June 22, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-134: Major hack of Israeli Twitter accounts</ddb:entrytitle>      <ddb:incidentdescription>According to Mikko Hyponnen, chief research officer with F-Secure, more than 1000 accounts on the microblogging social networking service were hacked within the space of 12 hours, each of them broadcasting the message: &quot;Hacked by Turkish Hackers.&quot;&#13;&#10;&#13;&#10;In a security blog posting made last night, Hyponnen said that, although the exploit mechanism is unclear, most of the compromised accounts &quot;seem to seem to belong to Israeli Twitter users."</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Defacement</ddb:outcome>      <ddb:reference>http://www.infosecurity-magazine.com/view/10426/major-hack-of-israeli-twitter-accounts-/</ddb:reference>      <ddb:whidid>2010-134</ddb:whidid>    </item>    <item>      <title>WHID 2010-133: Druknet websites hacked</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=57280</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-133: Druknet websites hacked&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-133&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;June 19, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Defacement&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;Local internet service provider (ISP) Druknet is currently recovering, after 50 of its websites were hacked early yesterday.&lt;br&gt;Users trying to access certain websites hosted by the ISP were greeted with a blank home page and a message that said the website had been hacked.&lt;br&gt;Although some of the hacked websites were back online by afternoon, many websites were still down as of last night. Druknet’s web server, on which the websites are stored, was also taken offline periodically throughout yesterday.&lt;br&gt;The hacker or hackers had exploited websites designed, using free open sourced content management systems (CMS), like Word Press, according to Druknet.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Hosting Providers&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;Bhutan&lt;br&gt;&lt;b&gt;Attacked System Technology: &lt;/b&gt;WordPress&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://www.kuenselonline.com/modules.php?name=News&amp;file=article&amp;sid=15822&quot;&gt;http://www.kuenselonline.com/modules.php?name=News&amp;file=article&amp;sid=15822&lt;/a></description>      <pubDate>Mon, 21 Jun 2010 20:19:03 -0400</pubDate>      <ddb:attackedentityfield>Hosting Providers</ddb:attackedentityfield>      <ddb:attackedentitygeography>Bhutan</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology>WordPress</ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>June 19, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-133: Druknet websites hacked</ddb:entrytitle>      <ddb:incidentdescription>Local internet service provider (ISP) Druknet is currently recovering, after 50 of its websites were hacked early yesterday.&#13;&#10;&#13;&#10;Users trying to access certain websites hosted by the ISP were greeted with a blank home page and a message that said the website had been hacked.&#13;&#10;&#13;&#10;Although some of the hacked websites were back online by afternoon, many websites were still down as of last night. Druknet’s web server, on which the websites are stored, was also taken offline periodically throughout yesterday.&#13;&#10;&#13;&#10;The hacker or hackers had exploited websites designed, using free open sourced content management systems (CMS), like Word Press, according to Druknet.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Defacement</ddb:outcome>      <ddb:reference>http://www.kuenselonline.com/modules.php?name=News&amp;file=article&amp;sid=15822</ddb:reference>      <ddb:whidid>2010-133</ddb:whidid>    </item>    <item>      <title>WHID 2010-132: Another Opposition Website Shut Down by Hackers</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=57261</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-132: Another Opposition Website Shut Down by Hackers&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-132&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;June 19, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Downtime&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;The popular Burmese Web site photayokeking.org, edited by a Burmese army deserter, was recently attacked, leaving it inaccessible and out of operation.&lt;br&gt;According to one of the editors, who goes by the name Photayoke, the Web site came under major attacks on May 27 and June 11, following three smaller attacks.&lt;br&gt;On June 11, the server provider sent an email to the Web site's owners stating that a major distributed denial-of-service attack (DDoS) had been focused on their data center.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;Burma&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;News&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;Burma&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://www.irrawaddy.org/article.php?art_id=18759&quot;&gt;http://www.irrawaddy.org/article.php?art_id=18759&lt;/a></description>      <pubDate>Mon, 21 Jun 2010 20:04:56 -0400</pubDate>      <ddb:attackedentityfield>News</ddb:attackedentityfield>      <ddb:attackedentitygeography>Burma</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography>Burma</ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>June 19, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-132: Another Opposition Website Shut Down by Hackers</ddb:entrytitle>      <ddb:incidentdescription>The popular Burmese Web site photayokeking.org, edited by a Burmese army deserter, was recently attacked, leaving it inaccessible and out of operation.&#13;&#10;&#13;&#10;According to one of the editors, who goes by the name Photayoke, the Web site came under major attacks on May 27 and June 11, following three smaller attacks.&#13;&#10;&#13;&#10;On June 11, the server provider sent an email to the Web site's owners stating that a major distributed denial-of-service attack (DDoS) had been focused on their data center.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Downtime</ddb:outcome>      <ddb:reference>http://www.irrawaddy.org/article.php?art_id=18759</ddb:reference>      <ddb:whidid>2010-132</ddb:whidid>    </item>    <item>      <title>WHID 2010-131: DoS attack stuffs Turkey's internet censors</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=57236</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-131: DoS attack stuffs Turkey's internet censors&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-131&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;June 18, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Downtime&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;Access to the internet in Turkey is becoming increasingly ragged, as growing state censorship collides with retaliation by anti-censorship hackers, leading to difficulties both in viewing sites and applying key online functions.&lt;br&gt;Since early this morning the websites of the Ministry of Transportation, the Information and Communication Technologies Authority and the Telecommunications Communication Presidency have been inaccessible. These three state bodies are responsible for internet censorship and have been the principal actors behind attempts to block access to YouTube and Google-related services in Turkey.&lt;br&gt;A number of theories abound, with favourites the state authorities’ websites have either been hacked or subject to a serious denial of service attack by hackers unhappy at the censorship.&lt;br&gt;Writing for the CyberLaw UK Blog, Dr Yaman Akdeniz, Associate Professor at the Faculty of Law, Istanbul Bilgi University, now writes that it has been confirmed as a denial of service attack coordinated by a group of hackers to protest against internet censorship in Turkey, and that the attack lasted 10 hours.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;Turkey&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Government&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;Turkey&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://www.theregister.co.uk/2010/06/18/turkey_dos_attack/&quot;&gt;http://www.theregister.co.uk/2010/06/18/turkey_dos_attack/&lt;/a></description>      <pubDate>Fri, 18 Jun 2010 16:20:55 -0400</pubDate>      <ddb:attackedentityfield>Government</ddb:attackedentityfield>      <ddb:attackedentitygeography>Turkey</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography>Turkey</ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>June 18, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-131: DoS attack stuffs Turkey's internet censors</ddb:entrytitle>      <ddb:incidentdescription>Access to the internet in Turkey is becoming increasingly ragged, as growing state censorship collides with retaliation by anti-censorship hackers, leading to difficulties both in viewing sites and applying key online functions.&#13;&#10;Since early this morning the websites of the Ministry of Transportation, the Information and Communication Technologies Authority and the Telecommunications Communication Presidency have been inaccessible. These three state bodies are responsible for internet censorship and have been the principal actors behind attempts to block access to YouTube and Google-related services in Turkey.&#13;&#10;&#13;&#10;A number of theories abound, with favourites the state authorities’ websites have either been hacked or subject to a serious denial of service attack by hackers unhappy at the censorship.&#13;&#10;&#13;&#10;Writing for the CyberLaw UK Blog, Dr Yaman Akdeniz, Associate Professor at the Faculty of Law, Istanbul Bilgi University, now writes that it has been confirmed as a denial of service attack coordinated by a group of hackers to protest against internet censorship in Turkey, and that the attack lasted 10 hours.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Downtime</ddb:outcome>      <ddb:reference>http://www.theregister.co.uk/2010/06/18/turkey_dos_attack/</ddb:reference>      <ddb:whidid>2010-131</ddb:whidid>    </item>    <item>      <title>WHID 2010-130: Google Trends Hacked With Racial Slur (Again!)</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=57018</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-130: Google Trends Hacked With Racial Slur (Again!)&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-130&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;June 17, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Disinformation&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;Google Trends is a powerful tool that many media companies (us included) rely upon for a sense of what new topics people are searching for at any given time -- at least, when it's not getting hacked with racial slurs, which is exactly what happened early this morning.&lt;br&gt;At around 9 a.m. Eastern, instead of the normal list of the hottest new search terms of the hour, visitors to the Google Trends website were greeted with the phrase &quot;lol n------&quot;. &lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Search Engine&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;San Jose, California&lt;br&gt;&lt;b&gt;Attacked System Technology: &lt;/b&gt;Google&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://www.politicsdaily.com/2010/06/17/google-trends-hacked-with-racial-slur-again/&quot;&gt;http://www.politicsdaily.com/2010/06/17/google-trends-hacked-with-racial-slur-again/&lt;/a></description>      <pubDate>Thu, 17 Jun 2010 18:07:43 -0400</pubDate>      <ddb:attackedentityfield>Search Engine</ddb:attackedentityfield>      <ddb:attackedentitygeography>San Jose, California</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology>Google</ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>June 17, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-130: Google Trends Hacked With Racial Slur (Again!)</ddb:entrytitle>      <ddb:incidentdescription>Google Trends is a powerful tool that many media companies (us included) rely upon for a sense of what new topics people are searching for at any given time -- at least, when it's not getting hacked with racial slurs, which is exactly what happened early this morning.&#13;&#10;&#13;&#10;At around 9 a.m. Eastern, instead of the normal list of the hottest new search terms of the hour, visitors to the Google Trends website were greeted with the phrase &quot;lol n------&quot;. </ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Disinformation</ddb:outcome>      <ddb:reference>http://www.politicsdaily.com/2010/06/17/google-trends-hacked-with-racial-slur-again/</ddb:reference>      <ddb:whidid>2010-130</ddb:whidid>    </item>    <item>      <title>WHID 2010-129: Hackers Seize Top Tory’s Facebook, Blog &amp; Twitter Accounts</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=56944</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-129: Hackers Seize Top Tory’s Facebook, Blog &amp; Twitter Accounts&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-129&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;June 17, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Disinformation&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;hackers have stolen the account details of Therese Coffey, Tory candidate for Suffolk Coastal (UK Parliament constituency), London Spin can exclusively reveal. The attackers bombarded social media users with sexually explicit messages and comments after gaining access to her Blog, Facebook and Twitter account details.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Web 2.0&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;London, England&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://www.londonspinonline.com/2010/06/exclusive-hackers-seize-top-torys.html&quot;&gt;http://www.londonspinonline.com/2010/06/exclusive-hackers-seize-top-torys.html&lt;/a></description>      <pubDate>Thu, 17 Jun 2010 17:26:28 -0400</pubDate>      <ddb:attackedentityfield>Web 2.0</ddb:attackedentityfield>      <ddb:attackedentitygeography>London, England</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>June 17, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-129: Hackers Seize Top Tory’s Facebook, Blog &amp; Twitter Accounts</ddb:entrytitle>      <ddb:incidentdescription>hackers have stolen the account details of Therese Coffey, Tory candidate for Suffolk Coastal (UK Parliament constituency), London Spin can exclusively reveal. The attackers bombarded social media users with sexually explicit messages and comments after gaining access to her Blog, Facebook and Twitter account details.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Disinformation</ddb:outcome>      <ddb:reference>http://www.londonspinonline.com/2010/06/exclusive-hackers-seize-top-torys.html</ddb:reference>      <ddb:whidid>2010-129</ddb:whidid>    </item>    <item>      <title>WHID 2010-128: Microsoft Sues Alleged Spammer For Circumventing Filters</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=56931</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-128: Microsoft Sues Alleged Spammer For Circumventing Filters&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-128&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;June 16, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Spam&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;Microsoft has sued Connecticut resident Boris Mizhen for allegedly gaming Hotmail's spam filters and sending unwanted emails to consumers.  Mizhen, who previously settled a separate spam lawsuit brought by Microsoft, allegedly got around the company's anti-spam system by creating millions of new email accounts and then arranging for those accounts to classify his messages as &quot;not spam,&quot; according to the lawsuit.&lt;br&gt;&quot;Defendants developed and executed an elaborate scheme to circumvent Microsoft's Hotmail spam filters to disseminate a large quantity of spam email advertisements to Microsoft's Hotmail users,&quot; the company alleges in its complaint, filed last week in federal district court in Seattle.&lt;br&gt;The complaint details how Mizhen and his affiliates allegedly manipulated the statistics that Microsoft's anti-spam system relies on by creating millions of new email accounts and then moving up to 200,000 of their own messages a day from &quot;junk&quot; files into inboxes.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;Connecticut, USA&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Information Services&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;Washington, USA&lt;br&gt;&lt;b&gt;Attacked System Technology: &lt;/b&gt;Hotmail&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://www.mediapost.com/publications/?fa=Articles.showArticle&amp;art_aid=130320&quot;&gt;http://www.mediapost.com/publications/?fa=Articles.showArticle&amp;art_aid=130320&lt;/a></description>      <pubDate>Thu, 17 Jun 2010 17:22:41 -0400</pubDate>      <ddb:attackedentityfield>Information Services</ddb:attackedentityfield>      <ddb:attackedentitygeography>Washington, USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology>Hotmail</ddb:attackedsystemtechnology>      <ddb:attacksourcegeography>Connecticut, USA</ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>June 16, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-128: Microsoft Sues Alleged Spammer For Circumventing Filters</ddb:entrytitle>      <ddb:incidentdescription>Microsoft has sued Connecticut resident Boris Mizhen for allegedly gaming Hotmail's spam filters and sending unwanted emails to consumers.  Mizhen, who previously settled a separate spam lawsuit brought by Microsoft, allegedly got around the company's anti-spam system by creating millions of new email accounts and then arranging for those accounts to classify his messages as &quot;not spam,&quot; according to the lawsuit.&#13;&#10;&quot;Defendants developed and executed an elaborate scheme to circumvent Microsoft's Hotmail spam filters to disseminate a large quantity of spam email advertisements to Microsoft's Hotmail users,&quot; the company alleges in its complaint, filed last week in federal district court in Seattle.&#13;&#10;&#13;&#10;The complaint details how Mizhen and his affiliates allegedly manipulated the statistics that Microsoft's anti-spam system relies on by creating millions of new email accounts and then moving up to 200,000 of their own messages a day from &quot;junk&quot; files into inboxes.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Spam</ddb:outcome>      <ddb:reference>http://www.mediapost.com/publications/?fa=Articles.showArticle&amp;art_aid=130320</ddb:reference>      <ddb:whidid>2010-128</ddb:whidid>    </item>    <item>      <title>WHID 2010-127: Israeli hacker hits IHH website</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=56918</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-127: Israeli hacker hits IHH website&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-127&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;June 17, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Monetary Loss&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;An Israeli hacker managed to break into the website of  Turkish IHH group, which organized the Gaza flotilla, disabling the organization's fundraising mechanism for a few hours.&lt;br&gt; &lt;br&gt;The 30-year-old hacker from Holon, who wished to remain anonymous, said he was concerned with Israel's poor PR efforts and decided to make a contribution of his own.&lt;br&gt; &lt;br&gt;&quot;The real war today is online. I spent an entire week exploring the site, a few hours each night, until I succeeded,&quot; he said.&lt;br&gt; &lt;br&gt;The hacker added that he was surprised to learn that IHH received some 9,000 euros in donations every hour via the website. The group is planning to send a second flotilla to Gaza next month.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;Israel&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Politics&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;Turkey&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://www.ynetnews.com/articles/0,7340,L-3906872,00.html&quot;&gt;http://www.ynetnews.com/articles/0,7340,L-3906872,00.html&lt;/a></description>      <pubDate>Thu, 17 Jun 2010 17:14:20 -0400</pubDate>      <ddb:attackedentityfield>Politics</ddb:attackedentityfield>      <ddb:attackedentitygeography>Turkey</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography>Israel</ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>June 17, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-127: Israeli hacker hits IHH website</ddb:entrytitle>      <ddb:incidentdescription>An Israeli hacker managed to break into the website of  Turkish IHH group, which organized the Gaza flotilla, disabling the organization's fundraising mechanism for a few hours.&#13;&#10; &#13;&#10;The 30-year-old hacker from Holon, who wished to remain anonymous, said he was concerned with Israel's poor PR efforts and decided to make a contribution of his own.&#13;&#10; &#13;&#10;&quot;The real war today is online. I spent an entire week exploring the site, a few hours each night, until I succeeded,&quot; he said.&#13;&#10; &#13;&#10;The hacker added that he was surprised to learn that IHH received some 9,000 euros in donations every hour via the website. The group is planning to send a second flotilla to Gaza next month.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Monetary Loss</ddb:outcome>      <ddb:reference>http://www.ynetnews.com/articles/0,7340,L-3906872,00.html</ddb:reference>      <ddb:whidid>2010-127</ddb:whidid>    </item>    <item>      <title>WHID 2010-126: Website breached by hacker through SQL injection - exposing personal information of customers</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=56851</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-126: Website breached by hacker through SQL injection - exposing personal information of customers&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-126&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;March 24, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Credit Card Leakage&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;New Hampshire breach notification: HBDirect.com - Website hacked through SQL injection - exposing credit cards of customers from December 1, 2009 to February 10, 2010. 19 NH residents affected.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Entertainment&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;New Hampshire, USA&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://datalossdb.org/primary_sources/2548&quot;&gt;http://datalossdb.org/primary_sources/2548&lt;/a></description>      <pubDate>Thu, 17 Jun 2010 14:21:05 -0400</pubDate>      <ddb:attackedentityfield>Entertainment</ddb:attackedentityfield>      <ddb:attackedentitygeography>New Hampshire, USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>March 24, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-126: Website breached by hacker through SQL injection - exposing personal information of customers</ddb:entrytitle>      <ddb:incidentdescription>New Hampshire breach notification: HBDirect.com - Website hacked through SQL injection - exposing credit cards of customers from December 1, 2009 to February 10, 2010. 19 NH residents affected.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Credit Card Leakage</ddb:outcome>      <ddb:reference>http://datalossdb.org/primary_sources/2548</ddb:reference>      <ddb:whidid>2010-126</ddb:whidid>    </item>    <item>      <title>WHID 2010-125: Eastern European banks under attack by next-gen crime app</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=56764</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-125: Eastern European banks under attack by next-gen crime app&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-125&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;June 16, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Monetary Loss&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;Banks in Russia and Ukraine are under continued siege by criminal gangs wielding a sophisticated, next-generation exploitation kit that hacks the financial institutions' authentication system and then hits it with a denial-of-service attack.&lt;br&gt;The attacks are being carried out with the help of a top-to-bottom revision of BlackEnergy, a popular hack-by-numbers toolkit that until recently was used primarily to launch DDoS, or distributed denial-of-service, attacks. Eastern European criminal gangs are using the expanded capabilities of BlackEnergy 2 to siphon funds out of electronic bank accounts and then assault the financial institutions with more data than they can handle, said Joe Stewart, a researcher with security firm SecureWorks' Counter Threat Unit.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Finance&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;Russia&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://www.theregister.co.uk/2010/06/16/blackenergy2_ddos_attacks/&quot;&gt;http://www.theregister.co.uk/2010/06/16/blackenergy2_ddos_attacks/&lt;/a></description>      <pubDate>Wed, 16 Jun 2010 22:20:31 -0400</pubDate>      <ddb:attackedentityfield>Finance</ddb:attackedentityfield>      <ddb:attackedentitygeography>Russia</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>June 16, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-125: Eastern European banks under attack by next-gen crime app</ddb:entrytitle>      <ddb:incidentdescription>Banks in Russia and Ukraine are under continued siege by criminal gangs wielding a sophisticated, next-generation exploitation kit that hacks the financial institutions' authentication system and then hits it with a denial-of-service attack.&#13;&#10;&#13;&#10;The attacks are being carried out with the help of a top-to-bottom revision of BlackEnergy, a popular hack-by-numbers toolkit that until recently was used primarily to launch DDoS, or distributed denial-of-service, attacks. Eastern European criminal gangs are using the expanded capabilities of BlackEnergy 2 to siphon funds out of electronic bank accounts and then assault the financial institutions with more data than they can handle, said Joe Stewart, a researcher with security firm SecureWorks' Counter Threat Unit.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Monetary Loss</ddb:outcome>      <ddb:reference>http://www.theregister.co.uk/2010/06/16/blackenergy2_ddos_attacks/</ddb:reference>      <ddb:whidid>2010-125</ddb:whidid>    </item>    <item>      <title>WHID 2010-124: Riyad Bank Website Gets Hacked</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=56745</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-124: Riyad Bank Website Gets Hacked&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-124&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;June 14, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Defacement&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;Saudi bank Riyad Bank has been hacked by a group of hackers who posted a message demanding to end the service of the Mayor of Al Madina province in Saudi Arabia. Al Madina is the second holiest city in Islam, and the burial place of the Prophet Muhammad peace be upon him and it is the capital of the first Islamic state established by the Prophet and his companions after early Muslims migrated from oppression imposed by their people in Mecca around 1400 years ago.&lt;br&gt;The hacker/s only managed to hack the homepage of the site as the internal pages seems intact, the hackers displayed  a message  on the bank’s homepage apologizing to the bank and saying “we are hacking you to deliver a message to the king of Saudi Arabia.” They asked him to fire the Mayer.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Finance&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;Saudi Arabia&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://arabcrunch.com/2010/06/riyad-bank-website-gets-hacked.html&quot;&gt;http://arabcrunch.com/2010/06/riyad-bank-website-gets-hacked.html&lt;/a></description>      <pubDate>Wed, 16 Jun 2010 22:08:03 -0400</pubDate>      <ddb:attackedentityfield>Finance</ddb:attackedentityfield>      <ddb:attackedentitygeography>Saudi Arabia</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>June 14, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-124: Riyad Bank Website Gets Hacked</ddb:entrytitle>      <ddb:incidentdescription>Saudi bank Riyad Bank has been hacked by a group of hackers who posted a message demanding to end the service of the Mayor of Al Madina province in Saudi Arabia. Al Madina is the second holiest city in Islam, and the burial place of the Prophet Muhammad peace be upon him and it is the capital of the first Islamic state established by the Prophet and his companions after early Muslims migrated from oppression imposed by their people in Mecca around 1400 years ago.&#13;&#10;&#13;&#10;The hacker/s only managed to hack the homepage of the site as the internal pages seems intact, the hackers displayed  a message  on the bank’s homepage apologizing to the bank and saying “we are hacking you to deliver a message to the king of Saudi Arabia.” They asked him to fire the Mayer.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Defacement</ddb:outcome>      <ddb:reference>http://arabcrunch.com/2010/06/riyad-bank-website-gets-hacked.html</ddb:reference>      <ddb:whidid>2010-124</ddb:whidid>    </item>    <item>      <title>WHID 2010-123: Botnet hijacks web servers for DDoS campaign</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=53706</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-123: Botnet hijacks web servers for DDoS campaign&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-123&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;May 13, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Botnet Participation&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;Researchers at Imperva have discovered an 'experimental' botnet that uses around 300 hijacked web servers to launch high-bandwidth DDoS attacks.&lt;br&gt;The servers are all believed to be open to an unspecified security vulnerability that allows the attacker, who calls him or herself 'Exeman', to infect them with a tiny, 40-line PHP script. This includes a simple GUI from which the attacker can return at a later date to enter in the IP, port and duration numbers for the attack that is to be launched.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Service Providers&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;Netherlands&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://www.computerworld.com.au/article/346342/botnet_hijacks_web_servers_ddos_campaign/&quot;&gt;http://www.computerworld.com.au/article/346342/botnet_hijacks_web_servers_ddos_campaign/&lt;/a></description>      <pubDate>Tue, 15 Jun 2010 20:30:26 -0400</pubDate>      <ddb:attackedentityfield>Service Providers</ddb:attackedentityfield>      <ddb:attackedentitygeography>Netherlands</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>May 13, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-123: Botnet hijacks web servers for DDoS campaign</ddb:entrytitle>      <ddb:incidentdescription>Researchers at Imperva have discovered an 'experimental' botnet that uses around 300 hijacked web servers to launch high-bandwidth DDoS attacks.&#13;&#10;&#13;&#10;The servers are all believed to be open to an unspecified security vulnerability that allows the attacker, who calls him or herself 'Exeman', to infect them with a tiny, 40-line PHP script. This includes a simple GUI from which the attacker can return at a later date to enter in the IP, port and duration numbers for the attack that is to be launched.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Botnet Participation</ddb:outcome>      <ddb:reference>http://www.computerworld.com.au/article/346342/botnet_hijacks_web_servers_ddos_campaign/</ddb:reference>      <ddb:whidid>2010-123</ddb:whidid>    </item>    <item>      <title>WHID 2010-122: Attack of WordPress Blogs on Rackspace</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=53676</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-122: Attack of WordPress Blogs on Rackspace&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-122&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;June 15, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Planting of Malware&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;If you follow our blog, you probably noticed that these last few months have been specially hard for hosting companies. Lots of them got hacked, bringing down thousands of sites with them. Now we are hearing reports of a mass hack of WordPress blogs hosted on Rackspace.&lt;br&gt;What is going on?&lt;br&gt;The attackers were able to get access to Rackspace databases and infect the sites through there. They created a new admin user on many Worpress sites, giving them full access to the WordPress admin panel.&lt;br&gt;With that access they were able to inject malware, and as we saw before they used that to inject SEO spam to the sites.&lt;br&gt;One of the posts in that thread also suggests that the attack vector is a vulnerable version (2.11.3) of phpMyAdmin used by RackSpace Cloud. If this is true, hackers must have targeted an XSRF attack at one of RackSpace admins with mySql root permissions to gain access to the whole database (probably created one more admin user). At this point, RackSpace has upgraded their phpMyAdmin nodes. Hope, they also found any changes in the database done by those hackers.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Service Providers&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://blog.sucuri.net/2010/06/mass-attack-of-wordpress-blogs-on-rackspace.html&quot;&gt;http://blog.sucuri.net/2010/06/mass-attack-of-wordpress-blogs-on-rackspace.html&lt;/a></description>      <pubDate>Tue, 15 Jun 2010 20:06:30 -0400</pubDate>      <ddb:attackedentityfield>Service Providers</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>June 15, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-122: Attack of WordPress Blogs on Rackspace</ddb:entrytitle>      <ddb:incidentdescription>If you follow our blog, you probably noticed that these last few months have been specially hard for hosting companies. Lots of them got hacked, bringing down thousands of sites with them. Now we are hearing reports of a mass hack of WordPress blogs hosted on Rackspace.&#13;&#10;&#13;&#10;What is going on?&#13;&#10;&#13;&#10;The attackers were able to get access to Rackspace databases and infect the sites through there. They created a new admin user on many Worpress sites, giving them full access to the WordPress admin panel.&#13;&#10;&#13;&#10;With that access they were able to inject malware, and as we saw before they used that to inject SEO spam to the sites.&#13;&#10;&#13;&#10;One of the posts in that thread also suggests that the attack vector is a vulnerable version (2.11.3) of phpMyAdmin used by RackSpace Cloud. If this is true, hackers must have targeted an XSRF attack at one of RackSpace admins with mySql root permissions to gain access to the whole database (probably created one more admin user). At this point, RackSpace has upgraded their phpMyAdmin nodes. Hope, they also found any changes in the database done by those hackers.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Planting of Malware</ddb:outcome>      <ddb:reference>http://blog.sucuri.net/2010/06/mass-attack-of-wordpress-blogs-on-rackspace.html</ddb:reference>      <ddb:whidid>2010-122</ddb:whidid>    </item>    <item>      <title>WHID 2010-121: Second round of GoDaddy sites hacked</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=53613</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-121: Second round of GoDaddy sites hacked&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-121&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;May 1, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Planting of Malware&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;It seems that a second round of attacks are happening today at GoDaddy and infecting all kind of sites (Joomla, Wordress,etc). Looking at the modification dates on the files, they all happened May 1st (today) during the morning from 1 to 3/4 am.&lt;br&gt;All of them had the following javascript added to their pages:&lt;br&gt;script src= http://kdjkfjskdfjlskdjf.com/kp.php&lt;br&gt;Which looks very similar to the attacks from the last few weeks, but this time using kp.php instead of js.php. Also, many sites that were not infected during the previous batch got hacked now.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Service Providers&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA&lt;br&gt;&lt;b&gt;Attacked System Technology: &lt;/b&gt;WordPress&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://blog.sucuri.net/2010/05/second-round-of-godaddy-sites-hacked.html&quot;&gt;http://blog.sucuri.net/2010/05/second-round-of-godaddy-sites-hacked.html&lt;/a></description>      <pubDate>Tue, 15 Jun 2010 19:45:27 -0400</pubDate>      <ddb:attackedentityfield>Service Providers</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology>WordPress</ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>May 1, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-121: Second round of GoDaddy sites hacked</ddb:entrytitle>      <ddb:incidentdescription>It seems that a second round of attacks are happening today at GoDaddy and infecting all kind of sites (Joomla, Wordress,etc). Looking at the modification dates on the files, they all happened May 1st (today) during the morning from 1 to 3/4 am.&#13;&#10;&#13;&#10;All of them had the following javascript added to their pages:&#13;&#10;&#13;&#10;script src= http://kdjkfjskdfjlskdjf.com/kp.php&#13;&#10;Which looks very similar to the attacks from the last few weeks, but this time using kp.php instead of js.php. Also, many sites that were not infected during the previous batch got hacked now.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Planting of Malware</ddb:outcome>      <ddb:reference>http://blog.sucuri.net/2010/05/second-round-of-godaddy-sites-hacked.html</ddb:reference>      <ddb:whidid>2010-121</ddb:whidid>    </item>    <item>      <title>WHID 2010-120: Colombian government sites hacked (and spreading malware)</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=53566</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-120: Colombian government sites hacked (and spreading malware)&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-120&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;June 2011&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Planting of Malware&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;You would expect that a security-related web site would be secure, no? What about an official web site from a Government? Should that be safe? What about a government web site about security? Shouldn’t that be ultra super secure? (yes, I am joking  )&lt;br&gt;That’s not always the case… At Sucuri Security we have two main goals: Monitor your visible Internet presence (via DNS, site content changes, whois, blacklisting status, etc), and to also monitor what is not visible (or easily accessible). So we run multiple honey pots, we monitor IRC chats used by botnets and attackers, multiple forums, etc. All with the goal to protect our clients and notify them if we see any issue in the “underground”.&lt;br&gt;With this work, we get to see a lot of sites being exploited and attacked. Most of them are small sites, but sometimes we see big companies, .govs and many .edus in there.&lt;br&gt;One of those government web sites are from Colombia. And they are not a normal .gov site, they are about security and about cyber crimes.&lt;br&gt;They have two web sites that are currently hacked: http://www.delitosinformaticos.gov.co (related to solving cyber crimes) and &lt;br&gt;http://www.frentesdeseguridad.gov.co (related to security in general). We tried to contact them and got no replies. We would wait a little more to publish it, but since clem1 mentioned them on our post about Georgia government sites hacked, I think it is time to use full-disclosure to get them fixed.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Government&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;Colombia&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://blog.sucuri.net/2010/02/colombia-government-sites-hacked-and-spreading-malware.html&quot;&gt;http://blog.sucuri.net/2010/02/colombia-government-sites-hacked-and-spreading-malware.html&lt;/a></description>      <pubDate>Tue, 15 Jun 2010 17:57:55 -0400</pubDate>      <ddb:attackedentityfield>Government</ddb:attackedentityfield>      <ddb:attackedentitygeography>Colombia</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>June 2011</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-120: Colombian government sites hacked (and spreading malware)</ddb:entrytitle>      <ddb:incidentdescription>You would expect that a security-related web site would be secure, no? What about an official web site from a Government? Should that be safe? What about a government web site about security? Shouldn’t that be ultra super secure? (yes, I am joking  )&#13;&#10;&#13;&#10;That’s not always the case… At Sucuri Security we have two main goals: Monitor your visible Internet presence (via DNS, site content changes, whois, blacklisting status, etc), and to also monitor what is not visible (or easily accessible). So we run multiple honey pots, we monitor IRC chats used by botnets and attackers, multiple forums, etc. All with the goal to protect our clients and notify them if we see any issue in the “underground”.&#13;&#10;&#13;&#10;With this work, we get to see a lot of sites being exploited and attacked. Most of them are small sites, but sometimes we see big companies, .govs and many .edus in there.&#13;&#10;&#13;&#10;One of those government web sites are from Colombia. And they are not a normal .gov site, they are about security and about cyber crimes.&#13;&#10;&#13;&#10;They have two web sites that are currently hacked: http://www.delitosinformaticos.gov.co (related to solving cyber crimes) and &#13;&#10;http://www.frentesdeseguridad.gov.co (related to security in general). We tried to contact them and got no replies. We would wait a little more to publish it, but since clem1 mentioned them on our post about Georgia government sites hacked, I think it is time to use full-disclosure to get them fixed.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Planting of Malware</ddb:outcome>      <ddb:reference>http://blog.sucuri.net/2010/02/colombia-government-sites-hacked-and-spreading-malware.html</ddb:reference>      <ddb:whidid>2010-120</ddb:whidid>    </item>    <item>      <title>WHID 2010-119: Georgia government sites hacked (and spreading malware)</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=53505</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-119: Georgia government sites hacked (and spreading malware)&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-119&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;February 15, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Planting of Malware&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;*UPDATE: A few hours after this post, they removed the malware from justice.gov.ge and other sites. I am glad we had some effect.&lt;br&gt;You know, you would think that after all the attacks that Georgia suffered in 2008 they would be more careful about the security of their sites.&lt;br&gt;Well, not really. Even after I sent a bunch of emails to all their addresses that I could find and requested on twitter for contacts in the .ge government, nobody replied and they are still hacked, spreading malware and attacking other systems.&lt;br&gt;It doesn’t look like it is being caused by the Russians or anything like that. And the attackers this time didn’t defaced their web page. They just added some malware and scripts to attack others.&lt;br&gt;How do I know? We run multiple honeypots to detect web-based attacks and malware. And guess who started attacking us?&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Government&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;imereti, GE&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://blog.sucuri.net/2010/02/georgia-government-sites-hacked-and-spreading-malware.html&quot;&gt;http://blog.sucuri.net/2010/02/georgia-government-sites-hacked-and-spreading-malware.html&lt;/a></description>      <pubDate>Tue, 15 Jun 2010 17:53:37 -0400</pubDate>      <ddb:attackedentityfield>Government</ddb:attackedentityfield>      <ddb:attackedentitygeography>imereti, GE</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>February 15, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-119: Georgia government sites hacked (and spreading malware)</ddb:entrytitle>      <ddb:incidentdescription>*UPDATE: A few hours after this post, they removed the malware from justice.gov.ge and other sites. I am glad we had some effect.&#13;&#10;&#13;&#10;You know, you would think that after all the attacks that Georgia suffered in 2008 they would be more careful about the security of their sites.&#13;&#10;&#13;&#10;Well, not really. Even after I sent a bunch of emails to all their addresses that I could find and requested on twitter for contacts in the .ge government, nobody replied and they are still hacked, spreading malware and attacking other systems.&#13;&#10;&#13;&#10;It doesn’t look like it is being caused by the Russians or anything like that. And the attackers this time didn’t defaced their web page. They just added some malware and scripts to attack others.&#13;&#10;&#13;&#10;How do I know? We run multiple honeypots to detect web-based attacks and malware. And guess who started attacking us?</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Planting of Malware</ddb:outcome>      <ddb:reference>http://blog.sucuri.net/2010/02/georgia-government-sites-hacked-and-spreading-malware.html</ddb:reference>      <ddb:whidid>2010-119</ddb:whidid>    </item>    <item>      <title>WHID 2010-118: Two Korean govt. websites attacked by hackers</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=53225</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-118: Two Korean govt. websites attacked by hackers&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-118&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;June 12, 2010&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;Two South Korean government Web sites were attacked again Saturday by hackers traced to China, but there was no major damage, the home ministry said.&lt;br&gt;The sites of the Ministry of Justice and the Korea Culture and Information Service were hit by a massive number of access attempts in what is knowns as distributed denial-of-service (DDoS) attacks from 247 China-based Internet servers, according to the Ministry of Public Administration and Security.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;China&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Government&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;South Korea&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://english.yonhapnews.co.kr/techscience/2010/06/12/73/0601000000AEN20100612002100315F.HTML&quot;&gt;http://english.yonhapnews.co.kr/techscience/2010/06/12/73/0601000000AEN20100612002100315F.HTML&lt;/a></description>      <pubDate>Mon, 14 Jun 2010 13:33:34 -0400</pubDate>      <ddb:attackedentityfield>Government</ddb:attackedentityfield>      <ddb:attackedentitygeography>South Korea</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography>China</ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>June 12, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-118: Two Korean govt. websites attacked by hackers</ddb:entrytitle>      <ddb:incidentdescription>Two South Korean government Web sites were attacked again Saturday by hackers traced to China, but there was no major damage, the home ministry said.&#13;&#10;&#13;&#10;The sites of the Ministry of Justice and the Korea Culture and Information Service were hit by a massive number of access attempts in what is knowns as distributed denial-of-service (DDoS) attacks from 247 China-based Internet servers, according to the Ministry of Public Administration and Security.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome></ddb:outcome>      <ddb:reference>http://english.yonhapnews.co.kr/techscience/2010/06/12/73/0601000000AEN20100612002100315F.HTML</ddb:reference>      <ddb:whidid>2010-118</ddb:whidid>    </item>    <item>      <title>WHID 2010-117: Turkish Hacker Hijacks .CO.IL MSN and Hotmail Domains</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=53195</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-117: Turkish Hacker Hijacks .CO.IL MSN and Hotmail Domains&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-117&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;June 10, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Defacement&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;A Turkish hacker has managed to hijack msn.co.il and hotmail.co.il, two domains belonging to Microsoft, and use them to post a pro-Palestinian message. The name servers and administrative email address for the domains have been changed.&lt;br&gt;Users who accessed hotmail.co.il and msn.co.il earlier today were greeted by a page displaying the image of a child wearing the Palestinian flag as a cape and a message reading, &quot;Free Palestine. Hi to greatest [expletive] of the world (i mean all the Jews). u think one day u will own all the world eh? Lol that makes me laugh. that makes all the world laugh. u are just insects. make muslims angrier and just sit and watch what will happen to you.&quot; The attacker signs the messsage as TurkGuvenligi Tayfa (&quot;from Turkey with love&quot;) and sends greetings to Pakbugs, a notorious group of hackers and defacers.&lt;br&gt;It appears that the two Microsoft domains, which normally redirect users to login.live.com and il.msn.com, respectively, had their name server information altered. The new ns1.dollar2host.com and ns2.dollar2host.com name servers, which belong to a private Web hosting company, replaced the usual ns1.msft.net and ns2.msft.net that Microsoft used for its domains.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;Turkey&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Information Services&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://news.softpedia.com/news/Turkish-Hacker-Hijacks-CO-IL-MSN-and-Hotmail-Domains-144299.shtml&quot;&gt;http://news.softpedia.com/news/Turkish-Hacker-Hijacks-CO-IL-MSN-and-Hotmail-Domains-144299.shtml&lt;/a></description>      <pubDate>Fri, 11 Jun 2010 20:33:01 -0400</pubDate>      <ddb:attackedentityfield>Information Services</ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography>Turkey</ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>June 10, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-117: Turkish Hacker Hijacks .CO.IL MSN and Hotmail Domains</ddb:entrytitle>      <ddb:incidentdescription>A Turkish hacker has managed to hijack msn.co.il and hotmail.co.il, two domains belonging to Microsoft, and use them to post a pro-Palestinian message. The name servers and administrative email address for the domains have been changed.&#13;&#10;&#13;&#10;Users who accessed hotmail.co.il and msn.co.il earlier today were greeted by a page displaying the image of a child wearing the Palestinian flag as a cape and a message reading, &quot;Free Palestine. Hi to greatest [expletive] of the world (i mean all the Jews). u think one day u will own all the world eh? Lol that makes me laugh. that makes all the world laugh. u are just insects. make muslims angrier and just sit and watch what will happen to you.&quot; The attacker signs the messsage as TurkGuvenligi Tayfa (&quot;from Turkey with love&quot;) and sends greetings to Pakbugs, a notorious group of hackers and defacers.&#13;&#10;&#13;&#10;It appears that the two Microsoft domains, which normally redirect users to login.live.com and il.msn.com, respectively, had their name server information altered. The new ns1.dollar2host.com and ns2.dollar2host.com name servers, which belong to a private Web hosting company, replaced the usual ns1.msft.net and ns2.msft.net that Microsoft used for its domains.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Defacement</ddb:outcome>      <ddb:reference>http://news.softpedia.com/news/Turkish-Hacker-Hijacks-CO-IL-MSN-and-Hotmail-Domains-144299.shtml</ddb:reference>      <ddb:whidid>2010-117</ddb:whidid>    </item>    <item>      <title>WHID 2010-116: Hackers: Data Breach Exposed iPad Owners' Personal Info</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=53182</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-116: Hackers: Data Breach Exposed iPad Owners' Personal Info&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-116&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;June 9, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;A security flaw in AT&amp;T's network exposed the e-mail addresses of more than 100,000 owners of Apple's 3G iPad, according to a report published by Gawker today.&lt;br&gt;Calling it the &quot;most exclusive e-mail list on the planet,&quot; Gawker said the list of exposed owners included New York Mayor Michael Bloomberg, White House Chief of Staff Rahm Emanuel and other powerful figures in finance, media and politics.&lt;br&gt;The security hole was uncovered by Goatse Security, a group known among security experts as hackers who enjoy pulling Web pranks, Gawker reported. Still, the group previously has uncovered flaws in browsers Firefox and Safari, Gawker said.&lt;br&gt;When contacted by ABCNews.com, a man who asked to be named as a Goatse employee confirmed Gawker's report.&lt;br&gt;&quot;It's absolutely real,&quot; he said, adding that the group gave the Gawker reporter their data set and he was able to verify the information.&lt;br&gt;The employee said someone in his organization learned that when given an iPad owners' unique identification number, a program on AT&amp;T's website would return the e-mail address connected to that account.&lt;br&gt;Once the hole was uncovered, he said, the group was able to write a script that would automatically predict ID numbers and return the associated e-mail addresses.&lt;br&gt;In about six hours, he said, the group was able to scrape information for about 114,000 iPad 3G owners, but he did not say how many iPad owners could have been affected in total.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Information Services&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://abcnews.go.com/print?id=10871229&quot;&gt;http://abcnews.go.com/print?id=10871229&lt;/a></description>      <pubDate>Fri, 11 Jun 2010 20:21:47 -0400</pubDate>      <ddb:attackedentityfield>Information Services</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>June 9, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-116: Hackers: Data Breach Exposed iPad Owners' Personal Info</ddb:entrytitle>      <ddb:incidentdescription>A security flaw in AT&amp;T's network exposed the e-mail addresses of more than 100,000 owners of Apple's 3G iPad, according to a report published by Gawker today.&#13;&#10;&#13;&#10;Calling it the &quot;most exclusive e-mail list on the planet,&quot; Gawker said the list of exposed owners included New York Mayor Michael Bloomberg, White House Chief of Staff Rahm Emanuel and other powerful figures in finance, media and politics.&#13;&#10;&#13;&#10;The security hole was uncovered by Goatse Security, a group known among security experts as hackers who enjoy pulling Web pranks, Gawker reported. Still, the group previously has uncovered flaws in browsers Firefox and Safari, Gawker said.&#13;&#10;&#13;&#10;When contacted by ABCNews.com, a man who asked to be named as a Goatse employee confirmed Gawker's report.&#13;&#10;&#13;&#10;&quot;It's absolutely real,&quot; he said, adding that the group gave the Gawker reporter their data set and he was able to verify the information.&#13;&#10;&#13;&#10;The employee said someone in his organization learned that when given an iPad owners' unique identification number, a program on AT&amp;T's website would return the e-mail address connected to that account.&#13;&#10;&#13;&#10;Once the hole was uncovered, he said, the group was able to write a script that would automatically predict ID numbers and return the associated e-mail addresses.&#13;&#10;&#13;&#10;In about six hours, he said, the group was able to scrape information for about 114,000 iPad 3G owners, but he did not say how many iPad owners could have been affected in total.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference>http://abcnews.go.com/print?id=10871229</ddb:reference>      <ddb:whidid>2010-116</ddb:whidid>    </item>    <item>      <title>WHID 2010-115: Mass hack plants malware on thousands of webpages</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=53070</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-115: Mass hack plants malware on thousands of webpages&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-115&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;June 9, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Planting of Malware&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;More than 100,000 webpages, some belonging to newspapers, police departments, and other large organizations, have been hit by an attack over the past few days that redirected visitors to a website that attempted to install malware on their machines.&lt;br&gt;The mass compromise appears to have affected sites running a banner-ads module on top of Microsoft's Internet Information Services using ASP.net, said David Dede, head of malware research at Sucuri, a website monitoring firm.  The sites were infected using SQL injection exploits, which allow attackers to tamper with a server's database by typing commands into search boxes and other user-input fields. The hackers used the exploit to plant iframes in the compromised sites that redirected visitors to robint.us. Malicious javascript on that site attempted to infect end users with malware dubbed Mal/Behav-290 according to anti-virus firm Sophos.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;China&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://www.theregister.co.uk/2010/06/09/mass_webpage_attack/&quot;&gt;http://www.theregister.co.uk/2010/06/09/mass_webpage_attack/&lt;/a></description>      <pubDate>Fri, 11 Jun 2010 19:31:21 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography>China</ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>June 9, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-115: Mass hack plants malware on thousands of webpages</ddb:entrytitle>      <ddb:incidentdescription>More than 100,000 webpages, some belonging to newspapers, police departments, and other large organizations, have been hit by an attack over the past few days that redirected visitors to a website that attempted to install malware on their machines.&#13;&#10;&#13;&#10;The mass compromise appears to have affected sites running a banner-ads module on top of Microsoft's Internet Information Services using ASP.net, said David Dede, head of malware research at Sucuri, a website monitoring firm.  The sites were infected using SQL injection exploits, which allow attackers to tamper with a server's database by typing commands into search boxes and other user-input fields. The hackers used the exploit to plant iframes in the compromised sites that redirected visitors to robint.us. Malicious javascript on that site attempted to infect end users with malware dubbed Mal/Behav-290 according to anti-virus firm Sophos.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Planting of Malware</ddb:outcome>      <ddb:reference>http://www.theregister.co.uk/2010/06/09/mass_webpage_attack/</ddb:reference>      <ddb:whidid>2010-115</ddb:whidid>    </item>    <item>      <title>WHID 2010-114: Seven held in Andhra for hacking passport software</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=53026</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-114: Seven held in Andhra for hacking passport software&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-114&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;June 4, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Extortion&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;Seven people were arrested in Andhra Pradesh for hacking the online passport application software of the Hyderabad regional passport office, police said Friday.&lt;br&gt;Police Commissioner A.K. Khan told reporters that seven people, among them five passport agents, were arrested and a search was on for two other agents involved in the racket.&lt;br&gt;The passport office releases online slots for confirmed dates of appointments to the applicants for obtaining passports under 'Tatkal' scheme through its website www.passport.gov.in.&lt;br&gt;Every day these slots were visible to the users only for a few minutes till the slots released by the passport authorities were exhausted.&lt;br&gt;The accused hacked the website, blocked the online slots and were selling the same to the applicants for huge sums, police said.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;India&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Government&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;India&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://sify.com/news/seven-held-in-andhra-for-hacking-passport-software-news-national-kger4bcghcf.html&quot;&gt;http://sify.com/news/seven-held-in-andhra-for-hacking-passport-software-news-national-kger4bcghcf.html&lt;/a></description>      <pubDate>Fri, 04 Jun 2010 16:39:50 -0400</pubDate>      <ddb:attackedentityfield>Government</ddb:attackedentityfield>      <ddb:attackedentitygeography>India</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography>India</ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>June 4, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-114: Seven held in Andhra for hacking passport software</ddb:entrytitle>      <ddb:incidentdescription>Seven people were arrested in Andhra Pradesh for hacking the online passport application software of the Hyderabad regional passport office, police said Friday.&#13;&#10;&#13;&#10;Police Commissioner A.K. Khan told reporters that seven people, among them five passport agents, were arrested and a search was on for two other agents involved in the racket.&#13;&#10;&#13;&#10;The passport office releases online slots for confirmed dates of appointments to the applicants for obtaining passports under 'Tatkal' scheme through its website www.passport.gov.in.&#13;&#10;&#13;&#10;Every day these slots were visible to the users only for a few minutes till the slots released by the passport authorities were exhausted.&#13;&#10;&#13;&#10;The accused hacked the website, blocked the online slots and were selling the same to the applicants for huge sums, police said.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Extortion</ddb:outcome>      <ddb:reference>http://sify.com/news/seven-held-in-andhra-for-hacking-passport-software-news-national-kger4bcghcf.html</ddb:reference>      <ddb:whidid>2010-114</ddb:whidid>    </item>    <item>      <title>WHID 2010-113: Facebook plugs email address indexing bug</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=53013</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-113: Facebook plugs email address indexing bug&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-113&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;June 4, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;Incident-prone social network monolith Facebook has plugged yet another security leak, this time involving the indexing by search engines of email addresses not listed on Facebook.  Thousands of email addresses submitted using Facebook's &quot;Find a friend&quot; feature that were not tied to a Facebook account wound up getting indexed by Google, according to Blogger Cory Watilo, who was among those affected.&lt;br&gt;&quot;One obvious problem is that spammers can easily scrape this data and add easily legitimate address to their lists, many of whom might not give their addresses to Facebook for a reason,&quot; Watilo writes.  The issue sparked a lively discussion thread on Hacker News.  Facebook changed its robot.txt file to prevent the search engine from indexing the relevant &quot;opt out of emails from Facebook&quot; page so that email address data can no longer be harvested by spammers or other miscreants.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Web 2.0&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA&lt;br&gt;&lt;b&gt;Attacked System Technology: &lt;/b&gt;Facebook&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://www.theregister.co.uk/2010/06/04/facebook_email_indexing_snafu/&quot;&gt;http://www.theregister.co.uk/2010/06/04/facebook_email_indexing_snafu/&lt;/a></description>      <pubDate>Fri, 04 Jun 2010 16:32:19 -0400</pubDate>      <ddb:attackedentityfield>Web 2.0</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology>Facebook</ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>June 4, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-113: Facebook plugs email address indexing bug</ddb:entrytitle>      <ddb:incidentdescription>Incident-prone social network monolith Facebook has plugged yet another security leak, this time involving the indexing by search engines of email addresses not listed on Facebook.  Thousands of email addresses submitted using Facebook's &quot;Find a friend&quot; feature that were not tied to a Facebook account wound up getting indexed by Google, according to Blogger Cory Watilo, who was among those affected.&#13;&#10;&#13;&#10;&#13;&#10;&quot;One obvious problem is that spammers can easily scrape this data and add easily legitimate address to their lists, many of whom might not give their addresses to Facebook for a reason,&quot; Watilo writes.  The issue sparked a lively discussion thread on Hacker News.  Facebook changed its robot.txt file to prevent the search engine from indexing the relevant &quot;opt out of emails from Facebook&quot; page so that email address data can no longer be harvested by spammers or other miscreants.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference>http://www.theregister.co.uk/2010/06/04/facebook_email_indexing_snafu/</ddb:reference>      <ddb:whidid>2010-113</ddb:whidid>    </item>    <item>      <title>WHID 2010-112: Turkish Cyber Hackers Strike at Israel</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=52934</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-112: Turkish Cyber Hackers Strike at Israel&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-112&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;June 2, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Defacement&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;The unofficial Likudnik website was targeted by angry Turkish hackers who were apparently less than pleased with the IDF Navy commando operation which prevented the terrorists on board from breaking the Gaza embargo on Hamas-controlled Gaza.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;Turkey&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Government&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;Israel&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://www.theyeshivaworld.com/news/Israeli+News/60651/Turkish-Cyber-Hackers-Strike-at-Israel.html&quot;&gt;http://www.theyeshivaworld.com/news/Israeli+News/60651/Turkish-Cyber-Hackers-Strike-at-Israel.html&lt;/a></description>      <pubDate>Thu, 03 Jun 2010 16:00:05 -0400</pubDate>      <ddb:attackedentityfield>Government</ddb:attackedentityfield>      <ddb:attackedentitygeography>Israel</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography>Turkey</ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>June 2, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-112: Turkish Cyber Hackers Strike at Israel</ddb:entrytitle>      <ddb:incidentdescription>The unofficial Likudnik website was targeted by angry Turkish hackers who were apparently less than pleased with the IDF Navy commando operation which prevented the terrorists on board from breaking the Gaza embargo on Hamas-controlled Gaza.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Defacement</ddb:outcome>      <ddb:reference>http://www.theyeshivaworld.com/news/Israeli+News/60651/Turkish-Cyber-Hackers-Strike-at-Israel.html</ddb:reference>      <ddb:whidid>2010-112</ddb:whidid>    </item>    <item>      <title>WHID 2010-111: Thieves steal virtual furniture from unsuspecting Hotel Habbo players</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=52921</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-111: Thieves steal virtual furniture from unsuspecting Hotel Habbo players&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-111&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;June 2, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Monetary Loss&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;Finnish police are searching for thieves who stole 1,000 Euros (about $1,200 U.S.) worth of virtual furniture and other items from the virtual world Habbo Hotel. The thieves allegedly used phishing scams to the capture usernames and passwords from Habbo Hotel users, who contacted Finnish police after they noticed that their virtual goods missing.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Entertainment&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;Finland&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://www.gamezebo.com/news/2010/06/02/thieves-steal-virtual-furniture-unsuspecting-hotel-habbo-players&quot;&gt;http://www.gamezebo.com/news/2010/06/02/thieves-steal-virtual-furniture-unsuspecting-hotel-habbo-players&lt;/a></description>      <pubDate>Thu, 03 Jun 2010 15:44:13 -0400</pubDate>      <ddb:attackedentityfield>Entertainment</ddb:attackedentityfield>      <ddb:attackedentitygeography>Finland</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>June 2, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-111: Thieves steal virtual furniture from unsuspecting Hotel Habbo players</ddb:entrytitle>      <ddb:incidentdescription>Finnish police are searching for thieves who stole 1,000 Euros (about $1,200 U.S.) worth of virtual furniture and other items from the virtual world Habbo Hotel. The thieves allegedly used phishing scams to the capture usernames and passwords from Habbo Hotel users, who contacted Finnish police after they noticed that their virtual goods missing.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Monetary Loss</ddb:outcome>      <ddb:reference>http://www.gamezebo.com/news/2010/06/02/thieves-steal-virtual-furniture-unsuspecting-hotel-habbo-players</ddb:reference>      <ddb:whidid>2010-111</ddb:whidid>    </item>    <item>      <title>WHID 2010-110: Local restaurant's computer hacked, customers' card numbers stolen</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=52898</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-110: Local restaurant's computer hacked, customers' card numbers stolen&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-110&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;May 22, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Credit Card Leakage&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;The computer system at a local Mexican restaurant was hacked, and investigators believe thieves made off with the credit card numbers of hundreds of customers.  &quot;They know that it was a breach, and they know that the breach came from Russia, that's for sure,&quot; explained Blanca Aldaco. &quot;So, we are working with our I.T. guy. They're definitely looking into. Hopefully, they can figure out what the IP address is.&quot;&lt;br&gt;The U.S. Secret Service and the San Antonio Police Department's Fraud Unit is also investigating. Neither would comment, but News 4 WOAI learned they are trying to track down the overseas hacker.  The restaurant's owner said they have now changed the way they do business.  &quot;We are no longer on the internet when it comes to credit card authorizations,&quot; Blanca Aldaco told News 4 WOAI.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;Russia&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Retail&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://www.woai.com/news/local/story/Local-restaurants-computer-hacked-customers-card/NSwj0Mpf5keeSXLOfsGvCw.cspx&quot;&gt;http://www.woai.com/news/local/story/Local-restaurants-computer-hacked-customers-card/NSwj0Mpf5keeSXLOfsGvCw.cspx&lt;/a></description>      <pubDate>Thu, 17 Jun 2010 14:24:50 -0400</pubDate>      <ddb:attackedentityfield>Retail</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography>Russia</ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>May 22, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-110: Local restaurant's computer hacked, customers' card numbers stolen</ddb:entrytitle>      <ddb:incidentdescription>The computer system at a local Mexican restaurant was hacked, and investigators believe thieves made off with the credit card numbers of hundreds of customers.  &quot;They know that it was a breach, and they know that the breach came from Russia, that's for sure,&quot; explained Blanca Aldaco. &quot;So, we are working with our I.T. guy. They're definitely looking into. Hopefully, they can figure out what the IP address is.&quot;&#13;&#10;&#13;&#10;The U.S. Secret Service and the San Antonio Police Department's Fraud Unit is also investigating. Neither would comment, but News 4 WOAI learned they are trying to track down the overseas hacker.  The restaurant's owner said they have now changed the way they do business.  &quot;We are no longer on the internet when it comes to credit card authorizations,&quot; Blanca Aldaco told News 4 WOAI.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Credit Card Leakage</ddb:outcome>      <ddb:reference>http://www.woai.com/news/local/story/Local-restaurants-computer-hacked-customers-card/NSwj0Mpf5keeSXLOfsGvCw.cspx</ddb:reference>      <ddb:whidid>2010-110</ddb:whidid>    </item>    <item>      <title>WHID 2010-109: Viral clickjacking 'Like' worm hits Facebook users</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=52599</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-109: Viral clickjacking 'Like' worm hits Facebook users&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-109&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;May 31, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Worm&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;Hundreds of thousands of Facebook users have fallen for a social-engineering trick which allowed a clickjacking worm to spread quickly over Facebook this holiday weekend.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Web 2.0&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA&lt;br&gt;&lt;b&gt;Attacked System Technology: &lt;/b&gt;Facebook&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://www.sophos.com/blogs/gc/g/2010/05/31/viral-clickjacking-like-worm-hits-facebook-users/&quot;&gt;http://www.sophos.com/blogs/gc/g/2010/05/31/viral-clickjacking-like-worm-hits-facebook-users/&lt;/a></description>      <pubDate>Tue, 01 Jun 2010 16:07:36 -0400</pubDate>      <ddb:attackedentityfield>Web 2.0</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology>Facebook</ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>May 31, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-109: Viral clickjacking 'Like' worm hits Facebook users</ddb:entrytitle>      <ddb:incidentdescription>Hundreds of thousands of Facebook users have fallen for a social-engineering trick which allowed a clickjacking worm to spread quickly over Facebook this holiday weekend.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Worm</ddb:outcome>      <ddb:reference>http://www.sophos.com/blogs/gc/g/2010/05/31/viral-clickjacking-like-worm-hits-facebook-users/</ddb:reference>      <ddb:whidid>2010-109</ddb:whidid>    </item>    <item>      <title>WHID 2010-108: Cyber Thieves Rob Treasury Credit Union</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=52561</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-108: Cyber Thieves Rob Treasury Credit Union&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-108&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;May 20, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Monetary Loss&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;Organized cyber thieves stole more than $100,000 from a small credit union in Salt Lake City last week, in a brazen online robbery that involved dozens of co-conspirators, KrebsOnSecurity has learned.&lt;br&gt;According to Melgar, the perpetrators who set up the bogus transactions had previously stolen a bank employee’s online login credentials after infecting the employee’s Microsoft Windows computer with a Trojan horse program. Melgar said investigators have not yet determined which particular strain of malware had infected the PC, adding that the bank’s installation of Symantec’s Norton Antivirus failed to detect the infection prior to the unauthorized transfers.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;Ukraine&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Government&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://krebsonsecurity.com/2010/05/cyber-thieves-rob-treasury-credit-union/&quot;&gt;http://krebsonsecurity.com/2010/05/cyber-thieves-rob-treasury-credit-union/&lt;/a></description>      <pubDate>Fri, 28 May 2010 13:23:43 -0400</pubDate>      <ddb:attackedentityfield>Government</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography>Ukraine</ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>May 20, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-108: Cyber Thieves Rob Treasury Credit Union</ddb:entrytitle>      <ddb:incidentdescription>Organized cyber thieves stole more than $100,000 from a small credit union in Salt Lake City last week, in a brazen online robbery that involved dozens of co-conspirators, KrebsOnSecurity has learned.&#13;&#10;&#13;&#10;According to Melgar, the perpetrators who set up the bogus transactions had previously stolen a bank employee’s online login credentials after infecting the employee’s Microsoft Windows computer with a Trojan horse program. Melgar said investigators have not yet determined which particular strain of malware had infected the PC, adding that the bank’s installation of Symantec’s Norton Antivirus failed to detect the infection prior to the unauthorized transfers.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Monetary Loss</ddb:outcome>      <ddb:reference>http://krebsonsecurity.com/2010/05/cyber-thieves-rob-treasury-credit-union/</ddb:reference>      <ddb:whidid>2010-108</ddb:whidid>    </item>    <item>      <title>WHID 2010-107: Hackers Take Over BP Twitter Feed</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=52517</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-107: Hackers Take Over BP Twitter Feed&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-107&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;May 27, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Disinformation&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;BP's Twitter account looked to have fallen victim to hackers early Thursday, with a post referencing a fictional character from a popular fake BP microblog page.&lt;br&gt;Followers to the genuine account were told: &quot;Terry is now in charge of operation Top Kill, work will recommence after we find a XXL wetsuit. #bpcares #oilspill.&quot;&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Web 2.0&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA&lt;br&gt;&lt;b&gt;Attacked System Technology: &lt;/b&gt;Twitter&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://www.foxnews.com/scitech/2010/05/27/hackers-bp-twitter-feed/&quot;&gt;http://www.foxnews.com/scitech/2010/05/27/hackers-bp-twitter-feed/&lt;/a></description>      <pubDate>Thu, 27 May 2010 17:58:19 -0400</pubDate>      <ddb:attackedentityfield>Web 2.0</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology>Twitter</ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>May 27, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-107: Hackers Take Over BP Twitter Feed</ddb:entrytitle>      <ddb:incidentdescription>BP's Twitter account looked to have fallen victim to hackers early Thursday, with a post referencing a fictional character from a popular fake BP microblog page.&#13;&#10;&#13;&#10;Followers to the genuine account were told: &quot;Terry is now in charge of operation Top Kill, work will recommence after we find a XXL wetsuit. #bpcares #oilspill."</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Disinformation</ddb:outcome>      <ddb:reference>http://www.foxnews.com/scitech/2010/05/27/hackers-bp-twitter-feed/</ddb:reference>      <ddb:whidid>2010-107</ddb:whidid>    </item>    <item>      <title>WHID 2010-106: AMC website vulnerable to hackers</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=52498</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-106: AMC website vulnerable to hackers&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-106&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;May 27, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;With a weak network security, the website http:// www.egovamc.com. has several chinks in its armour and is a ready invitation for hackers. The issue has been brought to notice of senior AMC officials and only recently they effected a few cosmetic security patch-ups for their website. &lt;br&gt;“We have reported the bugs in the website and problems with database management system and coding. We had earlier told the systems department of the AMC about a system that can be exploited with username and password as simple ‘0’. The vulnerability has been fixed by now but there are bigger challenges,” said Sunny Vaghela, a city-based cyber crime expert. &lt;br&gt;He said that if the website is vulnerable , it means that the hacker can get access to the control panel of the site, look into the contents such as tendering details, property tax details , building plans and allocation of funds, access to which is restricted to only senior-level civic officials. &lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Government&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;India&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://timesofindia.indiatimes.com/articleshow/5979202.cms&quot;&gt;http://timesofindia.indiatimes.com/articleshow/5979202.cms&lt;/a></description>      <pubDate>Thu, 27 May 2010 13:58:49 -0400</pubDate>      <ddb:attackedentityfield>Government</ddb:attackedentityfield>      <ddb:attackedentitygeography>India</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>May 27, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-106: AMC website vulnerable to hackers</ddb:entrytitle>      <ddb:incidentdescription>With a weak network security, the website http:// www.egovamc.com. has several chinks in its armour and is a ready invitation for hackers. The issue has been brought to notice of senior AMC officials and only recently they effected a few cosmetic security patch-ups for their website. &#13;&#10;&#13;&#10;“We have reported the bugs in the website and problems with database management system and coding. We had earlier told the systems department of the AMC about a system that can be exploited with username and password as simple ‘0’. The vulnerability has been fixed by now but there are bigger challenges,” said Sunny Vaghela, a city-based cyber crime expert. &#13;&#10;&#13;&#10;He said that if the website is vulnerable , it means that the hacker can get access to the control panel of the site, look into the contents such as tendering details, property tax details , building plans and allocation of funds, access to which is restricted to only senior-level civic officials. </ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference>http://timesofindia.indiatimes.com/articleshow/5979202.cms</ddb:reference>      <ddb:whidid>2010-106</ddb:whidid>    </item>    <item>      <title>WHID 2010-105: Poll removed due to widespread ballot stuffing and hacking</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=52443</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-105: Poll removed due to widespread ballot stuffing and hacking&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-105&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;May 25, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Fraud&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;Dear users, yesterday we began a poll about the controversial immigration bill SB 1070 asking users what was their sentiment on the bill. It spread virally and was shared on facebook over 500 times and viewed over 10,000 times.&lt;br&gt;Unfortunately all the of attention has made it the target of some unscrupulous individuals. Around 3:00pm Tuesday afternoon we noticed that an individual was voting in the poll once every 10 seconds, and did this activity for nearly 2 hours.&lt;br&gt;Upon checking the logs we realized there were multiple users engaging in this sort of behavior from multiple vectors forcing us to remove the poll entirely. In terms of a long term solution, it seems inevitable that we will adopt a system that requires a KVOA.com user account in order to vote in a poll, but that modification cannot be patched in on the fly and would require a few days work.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Media&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://www.kvoa.com/news/poll-removed-due-to-widespread-ballot-stuffing-and-hacking/&quot;&gt;http://www.kvoa.com/news/poll-removed-due-to-widespread-ballot-stuffing-and-hacking/&lt;/a></description>      <pubDate>Wed, 26 May 2010 13:10:41 -0400</pubDate>      <ddb:attackedentityfield>Media</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>May 25, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-105: Poll removed due to widespread ballot stuffing and hacking</ddb:entrytitle>      <ddb:incidentdescription>Dear users, yesterday we began a poll about the controversial immigration bill SB 1070 asking users what was their sentiment on the bill. It spread virally and was shared on facebook over 500 times and viewed over 10,000 times.&#13;&#10;&#13;&#10;Unfortunately all the of attention has made it the target of some unscrupulous individuals. Around 3:00pm Tuesday afternoon we noticed that an individual was voting in the poll once every 10 seconds, and did this activity for nearly 2 hours.&#13;&#10;&#13;&#10;Upon checking the logs we realized there were multiple users engaging in this sort of behavior from multiple vectors forcing us to remove the poll entirely. In terms of a long term solution, it seems inevitable that we will adopt a system that requires a KVOA.com user account in order to vote in a poll, but that modification cannot be patched in on the fly and would require a few days work.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Fraud</ddb:outcome>      <ddb:reference>http://www.kvoa.com/news/poll-removed-due-to-widespread-ballot-stuffing-and-hacking/</ddb:reference>      <ddb:whidid>2010-105</ddb:whidid>    </item>    <item>      <title>WHID 2010-104: Code Security: MidAmerican Energy's top priority after SQL injection attacks</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=52420</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-104: Code Security: MidAmerican Energy's top priority after SQL injection attacks&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-104&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;May 21, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&quot;Last May we had an incident where one of our web pages was exploited through an SQL injection flaw,&quot; Kerber said. &quot;It was a wake-up call that we had vulnerabilities people could find out about.&quot;&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Energy&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://www.csoonline.com/article/594613/Code_Security_MidAmerican_Energy_s_top_priority_after_SQL_injection_attacks&quot;&gt;http://www.csoonline.com/article/594613/Code_Security_MidAmerican_Energy_s_top_priority_after_SQL_injection_attacks&lt;/a></description>      <pubDate>Tue, 25 May 2010 21:09:22 -0400</pubDate>      <ddb:attackedentityfield>Energy</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>May 21, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-104: Code Security: MidAmerican Energy's top priority after SQL injection attacks</ddb:entrytitle>      <ddb:incidentdescription>&quot;Last May we had an incident where one of our web pages was exploited through an SQL injection flaw,&quot; Kerber said. &quot;It was a wake-up call that we had vulnerabilities people could find out about."</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference>http://www.csoonline.com/article/594613/Code_Security_MidAmerican_Energy_s_top_priority_after_SQL_injection_attacks</ddb:reference>      <ddb:whidid>2010-104</ddb:whidid>    </item>    <item>      <title>WHID 2010-103: SEO SPAM network - Details of the wp-includes infection</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=52389</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-103: SEO SPAM network - Details of the wp-includes infection&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-103&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;May 25, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Link Spam&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;We have been digging lately in a large SEO SPAM network which is using thousands of compromised sites to increase their page rankings and spread malware. They are similar to the one we reported earlier affecting lean.mit.edu, but this time they seem focused only on Wordpress web sites&lt;br&gt;Attack method&lt;br&gt;All the sites infected are using the latest Wordpress version and had a PHP script injected inside their wp-includes directory. The script name is random and it does two things:&lt;br&gt;1-For a search engine, it shows a bunch of keywords (cialis, viagra, movie downloads, etc)&lt;br&gt;2-For a normal user coming from Google, they are redirected to a web site with malware or to another site for more spam.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Education&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA&lt;br&gt;&lt;b&gt;Attacked System Technology: &lt;/b&gt;WordPress&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://blog.sucuri.net/2010/05/seo-spam-network-details-of-wp-includes.html&quot;&gt;http://blog.sucuri.net/2010/05/seo-spam-network-details-of-wp-includes.html&lt;/a></description>      <pubDate>Tue, 25 May 2010 17:18:46 -0400</pubDate>      <ddb:attackedentityfield>Education</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology>WordPress</ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>May 25, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-103: SEO SPAM network - Details of the wp-includes infection</ddb:entrytitle>      <ddb:incidentdescription>We have been digging lately in a large SEO SPAM network which is using thousands of compromised sites to increase their page rankings and spread malware. They are similar to the one we reported earlier affecting lean.mit.edu, but this time they seem focused only on Wordpress web sites&#13;&#10;&#13;&#10;Attack method&#13;&#10;&#13;&#10;All the sites infected are using the latest Wordpress version and had a PHP script injected inside their wp-includes directory. The script name is random and it does two things:&#13;&#10;&#13;&#10;1-For a search engine, it shows a bunch of keywords (cialis, viagra, movie downloads, etc)&#13;&#10;2-For a normal user coming from Google, they are redirected to a web site with malware or to another site for more spam.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Link Spam</ddb:outcome>      <ddb:reference>http://blog.sucuri.net/2010/05/seo-spam-network-details-of-wp-includes.html</ddb:reference>      <ddb:whidid>2010-103</ddb:whidid>    </item>    <item>      <title>WHID 2010-102: Denver's website hacked twice in one week</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=52376</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-102: Denver's website hacked twice in one week&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-102&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;May 25, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Defacement&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;The city and county of Denver website was pulled down Monday night after it was hacked, the second such attack in a week.&lt;br&gt;Eric Brown, a spokesman for the mayor's office, said he didn't know what time the site was breached and when it might be restored.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Government&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://www.denverpost.com/news/ci_15155519&quot;&gt;http://www.denverpost.com/news/ci_15155519&lt;/a></description>      <pubDate>Tue, 25 May 2010 17:10:11 -0400</pubDate>      <ddb:attackedentityfield>Government</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>May 25, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-102: Denver's website hacked twice in one week</ddb:entrytitle>      <ddb:incidentdescription>The city and county of Denver website was pulled down Monday night after it was hacked, the second such attack in a week.&#13;&#10;&#13;&#10;Eric Brown, a spokesman for the mayor's office, said he didn't know what time the site was breached and when it might be restored.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Defacement</ddb:outcome>      <ddb:reference>http://www.denverpost.com/news/ci_15155519</ddb:reference>      <ddb:whidid>2010-102</ddb:whidid>    </item>    <item>      <title>WHID 2010-94: Hacker steals 22,000 e-mail address, demands Astley tune</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=50955</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-94: Hacker steals 22,000 e-mail address, demands Astley tune&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-94&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;May 19, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;Dutch hacker Darkc0ke hijacked a radio station database containing 22,000 e-mail addresses and threatened to publish them unless the station play Rick Astley's &quot;Never Gonna Give You Up,&quot; a variation of an Internet meme known as &quot;rickrolling.&quot;&lt;br&gt;&quot;It was a joke,&quot; Darkc0ke said via e-mail. &quot;They didn't play the song. Why can't they do someone a favor, just for once?&quot; Darkc0ke said he cracked the database using a basic SQL injection to exploit a security vulnerability. The hacker is known for breaking into databases. Last year, he stole a database containing 46,000 e-mail addresses from the Dutch magazine Autoweek.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Media&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;Netherlands&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://news.idg.no/cw/art.cfm?id=B143BFED-1A64-6A71-CE6E57CCCFC37786&quot;&gt;http://news.idg.no/cw/art.cfm?id=B143BFED-1A64-6A71-CE6E57CCCFC37786&lt;/a></description>      <pubDate>Mon, 24 May 2010 13:54:42 -0400</pubDate>      <ddb:attackedentityfield>Media</ddb:attackedentityfield>      <ddb:attackedentitygeography>Netherlands</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>May 19, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-94: Hacker steals 22,000 e-mail address, demands Astley tune</ddb:entrytitle>      <ddb:incidentdescription>Dutch hacker Darkc0ke hijacked a radio station database containing 22,000 e-mail addresses and threatened to publish them unless the station play Rick Astley's &quot;Never Gonna Give You Up,&quot; a variation of an Internet meme known as &quot;rickrolling.&quot;&#13;&#10;&#13;&#10;&quot;It was a joke,&quot; Darkc0ke said via e-mail. &quot;They didn't play the song. Why can't they do someone a favor, just for once?&quot; Darkc0ke said he cracked the database using a basic SQL injection to exploit a security vulnerability. The hacker is known for breaking into databases. Last year, he stole a database containing 46,000 e-mail addresses from the Dutch magazine Autoweek.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference>http://news.idg.no/cw/art.cfm?id=B143BFED-1A64-6A71-CE6E57CCCFC37786</ddb:reference>      <ddb:whidid>2010-94</ddb:whidid>    </item>    <item>      <title>WHID 2010-98: Man charged with attacking O'Reilly, Coulter websites</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=51289</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-98: Man charged with attacking O'Reilly, Coulter websites&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-98&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;May 19, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Downtime&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;A former college student has been charged with using the school's computer network to control a botnet and launch distributed denial-of-service (DDoS) attacks against conservative websites belonging to Bill O'Reilly, Ann Coulter and Rudy Giuliani.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;USA&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Media&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://www.scmagazineus.com/man-charged-with-attacking-oreilly-coulter-websites/article/170524/&quot;&gt;http://www.scmagazineus.com/man-charged-with-attacking-oreilly-coulter-websites/article/170524/&lt;/a></description>      <pubDate>Mon, 24 May 2010 13:54:42 -0400</pubDate>      <ddb:attackedentityfield>Media</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography>USA</ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>May 19, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-98: Man charged with attacking O'Reilly, Coulter websites</ddb:entrytitle>      <ddb:incidentdescription>A former college student has been charged with using the school's computer network to control a botnet and launch distributed denial-of-service (DDoS) attacks against conservative websites belonging to Bill O'Reilly, Ann Coulter and Rudy Giuliani.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Downtime</ddb:outcome>      <ddb:reference>http://www.scmagazineus.com/man-charged-with-attacking-oreilly-coulter-websites/article/170524/</ddb:reference>      <ddb:whidid>2010-98</ddb:whidid>    </item>    <item>      <title>WHID 2010-99: Got an iTunes account? That's music to a cyber fraudster's ears</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=52067</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-99: Got an iTunes account? That's music to a cyber fraudster's ears&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-99&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;May 22, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Session Hijacking&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;Up to 125million people worldwide have accounts set up on the site.&lt;br&gt;But computer security experts say hackers are easily hijacking accounts by pretending they are a customer who has forgotten their password.&lt;br&gt;As with many websites, iTunes tells users to select a socalled 'security question' from a list of options when they first set up their account.&lt;br&gt;These are fairly basic and include 'what is your mother's maiden name?' and 'where did you spend your honeymoon?'.&lt;br&gt;Customers who have forgotten their passwords are prompted with the question they first selected when they set up their profile - as long as they give the correct answer, they can access the account.&lt;br&gt;Security analysts claim this is leaving the website wide open to fraud.&lt;br&gt;Hackers simply pretend they are a customer who has forgotten their password and can easily work out the answer to the personal question using information that users have posted on social-networking websites such as Facebook and Twitter.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Web 2.0&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://www.dailymail.co.uk/news/article-1280354/Got-iTunes-account-Thats-music-cyber-fraudsters-ears.html&quot;&gt;http://www.dailymail.co.uk/news/article-1280354/Got-iTunes-account-Thats-music-cyber-fraudsters-ears.html&lt;/a></description>      <pubDate>Mon, 24 May 2010 14:30:16 -0400</pubDate>      <ddb:attackedentityfield>Web 2.0</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>May 22, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-99: Got an iTunes account? That's music to a cyber fraudster's ears</ddb:entrytitle>      <ddb:incidentdescription>Up to 125million people worldwide have accounts set up on the site.&#13;&#10;But computer security experts say hackers are easily hijacking accounts by pretending they are a customer who has forgotten their password.&#13;&#10;As with many websites, iTunes tells users to select a socalled 'security question' from a list of options when they first set up their account.&#13;&#10;These are fairly basic and include 'what is your mother's maiden name?' and 'where did you spend your honeymoon?'.&#13;&#10;Customers who have forgotten their passwords are prompted with the question they first selected when they set up their profile - as long as they give the correct answer, they can access the account.&#13;&#10;Security analysts claim this is leaving the website wide open to fraud.&#13;&#10;Hackers simply pretend they are a customer who has forgotten their password and can easily work out the answer to the personal question using information that users have posted on social-networking websites such as Facebook and Twitter.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Session Hijacking</ddb:outcome>      <ddb:reference>http://www.dailymail.co.uk/news/article-1280354/Got-iTunes-account-Thats-music-cyber-fraudsters-ears.html</ddb:reference>      <ddb:whidid>2010-99</ddb:whidid>    </item>    <item>      <title>WHID 2010-97: Microsoft files two lawsuits for &quot;click laundering"</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=51246</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-97: Microsoft files two lawsuits for &quot;click laundering&quot;&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-97&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;May 20, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Fraud&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;Microsoft this week filed two lawsuits in federal court in Seattle against alleged perpetrators of a new, technologically advanced form of online advertising click fraud being dubbed &quot;click laundering.&quot;&lt;br&gt;According to Microsoft, click fraud is an online advertising scam that occurs when a person or computer program imitates a legitimate user and clicks on an online ad for the purpose of generating a fraudulent “charge-per-click,” without having any interest in the ad.&lt;br&gt;Click laundering, meanwhile, is a more advanced form of click fraud designed to outwit fraud detection systems by hiding the origin of fake clicks. &lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Technology&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://www.scmagazineus.com/microsoft-files-two-lawsuits-for-click-laundering/article/170621/&quot;&gt;http://www.scmagazineus.com/microsoft-files-two-lawsuits-for-click-laundering/article/170621/&lt;/a></description>      <pubDate>Mon, 24 May 2010 13:54:42 -0400</pubDate>      <ddb:attackedentityfield>Technology</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>May 20, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-97: Microsoft files two lawsuits for &quot;click laundering"</ddb:entrytitle>      <ddb:incidentdescription>Microsoft this week filed two lawsuits in federal court in Seattle against alleged perpetrators of a new, technologically advanced form of online advertising click fraud being dubbed &quot;click laundering.&quot;&#13;&#10;&#13;&#10;According to Microsoft, click fraud is an online advertising scam that occurs when a person or computer program imitates a legitimate user and clicks on an online ad for the purpose of generating a fraudulent “charge-per-click,” without having any interest in the ad.&#13;&#10;&#13;&#10;Click laundering, meanwhile, is a more advanced form of click fraud designed to outwit fraud detection systems by hiding the origin of fake clicks. </ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Fraud</ddb:outcome>      <ddb:reference>http://www.scmagazineus.com/microsoft-files-two-lawsuits-for-click-laundering/article/170621/</ddb:reference>      <ddb:whidid>2010-97</ddb:whidid>    </item>    <item>      <title>WHID 2010-95: Fraud Bazaar Carders.cc Hacked</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=50998</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-95: Fraud Bazaar Carders.cc Hacked&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-95&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;May 18, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;Carders.cc, a German online forum dedicated to helping criminals trade and sell financial data stolen through hacking, has itself been hacked. The once-guarded contents of its servers are now being traded on public file-sharing networks, leading to the exposure of potentially identifying information on the forum’s users as well as countless passwords and credit card accounts swiped from unsuspecting victims.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Hacking&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;Germany&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://krebsonsecurity.com/2010/05/fraud-bazaar-carders-cc-hacked/&quot;&gt;http://krebsonsecurity.com/2010/05/fraud-bazaar-carders-cc-hacked/&lt;/a></description>      <pubDate>Mon, 24 May 2010 13:54:42 -0400</pubDate>      <ddb:attackedentityfield>Hacking</ddb:attackedentityfield>      <ddb:attackedentitygeography>Germany</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>May 18, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-95: Fraud Bazaar Carders.cc Hacked</ddb:entrytitle>      <ddb:incidentdescription>Carders.cc, a German online forum dedicated to helping criminals trade and sell financial data stolen through hacking, has itself been hacked. The once-guarded contents of its servers are now being traded on public file-sharing networks, leading to the exposure of potentially identifying information on the forum’s users as well as countless passwords and credit card accounts swiped from unsuspecting victims.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference>http://krebsonsecurity.com/2010/05/fraud-bazaar-carders-cc-hacked/</ddb:reference>      <ddb:whidid>2010-95</ddb:whidid>    </item>    <item>      <title>WHID 2010-100: Chinaz.com compromised</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=52350</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-100: Chinaz.com compromised&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-100&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;May 25, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Planting of Malware&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;Websense Security Labs™ ThreatSeeker™ Network has discovered that the speed testing site of chinaz.com has been compromised.&lt;br&gt;This payload contains two parts: ap.js, and the obfuscation code in the script tag. When combined, we get the entire exploit code. After analyzing this, we noticed that it is used to target the IE vulnerability (MS10-018), which downloads an executable file named dn.exe. This has a good detection rate by most  AV vendors; however dn.exe will download and execute remote files and send local information to a remote server.  The process disguises itself as an AV component while at the same time suspending the AV software. At present, a bug in the malicious code fails to get the MAC address correctly and as of this alert the site is still infected.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Information Services&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;China&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://community.websense.com/blogs/securitylabs/archive/2010/05/25/chinaz-com-compromised.aspx&quot;&gt;http://community.websense.com/blogs/securitylabs/archive/2010/05/25/chinaz-com-compromised.aspx&lt;/a></description>      <pubDate>Tue, 25 May 2010 16:33:04 -0400</pubDate>      <ddb:attackedentityfield>Information Services</ddb:attackedentityfield>      <ddb:attackedentitygeography>China</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>May 25, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-100: Chinaz.com compromised</ddb:entrytitle>      <ddb:incidentdescription>Websense Security Labs™ ThreatSeeker™ Network has discovered that the speed testing site of chinaz.com has been compromised.&#13;&#10;&#13;&#10;This payload contains two parts: ap.js, and the obfuscation code in the script tag. When combined, we get the entire exploit code. After analyzing this, we noticed that it is used to target the IE vulnerability (MS10-018), which downloads an executable file named dn.exe. This has a good detection rate by most  AV vendors; however dn.exe will download and execute remote files and send local information to a remote server.  The process disguises itself as an AV component while at the same time suspending the AV software. At present, a bug in the malicious code fails to get the MAC address correctly and as of this alert the site is still infected.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Planting of Malware</ddb:outcome>      <ddb:reference>http://community.websense.com/blogs/securitylabs/archive/2010/05/25/chinaz-com-compromised.aspx</ddb:reference>      <ddb:whidid>2010-100</ddb:whidid>    </item>    <item>      <title>WHID 2010-101: 37 million passwords stolen on the site of Skyrock?</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=52363</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-101: 37 million passwords stolen on the site of Skyrock?&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-101&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;May 21, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;A hacker broke the huge database site which had registered 36.7 million Internet users, raising fears of massive consequences. The Site Skyrock has sent a message to its internet users the message of the team to its Internet Skyrock&lt;br&gt;According Zataz, the hacker would be introduced through a security hole in the platform Waka , launched last week in partnership with the government . This ” backdoor “, which allowed anyone to edit the content of pages, had been quickly corrected.&lt;br&gt;For its part, Skyrock believes that “at this stage, we cannot determine whether the application Waka was concerned.”&lt;br&gt;Still, the hacker could have access to the huge database Skyrock.com, claiming “36.7 million active members in February 25. However, the head of security at the site revealed Monde.fr than Skyrock, passwords are stored in “plain” , that is to say they are not encrypted and protected.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Web 2.0&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;France&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://whitehatfirm.com/news/37-million-passwords-stolen-on-the-site-of-skyrock/2629.html&quot;&gt;http://whitehatfirm.com/news/37-million-passwords-stolen-on-the-site-of-skyrock/2629.html&lt;/a></description>      <pubDate>Tue, 25 May 2010 16:50:25 -0400</pubDate>      <ddb:attackedentityfield>Web 2.0</ddb:attackedentityfield>      <ddb:attackedentitygeography>France</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>May 21, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-101: 37 million passwords stolen on the site of Skyrock?</ddb:entrytitle>      <ddb:incidentdescription>A hacker broke the huge database site which had registered 36.7 million Internet users, raising fears of massive consequences. The Site Skyrock has sent a message to its internet users the message of the team to its Internet Skyrock&#13;&#10;&#13;&#10;According Zataz, the hacker would be introduced through a security hole in the platform Waka , launched last week in partnership with the government . This ” backdoor “, which allowed anyone to edit the content of pages, had been quickly corrected.&#13;&#10;&#13;&#10;For its part, Skyrock believes that “at this stage, we cannot determine whether the application Waka was concerned.”&#13;&#10;&#13;&#10;Still, the hacker could have access to the huge database Skyrock.com, claiming “36.7 million active members in February 25. However, the head of security at the site revealed Monde.fr than Skyrock, passwords are stored in “plain” , that is to say they are not encrypted and protected.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference>http://whitehatfirm.com/news/37-million-passwords-stolen-on-the-site-of-skyrock/2629.html</ddb:reference>      <ddb:whidid>2010-101</ddb:whidid>    </item>    <item>      <title>WHID 2010-96: Facebook scrambles to close CSRF hole exposing private data</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=51046</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-96: Facebook scrambles to close CSRF hole exposing private data&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-96&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;May 19, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;Facebook engineers are finishing a patch for a critical vulnerability that exposed user birthdays and other sensitive data even when they were designated as private, a security researcher said Wednesday.&lt;br&gt;At time of writing, much of the CSRF (cross-site request forgery) bug appeared to have been patched, Keith said. However, as noted earlier by IDG News, attackers still could exploit the flaw to control a user's &quot;like&quot; functions, which are used to endorse ads and other types of content.&lt;br&gt;The flaw involved a piece of code Facebook engineers dubbed &quot;post_form_id,&quot; which is used to ensure that commands can be issued only by browsers that have previously logged into the website. Keith discovered a simple way to bypass the security token: by omitting it altogether, Facebook servers no longer attempted to validate browsers.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Web 2.0&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA&lt;br&gt;&lt;b&gt;Attacked System Technology: &lt;/b&gt;Facebook&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://www.theregister.co.uk/2010/05/19/facebook_private_data_leak/&quot;&gt;http://www.theregister.co.uk/2010/05/19/facebook_private_data_leak/&lt;/a></description>      <pubDate>Mon, 24 May 2010 13:54:42 -0400</pubDate>      <ddb:attackedentityfield>Web 2.0</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology>Facebook</ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>May 19, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-96: Facebook scrambles to close CSRF hole exposing private data</ddb:entrytitle>      <ddb:incidentdescription>Facebook engineers are finishing a patch for a critical vulnerability that exposed user birthdays and other sensitive data even when they were designated as private, a security researcher said Wednesday.&#13;&#10;&#13;&#10;At time of writing, much of the CSRF (cross-site request forgery) bug appeared to have been patched, Keith said. However, as noted earlier by IDG News, attackers still could exploit the flaw to control a user's &quot;like&quot; functions, which are used to endorse ads and other types of content.&#13;&#10;&#13;&#10;The flaw involved a piece of code Facebook engineers dubbed &quot;post_form_id,&quot; which is used to ensure that commands can be issued only by browsers that have previously logged into the website. Keith discovered a simple way to bypass the security token: by omitting it altogether, Facebook servers no longer attempted to validate browsers.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference>http://www.theregister.co.uk/2010/05/19/facebook_private_data_leak/</ddb:reference>      <ddb:whidid>2010-96</ddb:whidid>    </item>    <item>      <title>WHID 2010-93: Huge 'sexiest video ever' attack hits Facebook</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=50905</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-93: Huge 'sexiest video ever' attack hits Facebook&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-93&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;May 18, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Planting of Malware&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;A huge attack by a rogue Facebook application last weekend infected users' PCs with popup-spewing adware, a security researcher said Monday.&lt;br&gt;On Saturday, AVG Technologies received more than 300,000 reports of the malicious Facebook app, said Roger Thompson, AVG's chief research officer. AVG came up with its tally by counting the number of reports from its LinkScanner software, a free browser add-on that detects potentially poisoned pages.&lt;br&gt;&quot;It was stunning, really, the number,&quot; said Thompson in an interview via instant message late Monday. &quot;And stunning that it was not viral or wormy [but that] Facebook did it all by itself.&quot;&lt;br&gt;The volume of reports on Saturday's rogue Facebook software was highest during the nine-hour period between midnight and 9 a.m. Eastern, with spikes of approximately 40,000 per hour coming at 7 a.m. and noon. For the day, AVG received more than 300,000 reports, triple that of AVG's second-most-reported piece of spyware.&lt;br&gt;According to Thompson, Facebook eradicated the rogue application about 15 hours after the attack started. Facebook's only acknowledgment of the attack came on its security page, where a &quot;Tip of the Week&quot; Monday morning read: &quot;Don't click on suspicious-looking links, even if they've been sent or posted by friends.&quot;&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Web 2.0&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA&lt;br&gt;&lt;b&gt;Attacked System Technology: &lt;/b&gt;Facebook&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://www.computerworld.com/s/article/9176905/Huge_sexiest_video_ever_attack_hits_Facebook&quot;&gt;http://www.computerworld.com/s/article/9176905/Huge_sexiest_video_ever_attack_hits_Facebook&lt;/a></description>      <pubDate>Mon, 24 May 2010 13:54:42 -0400</pubDate>      <ddb:attackedentityfield>Web 2.0</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology>Facebook</ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>May 18, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-93: Huge 'sexiest video ever' attack hits Facebook</ddb:entrytitle>      <ddb:incidentdescription>A huge attack by a rogue Facebook application last weekend infected users' PCs with popup-spewing adware, a security researcher said Monday.&#13;&#10;&#13;&#10;On Saturday, AVG Technologies received more than 300,000 reports of the malicious Facebook app, said Roger Thompson, AVG's chief research officer. AVG came up with its tally by counting the number of reports from its LinkScanner software, a free browser add-on that detects potentially poisoned pages.&#13;&#10;&#13;&#10;&quot;It was stunning, really, the number,&quot; said Thompson in an interview via instant message late Monday. &quot;And stunning that it was not viral or wormy [but that] Facebook did it all by itself.&quot;&#13;&#10;&#13;&#10;The volume of reports on Saturday's rogue Facebook software was highest during the nine-hour period between midnight and 9 a.m. Eastern, with spikes of approximately 40,000 per hour coming at 7 a.m. and noon. For the day, AVG received more than 300,000 reports, triple that of AVG's second-most-reported piece of spyware.&#13;&#10;&#13;&#10;According to Thompson, Facebook eradicated the rogue application about 15 hours after the attack started. Facebook's only acknowledgment of the attack came on its security page, where a &quot;Tip of the Week&quot; Monday morning read: &quot;Don't click on suspicious-looking links, even if they've been sent or posted by friends."</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Planting of Malware</ddb:outcome>      <ddb:reference>http://www.computerworld.com/s/article/9176905/Huge_sexiest_video_ever_attack_hits_Facebook</ddb:reference>      <ddb:whidid>2010-93</ddb:whidid>    </item>    <item>      <title>WHID 2010-76: Website hacked, election officials say</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=49922</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-76: Website hacked, election officials say&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-76&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;May 5, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Downtime&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;Local elections officials say their website was hacked as they tried to communicate the results of the Tuesday, May 4, primary election — crashing the site several times and delaying the announcement of vote tallies.&lt;br&gt;“We have crashed three servers, and in examining those servers, there are two unidentified sites that are deliberately diverting traffic,” said Butler County Board of Elections Director Betty McGary as her frenzied staff struggled to post election results.&lt;br&gt;“Our servers are under attack, we feel,” McGary said, stressing that the problem pertained only to transmitting totals to the public, not accurately counting the votes.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Government&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://www.middletownjournal.com/news/election/website-hacked-election-officials-say-687529.html&quot;&gt;http://www.middletownjournal.com/news/election/website-hacked-election-officials-say-687529.html&lt;/a></description>      <pubDate>Mon, 24 May 2010 13:54:42 -0400</pubDate>      <ddb:attackedentityfield>Government</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>May 5, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-76: Website hacked, election officials say</ddb:entrytitle>      <ddb:incidentdescription>Local elections officials say their website was hacked as they tried to communicate the results of the Tuesday, May 4, primary election — crashing the site several times and delaying the announcement of vote tallies.&#13;&#10;“We have crashed three servers, and in examining those servers, there are two unidentified sites that are deliberately diverting traffic,” said Butler County Board of Elections Director Betty McGary as her frenzied staff struggled to post election results.&#13;&#10;“Our servers are under attack, we feel,” McGary said, stressing that the problem pertained only to transmitting totals to the public, not accurately counting the votes.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Downtime</ddb:outcome>      <ddb:reference>http://www.middletownjournal.com/news/election/website-hacked-election-officials-say-687529.html</ddb:reference>      <ddb:whidid>2010-76</ddb:whidid>    </item>    <item>      <title>WHID 2010-92: SQL Injection attack used in breach of 168,000 Netherlands travelers</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=50872</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-92: SQL Injection attack used in breach of 168,000 Netherlands travelers&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-92&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;May 18, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;An attacker has discovered a serious flaw in a website set up to encourage the use of smart cards for public transportation in the Netherlands, resulting in the leakage of personal information of more than 168,000 travelers.&lt;br&gt;The website offered a coupon for a free trip using the OV smart card system and was set up to promote the new system which is being slowly rolled out throughout the region. According to Webwerld, a tech publication based in the Netherlands, the names, addresses and telephone numbers of individuals who signed up were publicly available as a result of the flaw.&lt;br&gt;Information about the flaw was exposed by an anonymous hacker who gave the magazine a video demonstrating the error using a SQL injection attack. The hacker told the magazine that he made the flaw publicly available because there is no excuse for simple website mistakes. The website has since been taken offline.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Government&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;Netherlands&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://itknowledgeexchange.techtarget.com/security-bytes/sql-injection-attack-used-in-breach-of-168000-netherlands-travelers/&quot;&gt;http://itknowledgeexchange.techtarget.com/security-bytes/sql-injection-attack-used-in-breach-of-168000-netherlands-travelers/&lt;/a></description>      <pubDate>Mon, 24 May 2010 13:54:42 -0400</pubDate>      <ddb:attackedentityfield>Government</ddb:attackedentityfield>      <ddb:attackedentitygeography>Netherlands</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>May 18, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-92: SQL Injection attack used in breach of 168,000 Netherlands travelers</ddb:entrytitle>      <ddb:incidentdescription>An attacker has discovered a serious flaw in a website set up to encourage the use of smart cards for public transportation in the Netherlands, resulting in the leakage of personal information of more than 168,000 travelers.&#13;&#10;&#13;&#10;The website offered a coupon for a free trip using the OV smart card system and was set up to promote the new system which is being slowly rolled out throughout the region. According to Webwerld, a tech publication based in the Netherlands, the names, addresses and telephone numbers of individuals who signed up were publicly available as a result of the flaw.&#13;&#10;&#13;&#10;Information about the flaw was exposed by an anonymous hacker who gave the magazine a video demonstrating the error using a SQL injection attack. The hacker told the magazine that he made the flaw publicly available because there is no excuse for simple website mistakes. The website has since been taken offline.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference>http://itknowledgeexchange.techtarget.com/security-bytes/sql-injection-attack-used-in-breach-of-168000-netherlands-travelers/</ddb:reference>      <ddb:whidid>2010-92</ddb:whidid>    </item>    <item>      <title>WHID 2010-88: phpnuke.org has been compromised</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=50618</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-88: phpnuke.org has been compromised&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-88&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;May 7, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Planting of Malware&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;Websense® Security Labs™ ThreatSeeker™ Network has discovered that the popular Web site, phpnuke.org, has been compromised.&lt;br&gt; &lt;br&gt;PHP-Nuke is a popular Web content management system (CMS), based on PHP and a database such as MySQL, PostgreSQL, Sybase, or Adabas. Earlier versions were open source and free software protected by GNU Public License, but since then it has become commercial software. As it is still very popular in the Internet community, it is not surprising that it has become a target of blackhat attacks.&lt;br&gt;  &lt;br&gt;The injected iframe hijacks the browser to a malicious site, where through several steps of iframe redirections the user finally ends up on a highly obfuscated malicious page.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Technology&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA&lt;br&gt;&lt;b&gt;Attacked System Technology: &lt;/b&gt;PHPNuke&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://community.websense.com/blogs/securitylabs/archive/2010/05/07/phpnuke-org-has-been-compromised.aspx&quot;&gt;http://community.websense.com/blogs/securitylabs/archive/2010/05/07/phpnuke-org-has-been-compromised.aspx&lt;/a></description>      <pubDate>Mon, 24 May 2010 13:54:42 -0400</pubDate>      <ddb:attackedentityfield>Technology</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology>PHPNuke</ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>May 7, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-88: phpnuke.org has been compromised</ddb:entrytitle>      <ddb:incidentdescription>Websense® Security Labs™ ThreatSeeker™ Network has discovered that the popular Web site, phpnuke.org, has been compromised.&#13;&#10; &#13;&#10;PHP-Nuke is a popular Web content management system (CMS), based on PHP and a database such as MySQL, PostgreSQL, Sybase, or Adabas. Earlier versions were open source and free software protected by GNU Public License, but since then it has become commercial software. As it is still very popular in the Internet community, it is not surprising that it has become a target of blackhat attacks.&#13;&#10;  &#13;&#10;The injected iframe hijacks the browser to a malicious site, where through several steps of iframe redirections the user finally ends up on a highly obfuscated malicious page.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Planting of Malware</ddb:outcome>      <ddb:reference>http://community.websense.com/blogs/securitylabs/archive/2010/05/07/phpnuke-org-has-been-compromised.aspx</ddb:reference>      <ddb:whidid>2010-88</ddb:whidid>    </item>    <item>      <title>WHID 2010-78: Butler County Election Website Hacked</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=50008</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-78: Butler County Election Website Hacked&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-78&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;May 5, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Downtime&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;The Butler County Sheriff will investigate an alleged hacking incident that brought  down election computers in that county last night, and slowed the reporting of votes.&lt;br&gt;The Board of Election tells our partners at the Journal News that the problem affected the reporting of vote totals, not the counting of votes itself.&lt;br&gt;The BOE says three services crashed during the incident and two unidentified sites were deliberately diverting traffic from the website.  The BOE believes the attack was deliberate.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Government&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://www.local12.com/news/local/story/Butler-County-Election-Website-Hacked/zsQw7iXCgkuoDeMvyY3dGA.cspx&quot;&gt;http://www.local12.com/news/local/story/Butler-County-Election-Website-Hacked/zsQw7iXCgkuoDeMvyY3dGA.cspx&lt;/a></description>      <pubDate>Mon, 24 May 2010 13:54:42 -0400</pubDate>      <ddb:attackedentityfield>Government</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>May 5, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-78: Butler County Election Website Hacked</ddb:entrytitle>      <ddb:incidentdescription>The Butler County Sheriff will investigate an alleged hacking incident that brought  down election computers in that county last night, and slowed the reporting of votes.&#13;&#10;&#13;&#10;The Board of Election tells our partners at the Journal News that the problem affected the reporting of vote totals, not the counting of votes itself.&#13;&#10;&#13;&#10;The BOE says three services crashed during the incident and two unidentified sites were deliberately diverting traffic from the website.  The BOE believes the attack was deliberate.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Downtime</ddb:outcome>      <ddb:reference>http://www.local12.com/news/local/story/Butler-County-Election-Website-Hacked/zsQw7iXCgkuoDeMvyY3dGA.cspx</ddb:reference>      <ddb:whidid>2010-78</ddb:whidid>    </item>    <item>      <title>WHID 2010-65: NewsBusters Knocked Offline</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=47610</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-65: NewsBusters Knocked Offline&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-65&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;April 9, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Downtime&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;A deliberate brute force attack, a criminal act, knocked NewsBusters offline since late Friday morning. More information to come, but now we’re back and we thank you for bearing with us as our tech team worked studiously to restore the site.&lt;br&gt;Read more: http://newsbusters.org/?q=blogs/nb-staff/2010/04/10/newsbusters-back-here-s-some-what-you-ve-missed#ixzz0kuulCcnh&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Media&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://newsbusters.org/?q=blogs/nb-staff/2010/04/10/newsbusters-back-here-s-some-what-you-ve-missed&quot;&gt;http://newsbusters.org/?q=blogs/nb-staff/2010/04/10/newsbusters-back-here-s-some-what-you-ve-missed&lt;/a></description>      <pubDate>Mon, 24 May 2010 13:54:42 -0400</pubDate>      <ddb:attackedentityfield>Media</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>April 9, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-65: NewsBusters Knocked Offline</ddb:entrytitle>      <ddb:incidentdescription>A deliberate brute force attack, a criminal act, knocked NewsBusters offline since late Friday morning. More information to come, but now we’re back and we thank you for bearing with us as our tech team worked studiously to restore the site.&#13;&#10;&#13;&#10;Read more: http://newsbusters.org/?q=blogs/nb-staff/2010/04/10/newsbusters-back-here-s-some-what-you-ve-missed#ixzz0kuulCcnh</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Downtime</ddb:outcome>      <ddb:reference>http://newsbusters.org/?q=blogs/nb-staff/2010/04/10/newsbusters-back-here-s-some-what-you-ve-missed</ddb:reference>      <ddb:whidid>2010-65</ddb:whidid>    </item>    <item>      <title>WHID 2010-71: Fire Alarm Company Burned by e-Banking Fraud</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=49462</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-71: Fire Alarm Company Burned by e-Banking Fraud&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-71&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;April 7, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Monetary Loss&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;A fire alarm company in Arkansas lost more than $110,000 this month when hackers stole the firm’s online banking credentials and drained its payroll account.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Finance&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA&lt;br&gt;&lt;b&gt;Cost: &lt;/b&gt;$110,000.00&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://krebsonsecurity.com/2010/04/fire-alarm-company-burned-by-e-banking-fraud/&quot;&gt;http://krebsonsecurity.com/2010/04/fire-alarm-company-burned-by-e-banking-fraud/&lt;/a></description>      <pubDate>Mon, 24 May 2010 13:54:42 -0400</pubDate>      <ddb:attackedentityfield>Finance</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost>$110,000.00</ddb:cost>      <ddb:dateoccured>April 7, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-71: Fire Alarm Company Burned by e-Banking Fraud</ddb:entrytitle>      <ddb:incidentdescription>A fire alarm company in Arkansas lost more than $110,000 this month when hackers stole the firm’s online banking credentials and drained its payroll account.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Monetary Loss</ddb:outcome>      <ddb:reference>http://krebsonsecurity.com/2010/04/fire-alarm-company-burned-by-e-banking-fraud/</ddb:reference>      <ddb:whidid>2010-71</ddb:whidid>    </item>    <item>      <title>WHID 2010-62: Computer Crooks Steal $100,000 from Ill. Town</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=46564</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-62: Computer Crooks Steal $100,000 from Ill. Town&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-62&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;March 11, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Monetary Loss&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;A rash of home foreclosures and abandoned dwellings had already taken its toll on the tax revenue for the Village of Summit, a town of 10,000 just outside Chicago. Then, in March, computer crooks broke into the town’s online bank account, making off with nearly $100,000.  According to Rivera, the theft took place Mar. 11, when her assistant went to log in to the town’s account at Bridgeview Bank. When the assistant submitted the credentials to the bank’s site, she was redirected to a page telling her that the bank’s site was experiencing technical difficulties. What she couldn’t have known was that the thieves were stalling her so that they could use the credentials she’d supplied to create their own interactive session with the town’s bank account.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Finance&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;Illinois, USA&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://www.krebsonsecurity.com/2010/04/computer-crooks-steal-100000-from-ill-town/&quot;&gt;http://www.krebsonsecurity.com/2010/04/computer-crooks-steal-100000-from-ill-town/&lt;/a></description>      <pubDate>Mon, 24 May 2010 13:54:42 -0400</pubDate>      <ddb:attackedentityfield>Finance</ddb:attackedentityfield>      <ddb:attackedentitygeography>Illinois, USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>March 11, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-62: Computer Crooks Steal $100,000 from Ill. Town</ddb:entrytitle>      <ddb:incidentdescription>A rash of home foreclosures and abandoned dwellings had already taken its toll on the tax revenue for the Village of Summit, a town of 10,000 just outside Chicago. Then, in March, computer crooks broke into the town’s online bank account, making off with nearly $100,000.  According to Rivera, the theft took place Mar. 11, when her assistant went to log in to the town’s account at Bridgeview Bank. When the assistant submitted the credentials to the bank’s site, she was redirected to a page telling her that the bank’s site was experiencing technical difficulties. What she couldn’t have known was that the thieves were stalling her so that they could use the credentials she’d supplied to create their own interactive session with the town’s bank account.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Monetary Loss</ddb:outcome>      <ddb:reference>http://www.krebsonsecurity.com/2010/04/computer-crooks-steal-100000-from-ill-town/</ddb:reference>      <ddb:whidid>2010-62</ddb:whidid>    </item>    <item>      <title>WHID 2010-82: Victorian councils, libraries taught security in hack</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=50161</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-82: Victorian councils, libraries taught security in hack&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-82&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;May 3, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Defacement&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;A hacker has busted the security of eight Victorian Government websites in a string of minor attacks on Sunday.&lt;br&gt;Purportedly hailing from an Indonesian hacking group, the hacker made unobtrusive defacements by inserting a text document into the homepages of six local council sites and two libraries.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;Indonesia&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Government&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;Australia&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://www.networkworld.com/news/2010/050310-victorian-councils-libraries-taught-security.html&quot;&gt;http://www.networkworld.com/news/2010/050310-victorian-councils-libraries-taught-security.html&lt;/a></description>      <pubDate>Mon, 24 May 2010 13:54:42 -0400</pubDate>      <ddb:attackedentityfield>Government</ddb:attackedentityfield>      <ddb:attackedentitygeography>Australia</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography>Indonesia</ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>May 3, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-82: Victorian councils, libraries taught security in hack</ddb:entrytitle>      <ddb:incidentdescription>A hacker has busted the security of eight Victorian Government websites in a string of minor attacks on Sunday.&#13;&#10;&#13;&#10;Purportedly hailing from an Indonesian hacking group, the hacker made unobtrusive defacements by inserting a text document into the homepages of six local council sites and two libraries.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Defacement</ddb:outcome>      <ddb:reference>http://www.networkworld.com/news/2010/050310-victorian-councils-libraries-taught-security.html</ddb:reference>      <ddb:whidid>2010-82</ddb:whidid>    </item>    <item>      <title>WHID 2010-83: High-profile tech blog is hacked</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=50212</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-83: High-profile tech blog is hacked&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-83&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;January 26, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Defacement&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;High-profile technology blog TechCrunch has been taken offline by hackers.&lt;br&gt;A message on the site said that it had been &quot;compromised by a security exploit&quot; but did not specify any further details.&lt;br&gt;&quot;We're working to identify the exploit and will bring the site back online shortly,&quot; the message read.&lt;br&gt;The site went down at around 0620 GMT and was replaced by various messages including a link to a site directing people towards adult material.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Media&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://news.bbc.co.uk/2/hi/technology/8480306.stm&quot;&gt;http://news.bbc.co.uk/2/hi/technology/8480306.stm&lt;/a></description>      <pubDate>Mon, 24 May 2010 13:54:42 -0400</pubDate>      <ddb:attackedentityfield>Media</ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>January 26, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-83: High-profile tech blog is hacked</ddb:entrytitle>      <ddb:incidentdescription>High-profile technology blog TechCrunch has been taken offline by hackers.&#13;&#10;A message on the site said that it had been &quot;compromised by a security exploit&quot; but did not specify any further details.&#13;&#10;&quot;We're working to identify the exploit and will bring the site back online shortly,&quot; the message read.&#13;&#10;The site went down at around 0620 GMT and was replaced by various messages including a link to a site directing people towards adult material.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Defacement</ddb:outcome>      <ddb:reference>http://news.bbc.co.uk/2/hi/technology/8480306.stm</ddb:reference>      <ddb:whidid>2010-83</ddb:whidid>    </item>    <item>      <title>WHID 2010-72: Blippy users’ credit card numbers found on Google</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=49511</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-72: Blippy users’ credit card numbers found on Google&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-72&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;April 23, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;Yesterday was a big day for social-oversharing site Blippy, which lets members automatically post their purchases to the Internet. The company announced $11.2 million in funding and was profiled in The New York Times.&lt;br&gt;Overnight, at least one Internet power user figured out a way to search for Blippy members’ credit card numbers on Google. A fairly obvious search for “from card” this morning returned 127 results that included full credit card numbers.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Web 2.0&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://venturebeat.com/2010/04/23/blippy-credit-card-citibank/&quot;&gt;http://venturebeat.com/2010/04/23/blippy-credit-card-citibank/&lt;/a></description>      <pubDate>Mon, 24 May 2010 20:58:00 -0400</pubDate>      <ddb:attackedentityfield>Web 2.0</ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>April 23, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-72: Blippy users’ credit card numbers found on Google</ddb:entrytitle>      <ddb:incidentdescription>Yesterday was a big day for social-oversharing site Blippy, which lets members automatically post their purchases to the Internet. The company announced $11.2 million in funding and was profiled in The New York Times.&#13;&#10;&#13;&#10;Overnight, at least one Internet power user figured out a way to search for Blippy members’ credit card numbers on Google. A fairly obvious search for “from card” this morning returned 127 results that included full credit card numbers.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference>http://venturebeat.com/2010/04/23/blippy-credit-card-citibank/</ddb:reference>      <ddb:whidid>2010-72</ddb:whidid>    </item>    <item>      <title>WHID 2010-66: Ads to blame for malware in Facebook's FarmTown?</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=47647</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-66: Ads to blame for malware in Facebook's FarmTown?&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-66&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;April 12, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Planting of Malware&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;The 9.6 million players of the Facebook game FarmTown are being warned about fake security warnings popping up that are designed to mislead people into paying for antivirus protection they don't need.&lt;br&gt;&quot;We are aware and have reported to the developers that many of our players have encountered the malware/spyware while on the FarmTown Site,&quot; the moderator of a user forum for FarmTown maker SlashKey warned over the weekend. &quot;We believe at this time that it is harmless to your computer and a result of one or more of the ads on the site, but you should NOT follow any links to any software claiming to 'clean your system.'&quot;&lt;br&gt;Sophos' Graham Cluley said it appeared that third-party advertising displayed underneath the FarmTown playing window is to blame.&lt;br&gt;&quot;In all likelihood, hackers have managed to poison some of the adverts that are being served to FarmTown by the outside advert provider,&quot; Cluley wrote on his blog.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Web 2.0&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA&lt;br&gt;&lt;b&gt;Attacked System Technology: &lt;/b&gt;Facebook&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://news.cnet.com/8301-27080_3-20002267-245.html&quot;&gt;http://news.cnet.com/8301-27080_3-20002267-245.html&lt;/a></description>      <pubDate>Mon, 24 May 2010 13:54:42 -0400</pubDate>      <ddb:attackedentityfield>Web 2.0</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology>Facebook</ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>April 12, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-66: Ads to blame for malware in Facebook's FarmTown?</ddb:entrytitle>      <ddb:incidentdescription>The 9.6 million players of the Facebook game FarmTown are being warned about fake security warnings popping up that are designed to mislead people into paying for antivirus protection they don't need.&#13;&#10;&quot;We are aware and have reported to the developers that many of our players have encountered the malware/spyware while on the FarmTown Site,&quot; the moderator of a user forum for FarmTown maker SlashKey warned over the weekend. &quot;We believe at this time that it is harmless to your computer and a result of one or more of the ads on the site, but you should NOT follow any links to any software claiming to 'clean your system.'&quot;&#13;&#10;Sophos' Graham Cluley said it appeared that third-party advertising displayed underneath the FarmTown playing window is to blame.&#13;&#10;&quot;In all likelihood, hackers have managed to poison some of the adverts that are being served to FarmTown by the outside advert provider,&quot; Cluley wrote on his blog.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Planting of Malware</ddb:outcome>      <ddb:reference>http://news.cnet.com/8301-27080_3-20002267-245.html</ddb:reference>      <ddb:whidid>2010-66</ddb:whidid>    </item>    <item>      <title>WHID 2010-70: Armenian websites attacked Turkish hackers</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=49410</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-70: Armenian websites attacked Turkish hackers&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-70&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;April 12, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Downtime&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;Turkish hackers have attacked several Armenian websites ahead of annual commemorative remembrances of the Armenian Genocide.&lt;br&gt;On April 12th, more than 250 sites were impacted when cyber terrorists attacked a server hosting sites including www.ArmeniaChat.com, www.ArmeniaSearch.com according to the owner of the sites (who wishes to remain anonymous), ANCA Communications Director Elizabeth Chouljian told PanARMENIAN.Net&lt;br&gt;The attackers also took down www.armenian.com, which is the website for Armenian Directory Yellow pages. Attackers attempted to hack into a second server which hosts www.ArmGate.com but were unsuccessful.  All the websites attacked were offline for a period of two days due to the damage caused by the attack. &lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;Turkey&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Government&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;Armenia&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://www.panarmenian.net/eng/it_telecom/news/47183/&quot;&gt;http://www.panarmenian.net/eng/it_telecom/news/47183/&lt;/a></description>      <pubDate>Mon, 24 May 2010 20:58:56 -0400</pubDate>      <ddb:attackedentityfield>Government</ddb:attackedentityfield>      <ddb:attackedentitygeography>Armenia</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography>Turkey</ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>April 12, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-70: Armenian websites attacked Turkish hackers</ddb:entrytitle>      <ddb:incidentdescription>Turkish hackers have attacked several Armenian websites ahead of annual commemorative remembrances of the Armenian Genocide.&#13;&#10;&#13;&#10;On April 12th, more than 250 sites were impacted when cyber terrorists attacked a server hosting sites including www.ArmeniaChat.com, www.ArmeniaSearch.com according to the owner of the sites (who wishes to remain anonymous), ANCA Communications Director Elizabeth Chouljian told PanARMENIAN.Net&#13;&#10;&#13;&#10;The attackers also took down www.armenian.com, which is the website for Armenian Directory Yellow pages. Attackers attempted to hack into a second server which hosts www.ArmGate.com but were unsuccessful.  All the websites attacked were offline for a period of two days due to the damage caused by the attack. </ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Downtime</ddb:outcome>      <ddb:reference>http://www.panarmenian.net/eng/it_telecom/news/47183/</ddb:reference>      <ddb:whidid>2010-70</ddb:whidid>    </item>    <item>      <title>WHID 2010-89: Breaking News: WordPress Hacked with Zettapetta on DreamHost</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=50662</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-89: Breaking News: WordPress Hacked with Zettapetta on DreamHost&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-89&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;May 6, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Planting of Malware&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;Early this morning, we received reports that WordPress blogs were hacked on Linux shared-hosting at DreamHost, as  well as other hosting companies. This is dangerous scareware which tries to install a virus on your visitor's computer.&lt;br&gt;WordPress, Zencart and other php-based platforms were hit. Our earliest hacked site report is of 5/6/2010 @ 9:17am.&lt;br&gt;This malware was just detected and is not showing up on website malware scanners yet. We have notified sucuri.net of this latest infection so that they can immediately update their malware detections systems.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Service Providers&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://www.wpsecuritylock.com/breaking-news-wordpress-hacked-with-zettapetta-on-dreamhost/&quot;&gt;http://www.wpsecuritylock.com/breaking-news-wordpress-hacked-with-zettapetta-on-dreamhost/&lt;/a></description>      <pubDate>Mon, 24 May 2010 13:54:42 -0400</pubDate>      <ddb:attackedentityfield>Service Providers</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>May 6, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-89: Breaking News: WordPress Hacked with Zettapetta on DreamHost</ddb:entrytitle>      <ddb:incidentdescription>Early this morning, we received reports that WordPress blogs were hacked on Linux shared-hosting at DreamHost, as  well as other hosting companies. This is dangerous scareware which tries to install a virus on your visitor's computer.&#13;&#10;WordPress, Zencart and other php-based platforms were hit. Our earliest hacked site report is of 5/6/2010 @ 9:17am.&#13;&#10;This malware was just detected and is not showing up on website malware scanners yet. We have notified sucuri.net of this latest infection so that they can immediately update their malware detections systems.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Planting of Malware</ddb:outcome>      <ddb:reference>http://www.wpsecuritylock.com/breaking-news-wordpress-hacked-with-zettapetta-on-dreamhost/</ddb:reference>      <ddb:whidid>2010-89</ddb:whidid>    </item>    <item>      <title>WHID 2010-67: Apache.org hit by targeted XSS attack, passwords compromised</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=47828</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-67: Apache.org hit by targeted XSS attack, passwords compromised&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-67&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;April 9, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Session Hijacking&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;On April 5th, the attackers via a compromised Slicehost server opened a new issue, INFRA-2591. This issue contained the following text:&lt;br&gt;ive got this error while browsing some projects in jira http://tinyurl.com/XXXXXXXXX [obscured]&lt;br&gt;Tinyurl is a URL redirection and shortening tool. This specific URL redirected back to the Apache instance of JIRA, at a special URL containing a cross site scripting (XSS) attack. The attack was crafted to steal the session cookie from the user logged-in to JIRA. When this issue was opened against the Infrastructure team, several of our administators clicked on the link. This compromised their sessions, including their JIRA administrator rights.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Technology&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://blogs.zdnet.com/security/?p=6123&amp;tag=nl.e539&quot;&gt;http://blogs.zdnet.com/security/?p=6123&amp;tag=nl.e539&lt;/a></description>      <pubDate>Mon, 24 May 2010 13:54:42 -0400</pubDate>      <ddb:attackedentityfield>Technology</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>April 9, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-67: Apache.org hit by targeted XSS attack, passwords compromised</ddb:entrytitle>      <ddb:incidentdescription>On April 5th, the attackers via a compromised Slicehost server opened a new issue, INFRA-2591. This issue contained the following text:&#13;&#10;&#13;&#10;ive got this error while browsing some projects in jira http://tinyurl.com/XXXXXXXXX [obscured]&#13;&#10;&#13;&#10;Tinyurl is a URL redirection and shortening tool. This specific URL redirected back to the Apache instance of JIRA, at a special URL containing a cross site scripting (XSS) attack. The attack was crafted to steal the session cookie from the user logged-in to JIRA. When this issue was opened against the Infrastructure team, several of our administators clicked on the link. This compromised their sessions, including their JIRA administrator rights.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Session Hijacking</ddb:outcome>      <ddb:reference>http://blogs.zdnet.com/security/?p=6123&amp;tag=nl.e539</ddb:reference>      <ddb:whidid>2010-67</ddb:whidid>    </item>    <item>      <title>WHID 2010-63: Police cuff 70 eBay fraud suspects</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=46598</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-63: Police cuff 70 eBay fraud suspects&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-63&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;April 6, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Fraud&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;Romanian police have arrested 70 suspected cybercrooks, thought to be members of three gangs which allegedly used compromised eBay accounts to run scams.&lt;br&gt;The alleged fraudsters obtained login credentials using phishing scams before using these trusted profiles to tout auctions for non-existent luxury goods (luxury cars, Rolex watches and even a recreational aircraft). Buyers handed over the loot but never received any goods in return.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;Romania&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Retail&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA&lt;br&gt;&lt;b&gt;Attacked System Technology: &lt;/b&gt;eBay&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://www.theregister.co.uk/2010/04/07/romania_cybercrime_bust/&quot;&gt;http://www.theregister.co.uk/2010/04/07/romania_cybercrime_bust/&lt;/a></description>      <pubDate>Mon, 24 May 2010 13:54:42 -0400</pubDate>      <ddb:attackedentityfield>Retail</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology>eBay</ddb:attackedsystemtechnology>      <ddb:attacksourcegeography>Romania</ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>April 6, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-63: Police cuff 70 eBay fraud suspects</ddb:entrytitle>      <ddb:incidentdescription>Romanian police have arrested 70 suspected cybercrooks, thought to be members of three gangs which allegedly used compromised eBay accounts to run scams.&#13;&#10;&#13;&#10;The alleged fraudsters obtained login credentials using phishing scams before using these trusted profiles to tout auctions for non-existent luxury goods (luxury cars, Rolex watches and even a recreational aircraft). Buyers handed over the loot but never received any goods in return.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Fraud</ddb:outcome>      <ddb:reference>http://www.theregister.co.uk/2010/04/07/romania_cybercrime_bust/</ddb:reference>      <ddb:whidid>2010-63</ddb:whidid>    </item>    <item>      <title>WHID 2010-81: Network Solutions customers hit by mass hack attack</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=50124</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-81: Network Solutions customers hit by mass hack attack&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-81&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;April 19, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Planting of Malware&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;Network Solutions' security team is battling a mysterious attack that has silently infected a &quot;huge&quot; number of the websites it hosts with malicious code.&lt;br&gt;The mass compromise affects sites running WordPress, Joomla, and plain-vanilla HTML, according to reports here and here from Securi Security and Stop Malvertising. Many of the infected sites include encoded javascript that secretly attempts to install malware on visitors' computers.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Service Providers&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA&lt;br&gt;&lt;b&gt;Attacked System Technology: &lt;/b&gt;WordPress&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://www.theregister.co.uk/2010/04/19/network_solutions_mass_hack/&quot;&gt;http://www.theregister.co.uk/2010/04/19/network_solutions_mass_hack/&lt;/a></description>      <pubDate>Mon, 24 May 2010 13:54:42 -0400</pubDate>      <ddb:attackedentityfield>Service Providers</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology>WordPress</ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>April 19, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-81: Network Solutions customers hit by mass hack attack</ddb:entrytitle>      <ddb:incidentdescription>Network Solutions' security team is battling a mysterious attack that has silently infected a &quot;huge&quot; number of the websites it hosts with malicious code.&#13;&#10;&#13;&#10;The mass compromise affects sites running WordPress, Joomla, and plain-vanilla HTML, according to reports here and here from Securi Security and Stop Malvertising. Many of the infected sites include encoded javascript that secretly attempts to install malware on visitors' computers.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Planting of Malware</ddb:outcome>      <ddb:reference>http://www.theregister.co.uk/2010/04/19/network_solutions_mass_hack/</ddb:reference>      <ddb:whidid>2010-81</ddb:whidid>    </item>    <item>      <title>WHID 2010-91: Twitter software bug forces followers</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=50814</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-91: Twitter software bug forces followers&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-91&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;May 10, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Disinformation&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;Twitter users had a big shock on Monday when they checked into the micro-blogging service. Their follower and following numbers were at 0, meaning they were suddenly very unpopular or something was seriously wrong with the site.&lt;br&gt;It was the latter, of course. To kill a bug that allowed a user to force other users to follow him or her, Twitter temporarily reset all follower/following counts to zero, according to the Twitter Status blog. Everything was back to normal by 11 a.m. Pacific.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Web 2.0&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA&lt;br&gt;&lt;b&gt;Attacked System Technology: &lt;/b&gt;Twitter&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://www.pcworld.com/article/195962/&quot;&gt;http://www.pcworld.com/article/195962/&lt;/a></description>      <pubDate>Mon, 24 May 2010 13:54:42 -0400</pubDate>      <ddb:attackedentityfield>Web 2.0</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology>Twitter</ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>May 10, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-91: Twitter software bug forces followers</ddb:entrytitle>      <ddb:incidentdescription>Twitter users had a big shock on Monday when they checked into the micro-blogging service. Their follower and following numbers were at 0, meaning they were suddenly very unpopular or something was seriously wrong with the site.&#13;&#10;&#13;&#10;It was the latter, of course. To kill a bug that allowed a user to force other users to follow him or her, Twitter temporarily reset all follower/following counts to zero, according to the Twitter Status blog. Everything was back to normal by 11 a.m. Pacific.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Disinformation</ddb:outcome>      <ddb:reference>http://www.pcworld.com/article/195962/</ddb:reference>      <ddb:whidid>2010-91</ddb:whidid>    </item>    <item>      <title>WHID 2010-87: Facebook hacker jailed after falsely accusing boyfriend of rape</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=50546</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-87: Facebook hacker jailed after falsely accusing boyfriend of rape&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-87&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;May 6, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Disinformation&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;A young mother who had accused her ex-boyfriend of rape hacked into his Facebook site to post a threat to herself to bolster her fakery.&lt;br&gt; &lt;br&gt;Zoe Williams was described as &quot;really wicked&quot; by the judge, who jailed her for four months.&lt;br&gt;A court heard she tried to set up her ex-boyfriend partner after accused him of raping her several times after the end of their five-year relationship in 2007.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;USA&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Web 2.0&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA&lt;br&gt;&lt;b&gt;Attacked System Technology: &lt;/b&gt;Facebook&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://www.telegraph.co.uk/technology/facebook/7685381/Facebook-hacker-jailed-after-falsely-accusing-boyfriend-of-rape.html&quot;&gt;http://www.telegraph.co.uk/technology/facebook/7685381/Facebook-hacker-jailed-after-falsely-accusing-boyfriend-of-rape.html&lt;/a></description>      <pubDate>Mon, 24 May 2010 13:54:42 -0400</pubDate>      <ddb:attackedentityfield>Web 2.0</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology>Facebook</ddb:attackedsystemtechnology>      <ddb:attacksourcegeography>USA</ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>May 6, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-87: Facebook hacker jailed after falsely accusing boyfriend of rape</ddb:entrytitle>      <ddb:incidentdescription>A young mother who had accused her ex-boyfriend of rape hacked into his Facebook site to post a threat to herself to bolster her fakery.&#13;&#10; &#13;&#10;Zoe Williams was described as &quot;really wicked&quot; by the judge, who jailed her for four months.&#13;&#10;A court heard she tried to set up her ex-boyfriend partner after accused him of raping her several times after the end of their five-year relationship in 2007.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Disinformation</ddb:outcome>      <ddb:reference>http://www.telegraph.co.uk/technology/facebook/7685381/Facebook-hacker-jailed-after-falsely-accusing-boyfriend-of-rape.html</ddb:reference>      <ddb:whidid>2010-87</ddb:whidid>    </item>    <item>      <title>WHID 2010-85: Facebook flaw exposes live chats</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=50444</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-85: Facebook flaw exposes live chats&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-85&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;May 6, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;Facebook has again come under fire for not doing enough to protect personal information after a security flaw allowed users to eavesdrop on private chat sessions.&lt;br&gt;The flaw also allowed Facebook members to view other people's pending friend requests.&lt;br&gt;The social networking site, which has more than 400 million active users, was forced to suspend the live chat function until engineers were able to fix the problem.&lt;br&gt;The flaw was in the Facebook feature that allows users to view their own privacy settings and could be easily exploited to view others' private information, according to TechCrunch blogger Steve O'Hear, who alerted the social networking site.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Web 2.0&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA&lt;br&gt;&lt;b&gt;Attacked System Technology: &lt;/b&gt;Facebook&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://www.infosecurity-magazine.com/view/9245/facebook-flaw-exposes-live-chats/&quot;&gt;http://www.infosecurity-magazine.com/view/9245/facebook-flaw-exposes-live-chats/&lt;/a></description>      <pubDate>Mon, 24 May 2010 13:54:42 -0400</pubDate>      <ddb:attackedentityfield>Web 2.0</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology>Facebook</ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>May 6, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-85: Facebook flaw exposes live chats</ddb:entrytitle>      <ddb:incidentdescription>Facebook has again come under fire for not doing enough to protect personal information after a security flaw allowed users to eavesdrop on private chat sessions.&#13;&#10;&#13;&#10;The flaw also allowed Facebook members to view other people's pending friend requests.&#13;&#10;&#13;&#10;The social networking site, which has more than 400 million active users, was forced to suspend the live chat function until engineers were able to fix the problem.&#13;&#10;&#13;&#10;The flaw was in the Facebook feature that allows users to view their own privacy settings and could be easily exploited to view others' private information, according to TechCrunch blogger Steve O'Hear, who alerted the social networking site.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference>http://www.infosecurity-magazine.com/view/9245/facebook-flaw-exposes-live-chats/</ddb:reference>      <ddb:whidid>2010-85</ddb:whidid>    </item>    <item>      <title>WHID 2010-75: Russian-born hacker selling 1.5m Facebook usernames</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=49655</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-75: Russian-born hacker selling 1.5m Facebook usernames&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-75&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;April 24, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Session Hijacking&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;A RUSSIAN-born hacker is attempting to sell Facebook IDs for as little as $25 per 100 usernames, social-media blog Mashable reports, citing researchers at VeriSign's iDefense.&lt;br&gt;The hacker, who calls himself Kirllos, has obtained 1.5 million Facebook IDs, or one for every 300 people who use the social networking website.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Web 2.0&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA&lt;br&gt;&lt;b&gt;Attacked System Technology: &lt;/b&gt;Facebook&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://www.news.com.au/technology/russian-born-hacker-selling-15m-facebook-usernames/story-e6frfro0-1225857706897&quot;&gt;http://www.news.com.au/technology/russian-born-hacker-selling-15m-facebook-usernames/story-e6frfro0-1225857706897&lt;/a></description>      <pubDate>Mon, 24 May 2010 13:54:42 -0400</pubDate>      <ddb:attackedentityfield>Web 2.0</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology>Facebook</ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>April 24, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-75: Russian-born hacker selling 1.5m Facebook usernames</ddb:entrytitle>      <ddb:incidentdescription>A RUSSIAN-born hacker is attempting to sell Facebook IDs for as little as $25 per 100 usernames, social-media blog Mashable reports, citing researchers at VeriSign's iDefense.&#13;&#10;&#13;&#10;The hacker, who calls himself Kirllos, has obtained 1.5 million Facebook IDs, or one for every 300 people who use the social networking website.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Session Hijacking</ddb:outcome>      <ddb:reference>http://www.news.com.au/technology/russian-born-hacker-selling-15m-facebook-usernames/story-e6frfro0-1225857706897</ddb:reference>      <ddb:whidid>2010-75</ddb:whidid>    </item>    <item>      <title>WHID 2010-79: Italian expert: the attack of Romanian hackers against La Stampa and Corriere newspapers was the most relevant in the last eight years</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=50050</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-79: Italian expert: the attack of Romanian hackers against La Stampa and Corriere newspapers was the most relevant in the last eight years&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-79&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;April 30, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Defacement&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;On April 30, a group of hackers, who sign as &quot;Romanian National Security&quot; attacked three of the most important media sites in Italy: La Stampa, Corriere della Sera and RAI. The Romanian hackers left a message inviting Italian journalists to avoid confusions between Romanians and gypsies. &lt;br&gt;The same group attacked in the last month the sites of the Daily Telegraph and Le Monde. However, unlike the British and French media, the Italian mass media did not mention the attack. Our HotNews.ro corresponded to Italy interviewed Italin Matteo Cavallini, responsible for IT security in the Commerce Ministry. He was one of the first Italians to raise the awareness about the attack of the Romanians hackers. &lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;Romania&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Media&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;Italy&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://english.hotnews.ro/stiri-regional_europe-7212366-italian-expert-the-attack-romanian-hackers-against-stampa-and-corriere-newspapers-was-the-most-relevant-the-last-eight-years.htm&quot;&gt;http://english.hotnews.ro/stiri-regional_europe-7212366-italian-expert-the-attack-romanian-hackers-against-stampa-and-corriere-newspapers-was-the-most-relevant-the-last-eight-years.htm&lt;/a></description>      <pubDate>Mon, 24 May 2010 13:54:42 -0400</pubDate>      <ddb:attackedentityfield>Media</ddb:attackedentityfield>      <ddb:attackedentitygeography>Italy</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography>Romania</ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>April 30, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-79: Italian expert: the attack of Romanian hackers against La Stampa and Corriere newspapers was the most relevant in the last eight years</ddb:entrytitle>      <ddb:incidentdescription>On April 30, a group of hackers, who sign as &quot;Romanian National Security&quot; attacked three of the most important media sites in Italy: La Stampa, Corriere della Sera and RAI. The Romanian hackers left a message inviting Italian journalists to avoid confusions between Romanians and gypsies. &#13;&#10;&#13;&#10;The same group attacked in the last month the sites of the Daily Telegraph and Le Monde. However, unlike the British and French media, the Italian mass media did not mention the attack. Our HotNews.ro corresponded to Italy interviewed Italin Matteo Cavallini, responsible for IT security in the Commerce Ministry. He was one of the first Italians to raise the awareness about the attack of the Romanians hackers. </ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Defacement</ddb:outcome>      <ddb:reference>http://english.hotnews.ro/stiri-regional_europe-7212366-italian-expert-the-attack-romanian-hackers-against-stampa-and-corriere-newspapers-was-the-most-relevant-the-last-eight-years.htm</ddb:reference>      <ddb:whidid>2010-79</ddb:whidid>    </item>    <item>      <title>WHID 2010-77: Kilpatrick's site down, spokesman suspects hackers</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=49959</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-77: Kilpatrick's site down, spokesman suspects hackers&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-77&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;May 5, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Downtime&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;The New York City-based spokesman for Kwame Kilpatrick complained this afternoon that www.friendsofkwame.com is not working properly, and he suspects hackers.&lt;br&gt;Mike Paul said he is investigating the matter seriously and will pursue prosecution if the site he is promoting on Kwame Kilpatrick’s behalf indeed has been tampered with by outsiders.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Government&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://www.freep.com/article/20100505/NEWS01/100505073/1322/Kilpatricks-site-down-spokesman-suspects-hackers&quot;&gt;http://www.freep.com/article/20100505/NEWS01/100505073/1322/Kilpatricks-site-down-spokesman-suspects-hackers&lt;/a></description>      <pubDate>Mon, 24 May 2010 13:54:42 -0400</pubDate>      <ddb:attackedentityfield>Government</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>May 5, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-77: Kilpatrick's site down, spokesman suspects hackers</ddb:entrytitle>      <ddb:incidentdescription>The New York City-based spokesman for Kwame Kilpatrick complained this afternoon that www.friendsofkwame.com is not working properly, and he suspects hackers.&#13;&#10;&#13;&#10;Mike Paul said he is investigating the matter seriously and will pursue prosecution if the site he is promoting on Kwame Kilpatrick’s behalf indeed has been tampered with by outsiders.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Downtime</ddb:outcome>      <ddb:reference>http://www.freep.com/article/20100505/NEWS01/100505073/1322/Kilpatricks-site-down-spokesman-suspects-hackers</ddb:reference>      <ddb:whidid>2010-77</ddb:whidid>    </item>    <item>      <title>WHID 2010-69: Walmart web site hacked and hosting spam</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=49373</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-69: Walmart web site hacked and hosting spam&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-69&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;April 15, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Link Spam&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;One of Walmart official web sites, www.walmartcommunity.com (for their Community Action Network)  has SPAM links.  The attackers probably injected the spam in one of their templates files. After a bit of search, we found all of them inside the footer.php&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Retail&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA&lt;br&gt;&lt;b&gt;Attacked System Technology: &lt;/b&gt;WordPress&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://blog.sucuri.net/2010/04/walmart-web-site-hacked-and-hosting.html&quot;&gt;http://blog.sucuri.net/2010/04/walmart-web-site-hacked-and-hosting.html&lt;/a></description>      <pubDate>Mon, 24 May 2010 13:54:42 -0400</pubDate>      <ddb:attackedentityfield>Retail</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology>WordPress</ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>April 15, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-69: Walmart web site hacked and hosting spam</ddb:entrytitle>      <ddb:incidentdescription>One of Walmart official web sites, www.walmartcommunity.com (for their Community Action Network)  has SPAM links.  The attackers probably injected the spam in one of their templates files. After a bit of search, we found all of them inside the footer.php</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Link Spam</ddb:outcome>      <ddb:reference>http://blog.sucuri.net/2010/04/walmart-web-site-hacked-and-hosting.html</ddb:reference>      <ddb:whidid>2010-69</ddb:whidid>    </item>    <item>      <title>WHID 2010-61: How Chinese Hackers Exploit Twitter, Google and Yahoo</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=46520</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-61: How Chinese Hackers Exploit Twitter, Google and Yahoo&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-61&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;April 6, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;A stunning new report issued last night by a team of U.S. and Canadian researchers highlights a critical development in the world of cyber crime: the use of popular services like Twitter, Google  (GOOG) and Yahoo (YHOO) to camouflage and carry out infiltrations at the highest level of international government and business.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;China&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Web 2.0&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://blogs.bnet.com/business-news/?p=856&quot;&gt;http://blogs.bnet.com/business-news/?p=856&lt;/a></description>      <pubDate>Mon, 24 May 2010 13:54:42 -0400</pubDate>      <ddb:attackedentityfield>Web 2.0</ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography>China</ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>April 6, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-61: How Chinese Hackers Exploit Twitter, Google and Yahoo</ddb:entrytitle>      <ddb:incidentdescription>A stunning new report issued last night by a team of U.S. and Canadian researchers highlights a critical development in the world of cyber crime: the use of popular services like Twitter, Google  (GOOG) and Yahoo (YHOO) to camouflage and carry out infiltrations at the highest level of international government and business.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference>http://blogs.bnet.com/business-news/?p=856</ddb:reference>      <ddb:whidid>2010-61</ddb:whidid>    </item>    <item>      <title>WHID 2010-64: Hundreds of Wordpress Blogs Hit by ‘Networkads.net’ Hack</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=47517</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-64: Hundreds of Wordpress Blogs Hit by ‘Networkads.net’ Hack&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-64&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;April 9, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Planting of Malware&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;A large number of bloggers using Wordpress are reporting that their sites recently were hacked and are redirecting visitors to a page that tries to install malicious software.&lt;br&gt;According to multiple postings on the Wordpress user forum and other blogs, the attack doesn’t modify or create files, but rather appears to inject a Web address — “networkads.net/grep” — directly into the target site’s database, so that any attempts to access the hacked site redirects the visitor to networkads.net. Worse yet, because of the way the attack is carried out, victim site owners are at least temporarily locked out of accessing their blogs from the Wordpress interface.&lt;br&gt;It’s not clear yet whether the point of compromise is a Wordpress vulnerability (users of the latest, patched version appear to be most affected), a malicious Wordpress plugin, or if a common service provider may be the culprit. However, nearly every site owner affected so far reports that Network Solutions is their current Web hosting provider.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Blogs&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked System Technology: &lt;/b&gt;WordPress&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://krebsonsecurity.com/2010/04/hundreds-of-wordpress-blogs-hit-by-networkads-net-hack/&quot;&gt;http://krebsonsecurity.com/2010/04/hundreds-of-wordpress-blogs-hit-by-networkads-net-hack/&lt;/a></description>      <pubDate>Mon, 24 May 2010 13:54:42 -0400</pubDate>      <ddb:attackedentityfield>Blogs</ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology>WordPress</ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>April 9, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-64: Hundreds of Wordpress Blogs Hit by ‘Networkads.net’ Hack</ddb:entrytitle>      <ddb:incidentdescription>A large number of bloggers using Wordpress are reporting that their sites recently were hacked and are redirecting visitors to a page that tries to install malicious software.&#13;&#10;&#13;&#10;According to multiple postings on the Wordpress user forum and other blogs, the attack doesn’t modify or create files, but rather appears to inject a Web address — “networkads.net/grep” — directly into the target site’s database, so that any attempts to access the hacked site redirects the visitor to networkads.net. Worse yet, because of the way the attack is carried out, victim site owners are at least temporarily locked out of accessing their blogs from the Wordpress interface.&#13;&#10;&#13;&#10;It’s not clear yet whether the point of compromise is a Wordpress vulnerability (users of the latest, patched version appear to be most affected), a malicious Wordpress plugin, or if a common service provider may be the culprit. However, nearly every site owner affected so far reports that Network Solutions is their current Web hosting provider.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Planting of Malware</ddb:outcome>      <ddb:reference>http://krebsonsecurity.com/2010/04/hundreds-of-wordpress-blogs-hit-by-networkads-net-hack/</ddb:reference>      <ddb:whidid>2010-64</ddb:whidid>    </item>    <item>      <title>WHID 2010-90: Facebook Board Member's Account Compromised</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=50713</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-90: Facebook Board Member's Account Compromised&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-90&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;May 10, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Phishing&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;A Facebook message sent out on Saturday from the account of company board member Jim Breyer to over 2,300 &quot;friends&quot; turns out to have been too good to be true.&lt;br&gt;The message, an invitation to an event at which attendees would be given a &quot;Facebook phone number,&quot; was a phishing attack, designed to capture information from recipients.&lt;br&gt;The incident underscores the risk of supplying Facebook with data that might be better kept private.&lt;br&gt;Facebook's appeal to cybercriminals arises from the high level of trust that users extend to Facebook messages, which are generally presumed to come from friends.&lt;br&gt;Compromising someone's Facebook account also provides immediate access to a pool of new potential victims: the friends of the person whose account has been hacked.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Web 2.0&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA&lt;br&gt;&lt;b&gt;Attacked System Technology: &lt;/b&gt;Facebook&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://www.informationweek.com/news/software/showArticle.jhtml?articleID=224701441&quot;&gt;http://www.informationweek.com/news/software/showArticle.jhtml?articleID=224701441&lt;/a></description>      <pubDate>Mon, 24 May 2010 13:54:42 -0400</pubDate>      <ddb:attackedentityfield>Web 2.0</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology>Facebook</ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>May 10, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-90: Facebook Board Member's Account Compromised</ddb:entrytitle>      <ddb:incidentdescription>A Facebook message sent out on Saturday from the account of company board member Jim Breyer to over 2,300 &quot;friends&quot; turns out to have been too good to be true.&#13;&#10;The message, an invitation to an event at which attendees would be given a &quot;Facebook phone number,&quot; was a phishing attack, designed to capture information from recipients.&#13;&#10;&#13;&#10;The incident underscores the risk of supplying Facebook with data that might be better kept private.&#13;&#10;&#13;&#10;Facebook's appeal to cybercriminals arises from the high level of trust that users extend to Facebook messages, which are generally presumed to come from friends.&#13;&#10;&#13;&#10;Compromising someone's Facebook account also provides immediate access to a pool of new potential victims: the friends of the person whose account has been hacked.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Phishing</ddb:outcome>      <ddb:reference>http://www.informationweek.com/news/software/showArticle.jhtml?articleID=224701441</ddb:reference>      <ddb:whidid>2010-90</ddb:whidid>    </item>    <item>      <title>WHID 2010-74: Another Zimbabwe news website attacked by hackers</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=49603</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-74: Another Zimbabwe news website attacked by hackers&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-74&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;April 24, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Downtime&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;London(ZimEye) Another Zimbabwe news website, the ZimDiaspora has been hacked by online criminals. As at Saturday, the website was no longer functioning and one of the editors speaking to ZimEye Saturday said that neither he nor the Hosting company were able to restore the site at the moment.&lt;br&gt;Despite the hosting company’s apparent desperation Saturday, ZimEye was able to trace the notorious hackers to a location in the Indonesian town of Bandug. The hackers specialise in hacking websites made by the Joomlah software on which the Zimdiaspora is built. They have also declared it openly that this is their field of speciality.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;Indonesia&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Media&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;Zimbabwe&lt;br&gt;&lt;b&gt;Attacked System Technology: &lt;/b&gt;Joomla&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://www.zimeye.org/?p=16521&quot;&gt;http://www.zimeye.org/?p=16521&lt;/a></description>      <pubDate>Mon, 24 May 2010 13:54:42 -0400</pubDate>      <ddb:attackedentityfield>Media</ddb:attackedentityfield>      <ddb:attackedentitygeography>Zimbabwe</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology>Joomla</ddb:attackedsystemtechnology>      <ddb:attacksourcegeography>Indonesia</ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>April 24, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-74: Another Zimbabwe news website attacked by hackers</ddb:entrytitle>      <ddb:incidentdescription>London(ZimEye) Another Zimbabwe news website, the ZimDiaspora has been hacked by online criminals. As at Saturday, the website was no longer functioning and one of the editors speaking to ZimEye Saturday said that neither he nor the Hosting company were able to restore the site at the moment.&#13;&#10;&#13;&#10;Despite the hosting company’s apparent desperation Saturday, ZimEye was able to trace the notorious hackers to a location in the Indonesian town of Bandug. The hackers specialise in hacking websites made by the Joomlah software on which the Zimdiaspora is built. They have also declared it openly that this is their field of speciality.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Downtime</ddb:outcome>      <ddb:reference>http://www.zimeye.org/?p=16521</ddb:reference>      <ddb:whidid>2010-74</ddb:whidid>    </item>    <item>      <title>WHID 2010-80: Hacked US Treasury websites serve visitors malware</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=50087</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-80: Hacked US Treasury websites serve visitors malware&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-80&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;May 3, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Planting of Malware&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;Updated Websites operated by the US Treasury Department are redirecting visitors to websites that attempt to install malware on their PCs, a security researcher warned on Monday.&lt;br&gt;The infection buries an invisible iframe in bep.treas.gov, moneyfactory.gov, and bep.gov that invokes malicious scripts from grepad.com, Roger Thompson, chief research officer of AVG Technologies, told The Register. The code was discovered late Sunday night and was active at time of writing, about 12 hours later.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Government&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://www.theregister.co.uk/2010/05/03/treasury_websites_attack/&quot;&gt;http://www.theregister.co.uk/2010/05/03/treasury_websites_attack/&lt;/a></description>      <pubDate>Mon, 24 May 2010 13:54:42 -0400</pubDate>      <ddb:attackedentityfield>Government</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>May 3, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-80: Hacked US Treasury websites serve visitors malware</ddb:entrytitle>      <ddb:incidentdescription>Updated Websites operated by the US Treasury Department are redirecting visitors to websites that attempt to install malware on their PCs, a security researcher warned on Monday.&#13;&#10;&#13;&#10;The infection buries an invisible iframe in bep.treas.gov, moneyfactory.gov, and bep.gov that invokes malicious scripts from grepad.com, Roger Thompson, chief research officer of AVG Technologies, told The Register. The code was discovered late Sunday night and was active at time of writing, about 12 hours later.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Planting of Malware</ddb:outcome>      <ddb:reference>http://www.theregister.co.uk/2010/05/03/treasury_websites_attack/</ddb:reference>      <ddb:whidid>2010-80</ddb:whidid>    </item>    <item>      <title>WHID 2010-68: Daily Telegraph website hacked</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=49325</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-68: Daily Telegraph website hacked&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-68&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;April 15, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Defacement&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;Part of the Daily Telegraph's website has been hacked, apparently by people in Romania who were aggrieved at its identification of &quot;gypsies&quot; and &quot;Romanians&quot;.&lt;br&gt;Its &quot;Short Breaks&quot; and Wine And Dine sections were both hacked, with the Short Breaks site still up at 12.55pm today, with a picture of a Romanian flag claiming to be for the &quot;Romanian National Security&quot;, some comments in Romanian and the remark in English at the bottom that &quot;Guess what, gypsies aren't romanians, morons.&quot; It also links to a Russian site which plays an MP3 called The Lonely Shepherd.&lt;br&gt;Sunbelt Software, which first noticed the hack, said that it had alerted the Telegraph when it noticed the hack.&lt;br&gt;The method used to hack into the site is not known. &lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;Romania&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Media&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;United Kingdom&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://www.guardian.co.uk/media/2010/apr/15/daily-telegraph-hacking&quot;&gt;http://www.guardian.co.uk/media/2010/apr/15/daily-telegraph-hacking&lt;/a></description>      <pubDate>Mon, 24 May 2010 20:59:27 -0400</pubDate>      <ddb:attackedentityfield>Media</ddb:attackedentityfield>      <ddb:attackedentitygeography>United Kingdom</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography>Romania</ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>April 15, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-68: Daily Telegraph website hacked</ddb:entrytitle>      <ddb:incidentdescription>Part of the Daily Telegraph's website has been hacked, apparently by people in Romania who were aggrieved at its identification of &quot;gypsies&quot; and &quot;Romanians&quot;.&#13;&#10;&#13;&#10;Its &quot;Short Breaks&quot; and Wine And Dine sections were both hacked, with the Short Breaks site still up at 12.55pm today, with a picture of a Romanian flag claiming to be for the &quot;Romanian National Security&quot;, some comments in Romanian and the remark in English at the bottom that &quot;Guess what, gypsies aren't romanians, morons.&quot; It also links to a Russian site which plays an MP3 called The Lonely Shepherd.&#13;&#10;&#13;&#10;Sunbelt Software, which first noticed the hack, said that it had alerted the Telegraph when it noticed the hack.&#13;&#10;&#13;&#10;The method used to hack into the site is not known. </ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Defacement</ddb:outcome>      <ddb:reference>http://www.guardian.co.uk/media/2010/apr/15/daily-telegraph-hacking</ddb:reference>      <ddb:whidid>2010-68</ddb:whidid>    </item>    <item>      <title>WHID 2010-73: Report: Music insider site source of leaked songs</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=49566</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-73: Report: Music insider site source of leaked songs&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-73&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;April 23, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Monetary Loss&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;As if the record industry hasn't tasted enough bitter irony lately, a bunch of album leaks over the weekend apparently came from a service used by music labels to share files with radio stations, media, and other trusted insiders.&lt;br&gt;According to a post on AbsolutePunk, somebody signed up for an account with Play MPE under false pretenses, claiming to be an Australian music critic. Then this person--apparently a teenage boy--figured out how to access music he wasn't entitled to, including upcoming releases by The Black Keys, Macy Gray, Hole, The Gaslight Anthem, and many other artists.&lt;br&gt;The AbsolutePunk story referred to this kid as a hacker, but looking at his self-described exploits, that term might be a little too strong. It's not as if he did any sophisticated DRM cracking. Rather, he noticed that that the URL in the Web-based download file had the characters &quot;songid=&quot; followed by a bunch of numbers. By changing the numbers, he was apparently able to to get other song downloads that he wasn't supposed to see.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Entertainment&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://news.cnet.com/8301-13526_3-20003331-27.html&quot;&gt;http://news.cnet.com/8301-13526_3-20003331-27.html&lt;/a></description>      <pubDate>Mon, 24 May 2010 13:54:42 -0400</pubDate>      <ddb:attackedentityfield>Entertainment</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>April 23, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-73: Report: Music insider site source of leaked songs</ddb:entrytitle>      <ddb:incidentdescription>As if the record industry hasn't tasted enough bitter irony lately, a bunch of album leaks over the weekend apparently came from a service used by music labels to share files with radio stations, media, and other trusted insiders.&#13;&#10;&#13;&#10;According to a post on AbsolutePunk, somebody signed up for an account with Play MPE under false pretenses, claiming to be an Australian music critic. Then this person--apparently a teenage boy--figured out how to access music he wasn't entitled to, including upcoming releases by The Black Keys, Macy Gray, Hole, The Gaslight Anthem, and many other artists.&#13;&#10;&#13;&#10;The AbsolutePunk story referred to this kid as a hacker, but looking at his self-described exploits, that term might be a little too strong. It's not as if he did any sophisticated DRM cracking. Rather, he noticed that that the URL in the Web-based download file had the characters &quot;songid=&quot; followed by a bunch of numbers. By changing the numbers, he was apparently able to to get other song downloads that he wasn't supposed to see.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Monetary Loss</ddb:outcome>      <ddb:reference>http://news.cnet.com/8301-13526_3-20003331-27.html</ddb:reference>      <ddb:whidid>2010-73</ddb:whidid>    </item>    <item>      <title>WHID 2010-86: China State News Agency Web Site Hit With Malware</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=50477</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-86: China State News Agency Web Site Hit With Malware&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-86&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;May 6, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Planting of Malware&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;A section of the Web site for China's state-run Xinhua news agency was found to be distributing malware last month, according to a Google malware scanning service that is still labeling the site as potentially harmful.&lt;br&gt;The &quot;news center&quot; section of the Xinhua's Web site, which displays a feed of the agency's stories, was found to have one scripting exploit and one Trojan on it during a scan, according to a Google Safe Browsing diagnostic page. No suspicious content was found on the site during a scan about ten days later, but the section of Xinhua's Web site is still being labeled potentially harmful in Google search results.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Government&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;China&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://news.yahoo.com/s/pcworld/20100506/tc_pcworld/chinastatenewsagencywebsitehitwithmalware&quot;&gt;http://news.yahoo.com/s/pcworld/20100506/tc_pcworld/chinastatenewsagencywebsitehitwithmalware&lt;/a></description>      <pubDate>Mon, 24 May 2010 13:54:42 -0400</pubDate>      <ddb:attackedentityfield>Government</ddb:attackedentityfield>      <ddb:attackedentitygeography>China</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>May 6, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-86: China State News Agency Web Site Hit With Malware</ddb:entrytitle>      <ddb:incidentdescription>A section of the Web site for China's state-run Xinhua news agency was found to be distributing malware last month, according to a Google malware scanning service that is still labeling the site as potentially harmful.&#13;&#10;The &quot;news center&quot; section of the Xinhua's Web site, which displays a feed of the agency's stories, was found to have one scripting exploit and one Trojan on it during a scan, according to a Google Safe Browsing diagnostic page. No suspicious content was found on the site during a scan about ten days later, but the section of Xinhua's Web site is still being labeled potentially harmful in Google search results.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Planting of Malware</ddb:outcome>      <ddb:reference>http://news.yahoo.com/s/pcworld/20100506/tc_pcworld/chinastatenewsagencywebsitehitwithmalware</ddb:reference>      <ddb:whidid>2010-86</ddb:whidid>    </item>    <item>      <title>WHID 2010-84: PHP Website XSS Defacement</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=50260</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-84: PHP Website XSS Defacement&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-84&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;May 2, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Defacement&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;Cross-site scripting , html injection and redirect on bugs.php.net and phpbuilder.com &lt;br&gt;Screenshots and proof of concept &lt;br&gt;Redirect from php site to google POC and XSS &lt;br&gt;Sample xss alert on phpbuilder.com&lt;br&gt;And now what about http://doc.php.net/phd/ar/phd/ ?&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Technology&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://security-sh3ll.blogspot.com/2010/05/php-website-xss-defacement.html&quot;&gt;http://security-sh3ll.blogspot.com/2010/05/php-website-xss-defacement.html&lt;/a></description>      <pubDate>Mon, 24 May 2010 13:54:42 -0400</pubDate>      <ddb:attackedentityfield>Technology</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>May 2, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-84: PHP Website XSS Defacement</ddb:entrytitle>      <ddb:incidentdescription>Cross-site scripting , html injection and redirect on bugs.php.net and phpbuilder.com &#13;&#10;&#13;&#10;Screenshots and proof of concept &#13;&#10;&#13;&#10;Redirect from php site to google POC and XSS &#13;&#10;&#13;&#10;Sample xss alert on phpbuilder.com&#13;&#10;&#13;&#10;And now what about http://doc.php.net/phd/ar/phd/ ?</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Defacement</ddb:outcome>      <ddb:reference>http://security-sh3ll.blogspot.com/2010/05/php-website-xss-defacement.html</ddb:reference>      <ddb:whidid>2010-84</ddb:whidid>    </item>    <item>      <title>WHID 2010-60: CNN redirect exploited by scammers</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=46481</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-60: CNN redirect exploited by scammers&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-60&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;April 6, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Link Spam&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;SPAMMERs use an Open Redirection vuln in a CNN ad site.  The clever touch was providing a link that exploits redirect functionality supported by CNN’s ad servers.  The link is structured as follows:&lt;br&gt;http://ads.cnn.com/event.ng/Type=click&amp;Redirect=http:/bit.ly/cP–XW&lt;br&gt;Clicking on the link sends a request to CNN which instructs the browser to send a second request to the redirect URL – in this case the shortened http:/bit.ly/cP—XW.  The host site would not be aware of the misuse – the spammer is simply abusing legitimate ad-serving functionality.&lt;br&gt;This technique provides several advantages to the spammer:&lt;br&gt;1)      The URL from cnn.com might give the impression that there was a genuine CNN-worthy story to be found&lt;br&gt;2)      The reputable site name would allay fears of anything malicious lurking at the end of the click.&lt;br&gt;3)      Most URL filtering solutions would not block the initial request to cnn.com (although reputable solutions would have been updated in real time about the follow on link which would be blocked)&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Media&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://blog.commtouch.com/cafe/email-security-news/cnn-redirect-exploited-by-scammers/?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed:+CommtouchCafe+(Commtouch+Café)&quot;&gt;http://blog.commtouch.com/cafe/email-security-news/cnn-redirect-exploited-by-scammers/?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed:+CommtouchCafe+(Commtouch+Café)&lt;/a></description>      <pubDate>Mon, 24 May 2010 13:54:42 -0400</pubDate>      <ddb:attackedentityfield>Media</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>April 6, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-60: CNN redirect exploited by scammers</ddb:entrytitle>      <ddb:incidentdescription>SPAMMERs use an Open Redirection vuln in a CNN ad site.  The clever touch was providing a link that exploits redirect functionality supported by CNN’s ad servers.  The link is structured as follows:&#13;&#10;http://ads.cnn.com/event.ng/Type=click&amp;Redirect=http:/bit.ly/cP–XW&#13;&#10;Clicking on the link sends a request to CNN which instructs the browser to send a second request to the redirect URL – in this case the shortened http:/bit.ly/cP—XW.  The host site would not be aware of the misuse – the spammer is simply abusing legitimate ad-serving functionality.&#13;&#10;This technique provides several advantages to the spammer:&#13;&#10;1)      The URL from cnn.com might give the impression that there was a genuine CNN-worthy story to be found&#13;&#10;2)      The reputable site name would allay fears of anything malicious lurking at the end of the click.&#13;&#10;3)      Most URL filtering solutions would not block the initial request to cnn.com (although reputable solutions would have been updated in real time about the follow on link which would be blocked)</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Link Spam</ddb:outcome>      <ddb:reference>http://blog.commtouch.com/cafe/email-security-news/cnn-redirect-exploited-by-scammers/?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed:+CommtouchCafe+(Commtouch+Café)</ddb:reference>      <ddb:whidid>2010-60</ddb:whidid>    </item>    <item>      <title>WHID 2009-49: RockYou Hack: From Bad To Worse</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=43356</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2009-49: RockYou Hack: From Bad To Worse&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2009-49&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;December 14, 2009&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;Earlier today news spread that social application site RockYou had suffered a data breached that resulted in the exposure of over 32 Million user accounts. To compound the severity of the security breach, it was found that RockYou are storing all user account data in plain text in their database, exposing all that information to attackers. RockYou have yet to inform users of the breach, and their blog is eerily silent – but the details of the security breach are going from bad to worse.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Web 2.0&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://techcrunch.com/2009/12/14/rockyou-hack-security-myspace-facebook-passwords/&quot;&gt;http://techcrunch.com/2009/12/14/rockyou-hack-security-myspace-facebook-passwords/&lt;/a></description>      <pubDate>Wed, 16 Jun 2010 14:12:18 -0400</pubDate>      <ddb:attackedentityfield>Web 2.0</ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>December 14, 2009</ddb:dateoccured>      <ddb:entrytitle>WHID 2009-49: RockYou Hack: From Bad To Worse</ddb:entrytitle>      <ddb:incidentdescription>Earlier today news spread that social application site RockYou had suffered a data breached that resulted in the exposure of over 32 Million user accounts. To compound the severity of the security breach, it was found that RockYou are storing all user account data in plain text in their database, exposing all that information to attackers. RockYou have yet to inform users of the breach, and their blog is eerily silent – but the details of the security breach are going from bad to worse.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference>http://techcrunch.com/2009/12/14/rockyou-hack-security-myspace-facebook-passwords/</ddb:reference>      <ddb:whidid>2009-49</ddb:whidid>    </item>    <item>      <title>WHID 2010-57: Web security under attack from ads in prominent advertising programs</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=46140</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-57: Web security under attack from ads in prominent advertising programs&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-57&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;March 31, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Planting of Malware&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;Advertisement programs operated by Google, Yahoo and Fox were recently found to deliver malware, according to CNET. Avast, the Czech Republic-based web security company, discovered the malware and stated that this particular strain target holes in popular web browsers such as Firefox and Internet Explorer.&lt;br&gt;Yahoo's Yield Manager and Fox FirmServe manage nearly 50 percent of all online ads. Google's program DoubleClick was found to contain some malvertisements, but not to the extent of Yield Manager or FirmServe. Other advertising platforms like Facebook and MySpace have also experienced similar problems in recent months.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Information Services&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://www.mxlogic.com/securitynews/web-security/web-security-under-attack-from-ads-in-prominent-advertising-programs651.cfm&quot;&gt;http://www.mxlogic.com/securitynews/web-security/web-security-under-attack-from-ads-in-prominent-advertising-programs651.cfm&lt;/a></description>      <pubDate>Mon, 24 May 2010 13:54:42 -0400</pubDate>      <ddb:attackedentityfield>Information Services</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>March 31, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-57: Web security under attack from ads in prominent advertising programs</ddb:entrytitle>      <ddb:incidentdescription>Advertisement programs operated by Google, Yahoo and Fox were recently found to deliver malware, according to CNET. Avast, the Czech Republic-based web security company, discovered the malware and stated that this particular strain target holes in popular web browsers such as Firefox and Internet Explorer.&#13;&#10;&#13;&#10;Yahoo's Yield Manager and Fox FirmServe manage nearly 50 percent of all online ads. Google's program DoubleClick was found to contain some malvertisements, but not to the extent of Yield Manager or FirmServe. Other advertising platforms like Facebook and MySpace have also experienced similar problems in recent months.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Planting of Malware</ddb:outcome>      <ddb:reference>http://www.mxlogic.com/securitynews/web-security/web-security-under-attack-from-ads-in-prominent-advertising-programs651.cfm</ddb:reference>      <ddb:whidid>2010-57</ddb:whidid>    </item>    <item>      <title>WHID 2010-32: Crooks Crank Up Volume of E-Banking Attacks</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=43849</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-32: Crooks Crank Up Volume of E-Banking Attacks&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-32&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;February 23, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Monetary Loss&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;Computer crooks stole more than $200,000 from an auto body shop in Ohio last month in a brazen online robbery. The attack is yet another example of how thieves are using malicious software to bypass bank security technologies that are often touted as strong deterrents to this type of fraud.&lt;br&gt;Story outlines Banking Trojan types of activity which intercepted the one-time passcode and then redirected the real user to a fake maintenance page.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Finance&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;Ohio, USA&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://www.krebsonsecurity.com/2010/03/crooks-crank-up-volume-of-e-banking-attacks/&quot;&gt;http://www.krebsonsecurity.com/2010/03/crooks-crank-up-volume-of-e-banking-attacks/&lt;/a></description>      <pubDate>Mon, 24 May 2010 13:54:42 -0400</pubDate>      <ddb:attackedentityfield>Finance</ddb:attackedentityfield>      <ddb:attackedentitygeography>Ohio, USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>February 23, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-32: Crooks Crank Up Volume of E-Banking Attacks</ddb:entrytitle>      <ddb:incidentdescription>Computer crooks stole more than $200,000 from an auto body shop in Ohio last month in a brazen online robbery. The attack is yet another example of how thieves are using malicious software to bypass bank security technologies that are often touted as strong deterrents to this type of fraud.&#13;&#10;&#13;&#10;Story outlines Banking Trojan types of activity which intercepted the one-time passcode and then redirected the real user to a fake maintenance page.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Monetary Loss</ddb:outcome>      <ddb:reference>http://www.krebsonsecurity.com/2010/03/crooks-crank-up-volume-of-e-banking-attacks/</ddb:reference>      <ddb:whidid>2010-32</ddb:whidid>    </item>    <item>      <title>WHID 2010-7: Hacker attacks Ceridian; data from 27,000 at risk</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=42201</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-7: Hacker attacks Ceridian; data from 27,000 at risk&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-7&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;January 20, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;A hacker attack at payroll processing firm Ceridian Corp. of Bloomington has potentially revealed the names, Social Security numbers, and, in some cases, the birth dates and bank accounts of 27,000 employees working at 1,900 companies nationwide.  The attack was against the Powerpay payroll system.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Finance&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;Minnesota, USA&lt;br&gt;&lt;b&gt;Number of Records: &lt;/b&gt;27,000&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://www.startribune.com/business/83505102.html?elr=KArksUUUU&quot;&gt;http://www.startribune.com/business/83505102.html?elr=KArksUUUU&lt;/a></description>      <pubDate>Mon, 24 May 2010 21:16:11 -0400</pubDate>      <ddb:attackedentityfield>Finance</ddb:attackedentityfield>      <ddb:attackedentitygeography>Minnesota, USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>January 20, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-7: Hacker attacks Ceridian; data from 27,000 at risk</ddb:entrytitle>      <ddb:incidentdescription>A hacker attack at payroll processing firm Ceridian Corp. of Bloomington has potentially revealed the names, Social Security numbers, and, in some cases, the birth dates and bank accounts of 27,000 employees working at 1,900 companies nationwide.  The attack was against the Powerpay payroll system.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords>27,000</ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference>http://www.startribune.com/business/83505102.html?elr=KArksUUUU</ddb:reference>      <ddb:whidid>2010-7</ddb:whidid>    </item>    <item>      <title>WHID 2010-15: Villar website 'hacked'</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=42707</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-15: Villar website 'hacked'&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-15&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;March 19, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Defacement&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;The rivalry between Senators Manny Villar and Benigno &quot;Noynoy&quot; Aquino has gone beyond the campaign trail as the official website of the Nacionalista Party presidential bet supposedly got hacked by an Aquino supporter Monday.  At about 10 a.m., Villar's official website www.mannyvillar.co.ph contained a blog entry titled &quot;Hacked by Kris Aquino.&quot;  The entry, which was written in &quot;swardspeak&quot;, took jabs at Villar's marketing strategy and ended up coaxing its readers to vote for Aquino instead. &lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;Phillipines&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Politics&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;Phillipines&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://www.abs-cbnnews.com/lifestyle/03/22/10/villar-website-hacked&quot;&gt;http://www.abs-cbnnews.com/lifestyle/03/22/10/villar-website-hacked&lt;/a></description>      <pubDate>Mon, 24 May 2010 21:15:24 -0400</pubDate>      <ddb:attackedentityfield>Politics</ddb:attackedentityfield>      <ddb:attackedentitygeography>Phillipines</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography>Phillipines</ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>March 19, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-15: Villar website 'hacked'</ddb:entrytitle>      <ddb:incidentdescription>The rivalry between Senators Manny Villar and Benigno &quot;Noynoy&quot; Aquino has gone beyond the campaign trail as the official website of the Nacionalista Party presidential bet supposedly got hacked by an Aquino supporter Monday.  At about 10 a.m., Villar's official website www.mannyvillar.co.ph contained a blog entry titled &quot;Hacked by Kris Aquino.&quot;  The entry, which was written in &quot;swardspeak&quot;, took jabs at Villar's marketing strategy and ended up coaxing its readers to vote for Aquino instead. </ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Defacement</ddb:outcome>      <ddb:reference>http://www.abs-cbnnews.com/lifestyle/03/22/10/villar-website-hacked</ddb:reference>      <ddb:whidid>2010-15</ddb:whidid>    </item>    <item>      <title>WHID 2010-56: Facebook Flub Leaks Private E-Mail Addresses</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=46107</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-56: Facebook Flub Leaks Private E-Mail Addresses&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-56&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;March 31, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;Private e-mail addresses that many Facebook users wanted to keep hidden were revealed publicly last night on a multitude of Facebook profiles, Gawker reports. The glitch lasted about 30 minutes before Facebook sealed the gap.&lt;br&gt;It might be that Facebook's recently proposed changes to its privacy settings could be to blame for the hiccup. PC World writer Paul Suarez reported that &quot;One of those changes [to Facebook's Privacy Policy and Statement of Rights and Responsibilities] would make it possible for Facebook to send your name, photo, friend list, and any public information about you and your friends to preapproved third-party Web sites.&quot; A slight tweak to broadcasting profile information could have resulted in this embarrassing flub.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Web 2.0&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://www.cio.com/article/589021/Facebook_Flub_Leaks_Private_E_Mail_Addresses&quot;&gt;http://www.cio.com/article/589021/Facebook_Flub_Leaks_Private_E_Mail_Addresses&lt;/a></description>      <pubDate>Mon, 24 May 2010 13:54:42 -0400</pubDate>      <ddb:attackedentityfield>Web 2.0</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>March 31, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-56: Facebook Flub Leaks Private E-Mail Addresses</ddb:entrytitle>      <ddb:incidentdescription>Private e-mail addresses that many Facebook users wanted to keep hidden were revealed publicly last night on a multitude of Facebook profiles, Gawker reports. The glitch lasted about 30 minutes before Facebook sealed the gap.&#13;&#10;It might be that Facebook's recently proposed changes to its privacy settings could be to blame for the hiccup. PC World writer Paul Suarez reported that &quot;One of those changes [to Facebook's Privacy Policy and Statement of Rights and Responsibilities] would make it possible for Facebook to send your name, photo, friend list, and any public information about you and your friends to preapproved third-party Web sites.&quot; A slight tweak to broadcasting profile information could have resulted in this embarrassing flub.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference>http://www.cio.com/article/589021/Facebook_Flub_Leaks_Private_E_Mail_Addresses</ddb:reference>      <ddb:whidid>2010-56</ddb:whidid>    </item>    <item>      <title>WHID 2010-45: Online Thieves Take $205,000 Bite Out of Missouri Dental Practice</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=44524</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-45: Online Thieves Take $205,000 Bite Out of Missouri Dental Practice&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-45&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;March 30, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Monetary Loss&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;Organized computer criminals yanked more than $200,000 out of the online bank accounts of a Missouri dental practice this month, in yet another attack that exposes the financial risks that small- to mid-sized organizations face when banking online.&lt;br&gt;Smile Zone is still investigating how the thieves compromised the account. But in case after case I’ve reported on involving this type of fraud, the attackers hacked the victim’s computer networks using a Trojan horse program known as Zeus or Zbot, which allows the criminals to tunnel back through the victim’s PC in order to log into the target account without raising red flags or additional security mechanisms.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Finance&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;Missouri, USA&lt;br&gt;&lt;b&gt;Cost: &lt;/b&gt;$205,000.00&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://www.krebsonsecurity.com/2010/03/online-thieves-take-205000-bite-out-of-missouri-dental-practice/&quot;&gt;http://www.krebsonsecurity.com/2010/03/online-thieves-take-205000-bite-out-of-missouri-dental-practice/&lt;/a></description>      <pubDate>Mon, 24 May 2010 13:54:42 -0400</pubDate>      <ddb:attackedentityfield>Finance</ddb:attackedentityfield>      <ddb:attackedentitygeography>Missouri, USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost>$205,000.00</ddb:cost>      <ddb:dateoccured>March 30, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-45: Online Thieves Take $205,000 Bite Out of Missouri Dental Practice</ddb:entrytitle>      <ddb:incidentdescription>Organized computer criminals yanked more than $200,000 out of the online bank accounts of a Missouri dental practice this month, in yet another attack that exposes the financial risks that small- to mid-sized organizations face when banking online.&#13;&#10;&#13;&#10;Smile Zone is still investigating how the thieves compromised the account. But in case after case I’ve reported on involving this type of fraud, the attackers hacked the victim’s computer networks using a Trojan horse program known as Zeus or Zbot, which allows the criminals to tunnel back through the victim’s PC in order to log into the target account without raising red flags or additional security mechanisms.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Monetary Loss</ddb:outcome>      <ddb:reference>http://www.krebsonsecurity.com/2010/03/online-thieves-take-205000-bite-out-of-missouri-dental-practice/</ddb:reference>      <ddb:whidid>2010-45</ddb:whidid>    </item>    <item>      <title>WHID 2010-31: Organized Crooks Hit Ark. Utility</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=43806</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-31: Organized Crooks Hit Ark. Utility&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-31&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;March 4, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Monetary Loss&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;In a separate incident on March 4, organized crooks stole roughly $130,000 from North Garland County Regional Water District, a public, nonprofit utility in Hot Springs, Ark. Again, thieves somehow broke into the utility’s online bank account and set up unauthorized transfers to more than a dozen individuals around the country that were not affiliated with the district.&lt;br&gt;Manager Bill Reinhardt said the district is still investigating how the thieves gained access to its accounts, and that it had notified the FBI about the breach. Reinhardt said the district has so far worked with its bank to reverse about half of the fraudulent transfers.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Finance&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;Arkansas, USA&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://www.krebsonsecurity.com/2010/03/organized-crooks-hit-nj-town-arizona-utility/#more-1918&quot;&gt;http://www.krebsonsecurity.com/2010/03/organized-crooks-hit-nj-town-arizona-utility/#more-1918&lt;/a></description>      <pubDate>Mon, 24 May 2010 13:54:42 -0400</pubDate>      <ddb:attackedentityfield>Finance</ddb:attackedentityfield>      <ddb:attackedentitygeography>Arkansas, USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>March 4, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-31: Organized Crooks Hit Ark. Utility</ddb:entrytitle>      <ddb:incidentdescription>In a separate incident on March 4, organized crooks stole roughly $130,000 from North Garland County Regional Water District, a public, nonprofit utility in Hot Springs, Ark. Again, thieves somehow broke into the utility’s online bank account and set up unauthorized transfers to more than a dozen individuals around the country that were not affiliated with the district.&#13;&#10;&#13;&#10;Manager Bill Reinhardt said the district is still investigating how the thieves gained access to its accounts, and that it had notified the FBI about the breach. Reinhardt said the district has so far worked with its bank to reverse about half of the fraudulent transfers.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Monetary Loss</ddb:outcome>      <ddb:reference>http://www.krebsonsecurity.com/2010/03/organized-crooks-hit-nj-town-arizona-utility/#more-1918</ddb:reference>      <ddb:whidid>2010-31</ddb:whidid>    </item>    <item>      <title>WHID 2010-33: N.Y. Firm Faces Bankruptcy from $164,000 E-Banking Loss</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=43887</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-33: N.Y. Firm Faces Bankruptcy from $164,000 E-Banking Loss&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-33&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;February 15, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Monetary Loss&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;A New York marketing firm that as recently as two weeks ago was preparing to be acquired now is facing bankruptcy from a computer virus infection that cost the company more than $164,000.&lt;br&gt;Immediately before the fraud occurred, Mrs. McCarthy found that her Windows PC would no longer boot, and that the computer complained it could not find vital operating system files. “She was using it one day and then this blue screen of death just came on her screen,” said a longtime friend who was helping McCarthy triage her computer.&lt;br&gt;Later, McCarthy’s friend would confirm that her system had been infected with the ZeuS Trojan, a potent family of malware that steals passwords and lets cyber thieves control the infected host from afar. ZeuS also includes a feature called “kill operating system,” which criminals have used in prior bank heists to effectively keep the victim offline and buy themselves time to make off with the cash.&lt;br&gt;Karen McCarthy said TDBank has dug in its heels and is now saying it has no responsibility for the loss.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Finance&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;NY, USA&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://www.krebsonsecurity.com/2010/02/n-y-firm-faces-bankruptcy-from-164000-e-banking-loss/&quot;&gt;http://www.krebsonsecurity.com/2010/02/n-y-firm-faces-bankruptcy-from-164000-e-banking-loss/&lt;/a></description>      <pubDate>Mon, 24 May 2010 13:54:42 -0400</pubDate>      <ddb:attackedentityfield>Finance</ddb:attackedentityfield>      <ddb:attackedentitygeography>NY, USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>February 15, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-33: N.Y. Firm Faces Bankruptcy from $164,000 E-Banking Loss</ddb:entrytitle>      <ddb:incidentdescription>A New York marketing firm that as recently as two weeks ago was preparing to be acquired now is facing bankruptcy from a computer virus infection that cost the company more than $164,000.&#13;&#10;Immediately before the fraud occurred, Mrs. McCarthy found that her Windows PC would no longer boot, and that the computer complained it could not find vital operating system files. “She was using it one day and then this blue screen of death just came on her screen,” said a longtime friend who was helping McCarthy triage her computer.&#13;&#10;&#13;&#10;Later, McCarthy’s friend would confirm that her system had been infected with the ZeuS Trojan, a potent family of malware that steals passwords and lets cyber thieves control the infected host from afar. ZeuS also includes a feature called “kill operating system,” which criminals have used in prior bank heists to effectively keep the victim offline and buy themselves time to make off with the cash.&#13;&#10;&#13;&#10;Karen McCarthy said TDBank has dug in its heels and is now saying it has no responsibility for the loss.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Monetary Loss</ddb:outcome>      <ddb:reference>http://www.krebsonsecurity.com/2010/02/n-y-firm-faces-bankruptcy-from-164000-e-banking-loss/</ddb:reference>      <ddb:whidid>2010-33</ddb:whidid>    </item>    <item>      <title>WHID 2010-14: Dismantling of Saudi-CIA Web site illustrates need for clearer cyberwar policies</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=42652</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-14: Dismantling of Saudi-CIA Web site illustrates need for clearer cyberwar policies&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-14&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;March 19, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Downtime&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;A very interesting cyberwarfare story involving US government/military on both sides.  By early 2008, top U.S. military officials had become convinced that extremists planning attacks on American forces in Iraq were making use of a Web site set up by the Saudi government and the CIA to uncover terrorist plots in the kingdom.  Elite U.S. military computer specialists, over the objections of the CIA, mounted a cyberattack that dismantled the online forum.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;USA&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Government&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;Saudi Arabia&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://www.washingtonpost.com/wp-dyn/content/article/2010/03/18/AR2010031805464.html&quot;&gt;http://www.washingtonpost.com/wp-dyn/content/article/2010/03/18/AR2010031805464.html&lt;/a></description>      <pubDate>Mon, 24 May 2010 13:54:42 -0400</pubDate>      <ddb:attackedentityfield>Government</ddb:attackedentityfield>      <ddb:attackedentitygeography>Saudi Arabia</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography>USA</ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>March 19, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-14: Dismantling of Saudi-CIA Web site illustrates need for clearer cyberwar policies</ddb:entrytitle>      <ddb:incidentdescription>A very interesting cyberwarfare story involving US government/military on both sides.  By early 2008, top U.S. military officials had become convinced that extremists planning attacks on American forces in Iraq were making use of a Web site set up by the Saudi government and the CIA to uncover terrorist plots in the kingdom.  Elite U.S. military computer specialists, over the objections of the CIA, mounted a cyberattack that dismantled the online forum.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Downtime</ddb:outcome>      <ddb:reference>http://www.washingtonpost.com/wp-dyn/content/article/2010/03/18/AR2010031805464.html</ddb:reference>      <ddb:whidid>2010-14</ddb:whidid>    </item>    <item>      <title>WHID 2010-8: Cross-site scripting vulnerabilities see two political websites hacked</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=42238</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-8: Cross-site scripting vulnerabilities see two political websites hacked&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-8&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;January 5, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Defacement&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;A report on BBC News said that visitors to Spain's EU presidency website were greeted by an image of comedy character Mr Bean instead of the Spanish Prime Minister Jose Luis Rodriguez Zapatero.  The government said that the site - www.eu2010.es - had not been attacked and that a hacker had taken a screenshot of the homepage to make a photo montage using a cross-site scripting (XSS) vulnerability. Visitors found an image of Mr Bean complete with a benign smile and the words ‘Hi there'.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Government&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;Spain&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://www.scmagazineuk.com/cross-site-scripting-vulnerabilities-see-two-political-websites-hacked/article/160597/&quot;&gt;http://www.scmagazineuk.com/cross-site-scripting-vulnerabilities-see-two-political-websites-hacked/article/160597/&lt;/a></description>      <pubDate>Mon, 24 May 2010 13:54:42 -0400</pubDate>      <ddb:attackedentityfield>Government</ddb:attackedentityfield>      <ddb:attackedentitygeography>Spain</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>January 5, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-8: Cross-site scripting vulnerabilities see two political websites hacked</ddb:entrytitle>      <ddb:incidentdescription>A report on BBC News said that visitors to Spain's EU presidency website were greeted by an image of comedy character Mr Bean instead of the Spanish Prime Minister Jose Luis Rodriguez Zapatero.  The government said that the site - www.eu2010.es - had not been attacked and that a hacker had taken a screenshot of the homepage to make a photo montage using a cross-site scripting (XSS) vulnerability. Visitors found an image of Mr Bean complete with a benign smile and the words ‘Hi there'.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Defacement</ddb:outcome>      <ddb:reference>http://www.scmagazineuk.com/cross-site-scripting-vulnerabilities-see-two-political-websites-hacked/article/160597/</ddb:reference>      <ddb:whidid>2010-8</ddb:whidid>    </item>    <item>      <title>WHID 2010-47: Court papers: JC Penney was hacking victim</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=45354</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-47: Court papers: JC Penney was hacking victim&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-47&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;October 23, 2007&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Credit Card Leakage&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;JC Penney Co. was one of the victims of notorious computer hacker Albert Gonzalez, according to unsealed documents made available on Monday by a federal judge in Boston.&lt;br&gt;Penney, which during Gonzalez' trial had asked the U.S. District Court for the District of Massachusetts to bar the government from disclosing its identity, was revealed in the documents to be the company that had been known throughout the trial as &quot;Company A.&quot;&lt;br&gt;ICQ chat logs confirm SQL Injection was used - http://datalossdb.org/system/jcp_attachment.pdf&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Retail&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://www.msnbc.msn.com/id/36088614/ns/technology_and_science-security/&quot;&gt;http://www.msnbc.msn.com/id/36088614/ns/technology_and_science-security/&lt;/a></description>      <pubDate>Thu, 17 Jun 2010 14:25:23 -0400</pubDate>      <ddb:attackedentityfield>Retail</ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>October 23, 2007</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-47: Court papers: JC Penney was hacking victim</ddb:entrytitle>      <ddb:incidentdescription>JC Penney Co. was one of the victims of notorious computer hacker Albert Gonzalez, according to unsealed documents made available on Monday by a federal judge in Boston.&#13;&#10;&#13;&#10;Penney, which during Gonzalez' trial had asked the U.S. District Court for the District of Massachusetts to bar the government from disclosing its identity, was revealed in the documents to be the company that had been known throughout the trial as &quot;Company A.&quot;&#13;&#10;&#13;&#10;ICQ chat logs confirm SQL Injection was used - http://datalossdb.org/system/jcp_attachment.pdf</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Credit Card Leakage</ddb:outcome>      <ddb:reference>http://www.msnbc.msn.com/id/36088614/ns/technology_and_science-security/</ddb:reference>      <ddb:whidid>2010-47</ddb:whidid>    </item>    <item>      <title>WHID 2010-55: Drudge Report accused of serving malware, again</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=46069</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-55: Drudge Report accused of serving malware, again&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-55&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;March 9, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Planting of Malware&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;For the second time in less than six months, visitors to the Drudge Report say they got malware in addition to the Web site's usual sensational headlines.&lt;br&gt;Matt Drudge denied that his site was infecting visitors, however it's likely that the malware is coming from ads delivered by a third-party ad network and not the site itself.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Media&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://news.cnet.com/8301-27080_3-10466044-245.html&quot;&gt;http://news.cnet.com/8301-27080_3-10466044-245.html&lt;/a></description>      <pubDate>Mon, 24 May 2010 13:54:42 -0400</pubDate>      <ddb:attackedentityfield>Media</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>March 9, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-55: Drudge Report accused of serving malware, again</ddb:entrytitle>      <ddb:incidentdescription>For the second time in less than six months, visitors to the Drudge Report say they got malware in addition to the Web site's usual sensational headlines.&#13;&#10;Matt Drudge denied that his site was infecting visitors, however it's likely that the malware is coming from ads delivered by a third-party ad network and not the site itself.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Planting of Malware</ddb:outcome>      <ddb:reference>http://news.cnet.com/8301-27080_3-10466044-245.html</ddb:reference>      <ddb:whidid>2010-55</ddb:whidid>    </item>    <item>      <title>WHID 2009-48: XSS Embedded iFrames</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=43323</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2009-48: XSS Embedded iFrames&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2009-48&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;December 14, 2009&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Planting of Malware&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;Today we saw a variety of pages being advertised that have search.htm and other pages vulnerable to cross-site scripting (XSS) being used to inject an iframe to a malicious webpage redirector. To an unknowing user following such an advertisement, they would believe that they were just visiting the intended host site unaware that the iframe was also redirecting them to malicious content.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Information Services&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://research.zscaler.com/2009/12/xss-embedded-iframes.html&quot;&gt;http://research.zscaler.com/2009/12/xss-embedded-iframes.html&lt;/a></description>      <pubDate>Wed, 16 Jun 2010 14:12:23 -0400</pubDate>      <ddb:attackedentityfield>Information Services</ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>December 14, 2009</ddb:dateoccured>      <ddb:entrytitle>WHID 2009-48: XSS Embedded iFrames</ddb:entrytitle>      <ddb:incidentdescription>Today we saw a variety of pages being advertised that have search.htm and other pages vulnerable to cross-site scripting (XSS) being used to inject an iframe to a malicious webpage redirector. To an unknowing user following such an advertisement, they would believe that they were just visiting the intended host site unaware that the iframe was also redirecting them to malicious content.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Planting of Malware</ddb:outcome>      <ddb:reference>http://research.zscaler.com/2009/12/xss-embedded-iframes.html</ddb:reference>      <ddb:whidid>2009-48</ddb:whidid>    </item>    <item>      <title>WHID 2010-16: The Game's Email Hacked, Monthly Expenses List Leaked</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=42770</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-16: The Game's Email Hacked, Monthly Expenses List Leaked&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-16&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;March 22, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;Hackers don't discriminate. The biggest targets these days seem to be celebrities. The latest is rapper The Game, whose GMAIL account was reportedly hacked into recently.  According to TheBoomBox.com, the rapper didn't have too many interesting things going on in his email. At least, nothing revealed just yet.  &lt;br&gt;The only thing of interest leaked was a detailed list of his monthly expenses, which total roughly $52,000.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Entertainment&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA&lt;br&gt;&lt;b&gt;Attacked System Technology: &lt;/b&gt;GMail&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://www.ballerstatus.com/2010/03/22/the-games-email-hacked-monthly-expense-list-leaked/&quot;&gt;http://www.ballerstatus.com/2010/03/22/the-games-email-hacked-monthly-expense-list-leaked/&lt;/a></description>      <pubDate>Mon, 24 May 2010 21:14:35 -0400</pubDate>      <ddb:attackedentityfield>Entertainment</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology>GMail</ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>March 22, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-16: The Game's Email Hacked, Monthly Expenses List Leaked</ddb:entrytitle>      <ddb:incidentdescription>Hackers don't discriminate. The biggest targets these days seem to be celebrities. The latest is rapper The Game, whose GMAIL account was reportedly hacked into recently.  According to TheBoomBox.com, the rapper didn't have too many interesting things going on in his email. At least, nothing revealed just yet.  &#13;&#10;The only thing of interest leaked was a detailed list of his monthly expenses, which total roughly $52,000.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference>http://www.ballerstatus.com/2010/03/22/the-games-email-hacked-monthly-expense-list-leaked/</ddb:reference>      <ddb:whidid>2010-16</ddb:whidid>    </item>    <item>      <title>WHID 2010-30: Organized Crooks Hit NJ Town</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=43762</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-30: Organized Crooks Hit NJ Town&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-30&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;March 19, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Monetary Loss&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;The Federal Bureau of Investigation and the Atlantic County Prosecutor's Office are helping Egg Harbor Township police investigate what township police said was an &quot;outside intrusion into a municipal banking account&quot;that was to blame for missing municipal funds.&quot;&lt;br&gt;In a statement, the township police also warned the public that computer criminals have become more sophisticated.&lt;br&gt;&quot;Emails can appear to originate from your bank, or other legitimate location, and when opened can cause great financial damage,&quot; the department wrote. &quot;Use extra care with your email and where you may send/enter any personal information.&quot;&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Finance&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;New Jersey, USA&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://www.pressofatlanticcity.com/news/top_three/article_35e425d8-32f2-11df-a24f-001cc4c03286.html&quot;&gt;http://www.pressofatlanticcity.com/news/top_three/article_35e425d8-32f2-11df-a24f-001cc4c03286.html&lt;/a></description>      <pubDate>Mon, 24 May 2010 13:54:42 -0400</pubDate>      <ddb:attackedentityfield>Finance</ddb:attackedentityfield>      <ddb:attackedentitygeography>New Jersey, USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>March 19, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-30: Organized Crooks Hit NJ Town</ddb:entrytitle>      <ddb:incidentdescription>The Federal Bureau of Investigation and the Atlantic County Prosecutor's Office are helping Egg Harbor Township police investigate what township police said was an &quot;outside intrusion into a municipal banking account&quot;that was to blame for missing municipal funds.&quot;&#13;&#10;&#13;&#10;In a statement, the township police also warned the public that computer criminals have become more sophisticated.&#13;&#10;&quot;Emails can appear to originate from your bank, or other legitimate location, and when opened can cause great financial damage,&quot; the department wrote. &quot;Use extra care with your email and where you may send/enter any personal information."</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Monetary Loss</ddb:outcome>      <ddb:reference>http://www.pressofatlanticcity.com/news/top_three/article_35e425d8-32f2-11df-a24f-001cc4c03286.html</ddb:reference>      <ddb:whidid>2010-30</ddb:whidid>    </item>    <item>      <title>WHID 2010-44: Baidu hacked by Iranian Cyber Army</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=44469</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-44: Baidu hacked by Iranian Cyber Army&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-44&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;January 12, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Downtime&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;The attack, which took place overnight, saw a message from the Iranian Cyber Army appear on the Baidu home page. It featured a picture of the Iranian flag, and a message written in Farsi.&lt;br&gt;Here’s how Baidu alleges the hacker got access to one of the world’s most popular web sites domain name account in under an hour:&lt;br&gt;1. Hacker starts online chat session with Register.com representative, claiming to be an agent of Baidu.&lt;br&gt;2. Register.com representative asks hacker to provide verification information. Hacker provides invalid information, but Register.com goes ahead and e-mails a security code to the email address it has on file for Baidu anyway.&lt;br&gt;3. The hacker doesn’t have access to that e-mail address, so he/she relays a bogus security code to the Register.com representative via chat. Baidu claims the representative didn’t bother to compare the code to the actual one.&lt;br&gt;4. Hacker asks Register.com representative to change email address on file to antiwahabi2008@gmail.com, and representative does.&lt;br&gt;5. Hacker now uses “forgot password” link at Register.com to request the username and password to the account. Hacker can then log in and change the name servers.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;Iran&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Internet&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;China&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://www.telegraph.co.uk/technology/news/6974129/Baidu-hacked-by-Iranian-Cyber-Army.html&quot;&gt;http://www.telegraph.co.uk/technology/news/6974129/Baidu-hacked-by-Iranian-Cyber-Army.html&lt;/a></description>      <pubDate>Mon, 24 May 2010 13:54:42 -0400</pubDate>      <ddb:attackedentityfield>Internet</ddb:attackedentityfield>      <ddb:attackedentitygeography>China</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography>Iran</ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>January 12, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-44: Baidu hacked by Iranian Cyber Army</ddb:entrytitle>      <ddb:incidentdescription>The attack, which took place overnight, saw a message from the Iranian Cyber Army appear on the Baidu home page. It featured a picture of the Iranian flag, and a message written in Farsi.&#13;&#10;&#13;&#10;Here’s how Baidu alleges the hacker got access to one of the world’s most popular web sites domain name account in under an hour:&#13;&#10;1. Hacker starts online chat session with Register.com representative, claiming to be an agent of Baidu.&#13;&#10;2. Register.com representative asks hacker to provide verification information. Hacker provides invalid information, but Register.com goes ahead and e-mails a security code to the email address it has on file for Baidu anyway.&#13;&#10;3. The hacker doesn’t have access to that e-mail address, so he/she relays a bogus security code to the Register.com representative via chat. Baidu claims the representative didn’t bother to compare the code to the actual one.&#13;&#10;4. Hacker asks Register.com representative to change email address on file to antiwahabi2008@gmail.com, and representative does.&#13;&#10;5. Hacker now uses “forgot password” link at Register.com to request the username and password to the account. Hacker can then log in and change the name servers.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Downtime</ddb:outcome>      <ddb:reference>http://www.telegraph.co.uk/technology/news/6974129/Baidu-hacked-by-Iranian-Cyber-Army.html</ddb:reference>      <ddb:whidid>2010-44</ddb:whidid>    </item>    <item>      <title>WHID 2010-6: Cyber hacker hits Paula Dockery's campaign site</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=42164</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-6: Cyber hacker hits Paula Dockery's campaign site&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-6&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;January 20, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Downtime&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;Attacker(s) conducted a DDoS attack against the Florida Candidate for Governor Paula Dockery's website.  In essence, what is happening is someone is sending approximately 40,000 requests per second to the website/server, then immediately closing them… It is the equivalent of 2.4 million people a minute browsing to the site and closing it immediately.  In essence this saturates the number of connections available to legitimate people trying to get to the server, causing them to time-out when they visit the site.  In security terms it is called a Denial of Service Attack (DoS). &lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Government&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;Florida, USA&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://blogs.tampabay.com/buzz/2010/01/cyber-hacker-hits-paula-dockerys-campaign-site.html&quot;&gt;http://blogs.tampabay.com/buzz/2010/01/cyber-hacker-hits-paula-dockerys-campaign-site.html&lt;/a></description>      <pubDate>Mon, 24 May 2010 13:54:42 -0400</pubDate>      <ddb:attackedentityfield>Government</ddb:attackedentityfield>      <ddb:attackedentitygeography>Florida, USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>January 20, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-6: Cyber hacker hits Paula Dockery's campaign site</ddb:entrytitle>      <ddb:incidentdescription>Attacker(s) conducted a DDoS attack against the Florida Candidate for Governor Paula Dockery's website.  In essence, what is happening is someone is sending approximately 40,000 requests per second to the website/server, then immediately closing them… It is the equivalent of 2.4 million people a minute browsing to the site and closing it immediately.  In essence this saturates the number of connections available to legitimate people trying to get to the server, causing them to time-out when they visit the site.  In security terms it is called a Denial of Service Attack (DoS). </ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Downtime</ddb:outcome>      <ddb:reference>http://blogs.tampabay.com/buzz/2010/01/cyber-hacker-hits-paula-dockerys-campaign-site.html</ddb:reference>      <ddb:whidid>2010-6</ddb:whidid>    </item>    <item>      <title>WHID 2010-2: Hacker Disables More Than 100 Cars Remotely</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=41892</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-2: Hacker Disables More Than 100 Cars Remotely&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-2&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;March 17, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Data Loss&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;Hundreds of cars would not start and/or had their horn honking when a former employee at Texas Auto Center used previous passwords to log into a system called Webtech Plus whic is used as an alternative to repossessing vehicles that haven’t been paid for.  Operated by Cleveland-based Pay Technologies, the system lets car dealers install a small black box under vehicle dashboards that responds to commands issued through a central website, and relayed over a wireless pager network. The dealer can disable a car’s ignition system, or trigger the horn to begin honking, as a reminder that a payment is due.  The hacker destroyed account records and then started to disable cars/force the horn to honk continuously.&lt;br&gt;Read More http://www.wired.com/threatlevel/2010/03/hacker-bricks-cars/#ixzz0iYvPwUVj&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;Texas, USA&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Automotive&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;Austin TX, USA&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://www.wired.com/threatlevel/2010/03/hacker-bricks-cars/&quot;&gt;http://www.wired.com/threatlevel/2010/03/hacker-bricks-cars/&lt;/a></description>      <pubDate>Mon, 24 May 2010 13:54:42 -0400</pubDate>      <ddb:attackedentityfield>Automotive</ddb:attackedentityfield>      <ddb:attackedentitygeography>Austin TX, USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography>Texas, USA</ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>March 17, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-2: Hacker Disables More Than 100 Cars Remotely</ddb:entrytitle>      <ddb:incidentdescription>Hundreds of cars would not start and/or had their horn honking when a former employee at Texas Auto Center used previous passwords to log into a system called Webtech Plus whic is used as an alternative to repossessing vehicles that haven’t been paid for.  Operated by Cleveland-based Pay Technologies, the system lets car dealers install a small black box under vehicle dashboards that responds to commands issued through a central website, and relayed over a wireless pager network. The dealer can disable a car’s ignition system, or trigger the horn to begin honking, as a reminder that a payment is due.  The hacker destroyed account records and then started to disable cars/force the horn to honk continuously.&#13;&#10;&#13;&#10;Read More http://www.wired.com/threatlevel/2010/03/hacker-bricks-cars/#ixzz0iYvPwUVj</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Data Loss</ddb:outcome>      <ddb:reference>http://www.wired.com/threatlevel/2010/03/hacker-bricks-cars/</ddb:reference>      <ddb:whidid>2010-2</ddb:whidid>    </item>    <item>      <title>WHID 2010-40: TCS Website Hacked, Domain Name Up For Sale</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=44190</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-40: TCS Website Hacked, Domain Name Up For Sale&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-40&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;February 8, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Defacement&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;Indian software giant Tata Consultancy Services Ltd. (TCS) has witnessed the hijacking of its official website www.tcs.com. The hackers not only attacked the website but also allegedly changed its domain name and put it up for sale!&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Technology&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;India&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://www.techtree.com/India/News/TCS_Website_Hacked_Domain_Name_Up_For_Sale/551-109190-643.html&quot;&gt;http://www.techtree.com/India/News/TCS_Website_Hacked_Domain_Name_Up_For_Sale/551-109190-643.html&lt;/a></description>      <pubDate>Mon, 24 May 2010 13:54:42 -0400</pubDate>      <ddb:attackedentityfield>Technology</ddb:attackedentityfield>      <ddb:attackedentitygeography>India</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>February 8, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-40: TCS Website Hacked, Domain Name Up For Sale</ddb:entrytitle>      <ddb:incidentdescription>Indian software giant Tata Consultancy Services Ltd. (TCS) has witnessed the hijacking of its official website www.tcs.com. The hackers not only attacked the website but also allegedly changed its domain name and put it up for sale!</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Defacement</ddb:outcome>      <ddb:reference>http://www.techtree.com/India/News/TCS_Website_Hacked_Domain_Name_Up_For_Sale/551-109190-643.html</ddb:reference>      <ddb:whidid>2010-40</ddb:whidid>    </item>    <item>      <title>WHID 2010-34: Over 120 000 Sanoma User Credentials Stolen</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=43945</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-34: Over 120 000 Sanoma User Credentials Stolen&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-34&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;March 23, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;Not exactly a startup news per se, but a healthy reminder to all those working with user credentials in their online services. One of the largest, if not the largest, online identity thefts has just occured in Finland. The service to be breached was Älypää, a Sanoma bought gaming site. The sad part is that while an identity breach of this magnitude is always bad – this has been made worse by Sanoma actually storing the passwords in plain text, making them usable anywhere.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Entertainment&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;Finland&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://www.arcticstartup.com/2010/03/23/over-120-000-sanoma-user-credentials-stolen/?ref=rc&quot;&gt;http://www.arcticstartup.com/2010/03/23/over-120-000-sanoma-user-credentials-stolen/?ref=rc&lt;/a></description>      <pubDate>Mon, 24 May 2010 13:54:42 -0400</pubDate>      <ddb:attackedentityfield>Entertainment</ddb:attackedentityfield>      <ddb:attackedentitygeography>Finland</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>March 23, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-34: Over 120 000 Sanoma User Credentials Stolen</ddb:entrytitle>      <ddb:incidentdescription>Not exactly a startup news per se, but a healthy reminder to all those working with user credentials in their online services. One of the largest, if not the largest, online identity thefts has just occured in Finland. The service to be breached was Älypää, a Sanoma bought gaming site. The sad part is that while an identity breach of this magnitude is always bad – this has been made worse by Sanoma actually storing the passwords in plain text, making them usable anywhere.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference>http://www.arcticstartup.com/2010/03/23/over-120-000-sanoma-user-credentials-stolen/?ref=rc</ddb:reference>      <ddb:whidid>2010-34</ddb:whidid>    </item>    <item>      <title>WHID 2010-17: Govt websites hacked</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=42803</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-17: Govt websites hacked&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-17&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;March 20, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Defacement&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;Bangladesh government websites, operating out of the Prime Minister's Office, were attacked on Saturday by hackers purporting to be &quot;Indian&quot; .&lt;br&gt;bdnews24.com, at around 2.30am, found that 19 out of 64 district web portals had been hacked by &quot;MIL INDIAN HACKER&quot;, threatening &quot;cyber war&quot; in retaliation to any terrorist attack by Pakistan on Indian soil &quot;via Bangladesh&quot;.&lt;br&gt;Most of the sites were fixed around 16 hours later, said officials, who in some cases had first been notified of the cyber attack by bdnews24.com's online report.&lt;br&gt;The hacked portals displayed a poster on opening, which said: 28 DIFFERENT STATES, 28 DIFFERENT LANGUAGES BUT ONE WORD JAI HIND!' &lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;India&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Government&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;Bangladesh, India&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://bdnews24.com/details.php?id=156315&amp;cid=2&quot;&gt;http://bdnews24.com/details.php?id=156315&amp;cid=2&lt;/a></description>      <pubDate>Mon, 24 May 2010 21:13:33 -0400</pubDate>      <ddb:attackedentityfield>Government</ddb:attackedentityfield>      <ddb:attackedentitygeography>Bangladesh, India</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography>India</ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>March 20, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-17: Govt websites hacked</ddb:entrytitle>      <ddb:incidentdescription>Bangladesh government websites, operating out of the Prime Minister's Office, were attacked on Saturday by hackers purporting to be &quot;Indian&quot; .&#13;&#10;&#13;&#10;bdnews24.com, at around 2.30am, found that 19 out of 64 district web portals had been hacked by &quot;MIL INDIAN HACKER&quot;, threatening &quot;cyber war&quot; in retaliation to any terrorist attack by Pakistan on Indian soil &quot;via Bangladesh&quot;.&#13;&#10;&#13;&#10;Most of the sites were fixed around 16 hours later, said officials, who in some cases had first been notified of the cyber attack by bdnews24.com's online report.&#13;&#10;&#13;&#10;The hacked portals displayed a poster on opening, which said: 28 DIFFERENT STATES, 28 DIFFERENT LANGUAGES BUT ONE WORD JAI HIND!' </ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Defacement</ddb:outcome>      <ddb:reference>http://bdnews24.com/details.php?id=156315&amp;cid=2</ddb:reference>      <ddb:whidid>2010-17</ddb:whidid>    </item>    <item>      <title>WHID 2010-29: Conservatives embarrassed as hackers exploit loophole on anti-union website</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=43729</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-29: Conservatives embarrassed as hackers exploit loophole on anti-union website&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-29&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;March 23, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Defacement&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;It was hoped that visitors to the website - http://cash-gordon.com – would use popular social networking websites such as Twitter and Facebook to spread the word about Gordon Brown’s union links.&lt;br&gt;One of its features displayed any message posted on Twitter if it included the term “#cashgordon”, no matter what else it said.&lt;br&gt;By writing Twitter messages containing the “#cashgordon” and their own piece of web code, they were able to redirect visitors to any other site on the internet.&lt;br&gt;Anyone who tried to access the Cash Gordon website for more than an hour was sent elsewhere, such as to the Labour Party’s site or to hardcore pornography pages.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Politics&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;United Kingdom&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://www.telegraph.co.uk/technology/twitter/7499228/Conservatives-embarrassed-as-hackers-exploit-loophole-on-anti-union-website.html&quot;&gt;http://www.telegraph.co.uk/technology/twitter/7499228/Conservatives-embarrassed-as-hackers-exploit-loophole-on-anti-union-website.html&lt;/a></description>      <pubDate>Mon, 24 May 2010 13:54:42 -0400</pubDate>      <ddb:attackedentityfield>Politics</ddb:attackedentityfield>      <ddb:attackedentitygeography>United Kingdom</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>March 23, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-29: Conservatives embarrassed as hackers exploit loophole on anti-union website</ddb:entrytitle>      <ddb:incidentdescription>It was hoped that visitors to the website - http://cash-gordon.com – would use popular social networking websites such as Twitter and Facebook to spread the word about Gordon Brown’s union links.&#13;&#10;One of its features displayed any message posted on Twitter if it included the term “#cashgordon”, no matter what else it said.&#13;&#10;By writing Twitter messages containing the “#cashgordon” and their own piece of web code, they were able to redirect visitors to any other site on the internet.&#13;&#10;Anyone who tried to access the Cash Gordon website for more than an hour was sent elsewhere, such as to the Labour Party’s site or to hardcore pornography pages.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Defacement</ddb:outcome>      <ddb:reference>http://www.telegraph.co.uk/technology/twitter/7499228/Conservatives-embarrassed-as-hackers-exploit-loophole-on-anti-union-website.html</ddb:reference>      <ddb:whidid>2010-29</ddb:whidid>    </item>    <item>      <title>WHID 2010-9: Pakistani cyber crime website hit by hacker who is able to access database</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=42289</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-9: Pakistani cyber crime website hit by hacker who is able to access database&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-9&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;January 11, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Defacement&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;Details of a political website, the Pakistani National Response Center for Cyber Crimes, part of the Federal Investigation Authority, being hacked has been reported when a sensitive site was hit by a hacker who managed to gain access to the email database.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Government&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;Pakistan&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://www.scmagazineuk.com/pakistani-cyber-crime-website-hit-by-hacker-who-is-able-to-access-database/article/160969/&quot;&gt;http://www.scmagazineuk.com/pakistani-cyber-crime-website-hit-by-hacker-who-is-able-to-access-database/article/160969/&lt;/a></description>      <pubDate>Mon, 24 May 2010 13:54:42 -0400</pubDate>      <ddb:attackedentityfield>Government</ddb:attackedentityfield>      <ddb:attackedentitygeography>Pakistan</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>January 11, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-9: Pakistani cyber crime website hit by hacker who is able to access database</ddb:entrytitle>      <ddb:incidentdescription>Details of a political website, the Pakistani National Response Center for Cyber Crimes, part of the Federal Investigation Authority, being hacked has been reported when a sensitive site was hit by a hacker who managed to gain access to the email database.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Defacement</ddb:outcome>      <ddb:reference>http://www.scmagazineuk.com/pakistani-cyber-crime-website-hit-by-hacker-who-is-able-to-access-database/article/160969/</ddb:reference>      <ddb:whidid>2010-9</ddb:whidid>    </item>    <item>      <title>WHID 2010-25: Flawed Security Exposes Vital Software to Hackers</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=37976</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-25: Flawed Security Exposes Vital Software to Hackers&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-25&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;March 5, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;McAfee, a leading maker of Internet security software, warned this week that software systems used by many companies to store and manage their intellectual property are being actively targeted by hackers and are in need of significantly increased security focus.&lt;br&gt;McAfee took issue with Perforce’s implementation of access controls. For instance, using the Web interface, someone who manages to access one user account could access those of other users by manipulating the associated URL, or Web address, it said. Perforce responded that, if customers choose the systems most restrictive mode, that situation isn’t possible.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Technology&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://bits.blogs.nytimes.com/2010/03/05/flawed-security-exposes-vital-software-to-hackers/&quot;&gt;http://bits.blogs.nytimes.com/2010/03/05/flawed-security-exposes-vital-software-to-hackers/&lt;/a></description>      <pubDate>Mon, 24 May 2010 13:54:42 -0400</pubDate>      <ddb:attackedentityfield>Technology</ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>March 5, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-25: Flawed Security Exposes Vital Software to Hackers</ddb:entrytitle>      <ddb:incidentdescription>McAfee, a leading maker of Internet security software, warned this week that software systems used by many companies to store and manage their intellectual property are being actively targeted by hackers and are in need of significantly increased security focus.&#13;&#10;&#13;&#10;McAfee took issue with Perforce’s implementation of access controls. For instance, using the Web interface, someone who manages to access one user account could access those of other users by manipulating the associated URL, or Web address, it said. Perforce responded that, if customers choose the systems most restrictive mode, that situation isn’t possible.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference>http://bits.blogs.nytimes.com/2010/03/05/flawed-security-exposes-vital-software-to-hackers/</ddb:reference>      <ddb:whidid>2010-25</ddb:whidid>    </item>    <item>      <title>WHID 2010-3: Feds Crack Hackers' Stock Manipulation Cybercrime</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=37975</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-3: Feds Crack Hackers' Stock Manipulation Cybercrime&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-3&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;March 16, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Monetary Loss&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;Hackers, working for BroCo Investments (a one-trader operation based in St. Petersburg, Russia) used stolen online brokerage credentials to initiate a pump-and-dump scheme.  Within minutes of making the unauthorized transactions, the SEC claims BroCo then sold shares of these same stocks held in its own account at the artificially inflated prices, netting the hackers more than $250,000 in profits.&lt;br&gt;From a defensive perspective, the online brokerage accounts should be doing more to authenticate users and validate transactions.  The challenging part is that these types of defensive mechanisms may actually interfere with many of the automated bot programs that investors use to monitor and execute trades.  Online trading fraud is not going to go away anytime soon.&lt;br&gt;Read More on SEC filing - http://www.wired.com/images_blogs/threatlevel/2010/03/brocosec.pdf&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;St. Petersburg, Russia&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Finance&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Cost: &lt;/b&gt;$600,000.00&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://www.esecurityplanet.com/news/article.php/3871176/Feds-Crack-Hackers-Stock-Manipulation-Cybercrime.htm&quot;&gt;http://www.esecurityplanet.com/news/article.php/3871176/Feds-Crack-Hackers-Stock-Manipulation-Cybercrime.htm&lt;/a></description>      <pubDate>Mon, 24 May 2010 13:54:42 -0400</pubDate>      <ddb:attackedentityfield>Finance</ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography>St. Petersburg, Russia</ddb:attacksourcegeography>      <ddb:cost>$600,000.00</ddb:cost>      <ddb:dateoccured>March 16, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-3: Feds Crack Hackers' Stock Manipulation Cybercrime</ddb:entrytitle>      <ddb:incidentdescription>Hackers, working for BroCo Investments (a one-trader operation based in St. Petersburg, Russia) used stolen online brokerage credentials to initiate a pump-and-dump scheme.  Within minutes of making the unauthorized transactions, the SEC claims BroCo then sold shares of these same stocks held in its own account at the artificially inflated prices, netting the hackers more than $250,000 in profits.&#13;&#10;&#13;&#10;From a defensive perspective, the online brokerage accounts should be doing more to authenticate users and validate transactions.  The challenging part is that these types of defensive mechanisms may actually interfere with many of the automated bot programs that investors use to monitor and execute trades.  Online trading fraud is not going to go away anytime soon.&#13;&#10;&#13;&#10;Read More on SEC filing - http://www.wired.com/images_blogs/threatlevel/2010/03/brocosec.pdf</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Monetary Loss</ddb:outcome>      <ddb:reference>http://www.esecurityplanet.com/news/article.php/3871176/Feds-Crack-Hackers-Stock-Manipulation-Cybercrime.htm</ddb:reference>      <ddb:whidid>2010-3</ddb:whidid>    </item>    <item>      <title>WHID 2010-49: Hackers pluck 8,300 customer logins from bank server</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=45476</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-49: Hackers pluck 8,300 customer logins from bank server&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-49&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;January 12, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;Hackers have stolen the login credentials for more than 8,300 customers of small New York bank after breaching its security and accessing a server that hosted its online banking system.&lt;br&gt;The intrusion at Suffolk County National Bank happened over a six-day period that started on November 18, according to a release (PDF) issued Monday. It was discovered on December 24 during an internal security review. In all, credentials for 8,378 online accounts were pilfered, a number that represents less than 10 percent of SCNB's total customer base.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Finance&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;NY, USA&lt;br&gt;&lt;b&gt;Number of Records: &lt;/b&gt;8,300&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://www.theregister.co.uk/2010/01/12/bank_server_breached/&quot;&gt;http://www.theregister.co.uk/2010/01/12/bank_server_breached/&lt;/a></description>      <pubDate>Mon, 24 May 2010 13:54:42 -0400</pubDate>      <ddb:attackedentityfield>Finance</ddb:attackedentityfield>      <ddb:attackedentitygeography>NY, USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>January 12, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-49: Hackers pluck 8,300 customer logins from bank server</ddb:entrytitle>      <ddb:incidentdescription>Hackers have stolen the login credentials for more than 8,300 customers of small New York bank after breaching its security and accessing a server that hosted its online banking system.&#13;&#10;&#13;&#10;The intrusion at Suffolk County National Bank happened over a six-day period that started on November 18, according to a release (PDF) issued Monday. It was discovered on December 24 during an internal security review. In all, credentials for 8,378 online accounts were pilfered, a number that represents less than 10 percent of SCNB's total customer base.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords>8,300</ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference>http://www.theregister.co.uk/2010/01/12/bank_server_breached/</ddb:reference>      <ddb:whidid>2010-49</ddb:whidid>    </item>    <item>      <title>WHID 2010-41: NineMSN compromised</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=44261</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-41: NineMSN compromised&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-41&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;February 17, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Planting of Malware&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;Microsoft's Ninemsn, one of the most visited portals in Australia (Alexa rank 573), was compromised and injected with malicious code. The malicious code was identified to be part of the Gumblar mass injections.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Internet&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;Australia&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://www.itwire.com/business-it-news/security/36912-ninemsn-compromised&quot;&gt;http://www.itwire.com/business-it-news/security/36912-ninemsn-compromised&lt;/a></description>      <pubDate>Mon, 24 May 2010 13:54:42 -0400</pubDate>      <ddb:attackedentityfield>Internet</ddb:attackedentityfield>      <ddb:attackedentitygeography>Australia</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>February 17, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-41: NineMSN compromised</ddb:entrytitle>      <ddb:incidentdescription>Microsoft's Ninemsn, one of the most visited portals in Australia (Alexa rank 573), was compromised and injected with malicious code. The malicious code was identified to be part of the Gumblar mass injections.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Planting of Malware</ddb:outcome>      <ddb:reference>http://www.itwire.com/business-it-news/security/36912-ninemsn-compromised</ddb:reference>      <ddb:whidid>2010-41</ddb:whidid>    </item>    <item>      <title>WHID 2010-35: CISO Witnesses Hack Like No Other</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=43978</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-35: CISO Witnesses Hack Like No Other&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-35&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;March 3, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Loss of Sales&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;Here's what Maley told attendees to an RSA Conference panel on state cybersecurity on Wednesday:&lt;br&gt;&quot;We saw thousands of hits on our Department of Transportation driver license exam scheduling site coming out of Russia, the same thing over and over, scheduling driver license exams. It was encrypted traffic, and we were trying to figure out what the heck is going on. Were they trying to test our systems? What exactly were they up to? The answer was, we really didn't know.&quot;&lt;br&gt;Authorities eventually discovered that the hacker who used a proxy server in Russia to mask his identity owned a driving school in Philadelphia, and exploited a vulnerability in the driving test scheduling system to allow the scheduling of more tests than the allotted time slots. It could take upward of six weeks to schedule a driving test in Philadelphia. Said Maley:&lt;br&gt;&quot;What he was doing was saying (to potential customers), &quot;You go over across the street, to John's driver training, and it's going to take you six to eight weeks to get your test. We can get you in tomorrow.&quot;&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;PA, USA&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Government&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;PA, USA&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://blogs.bankinfosecurity.com/posts.php?postID=469&quot;&gt;http://blogs.bankinfosecurity.com/posts.php?postID=469&lt;/a></description>      <pubDate>Mon, 24 May 2010 13:54:42 -0400</pubDate>      <ddb:attackedentityfield>Government</ddb:attackedentityfield>      <ddb:attackedentitygeography>PA, USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography>PA, USA</ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>March 3, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-35: CISO Witnesses Hack Like No Other</ddb:entrytitle>      <ddb:incidentdescription>Here's what Maley told attendees to an RSA Conference panel on state cybersecurity on Wednesday:&#13;&#10;&#13;&#10;&quot;We saw thousands of hits on our Department of Transportation driver license exam scheduling site coming out of Russia, the same thing over and over, scheduling driver license exams. It was encrypted traffic, and we were trying to figure out what the heck is going on. Were they trying to test our systems? What exactly were they up to? The answer was, we really didn't know.&quot;&#13;&#10;Authorities eventually discovered that the hacker who used a proxy server in Russia to mask his identity owned a driving school in Philadelphia, and exploited a vulnerability in the driving test scheduling system to allow the scheduling of more tests than the allotted time slots. It could take upward of six weeks to schedule a driving test in Philadelphia. Said Maley:&#13;&#10;&#13;&#10;&quot;What he was doing was saying (to potential customers), &quot;You go over across the street, to John's driver training, and it's going to take you six to eight weeks to get your test. We can get you in tomorrow."</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Loss of Sales</ddb:outcome>      <ddb:reference>http://blogs.bankinfosecurity.com/posts.php?postID=469</ddb:reference>      <ddb:whidid>2010-35</ddb:whidid>    </item>    <item>      <title>WHID 2010-13: Australian Government websites blitzed by DDoS attack</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=42571</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-13: Australian Government websites blitzed by DDoS attack&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-13&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;February 10, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Downtime&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;The websites of Senator Stephen Conroy and the Australian Parliament House were inaccessible this morning after the 'Anonymous' group of hackers claimed credit for a Distributed Denial of Service (DDoS) attack on Australian Government web sites.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Politics&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;Australia&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://www.securecomputing.net.au/News/166860,australian-government-websites-blitzed-by-ddos-attack.aspx&quot;&gt;http://www.securecomputing.net.au/News/166860,australian-government-websites-blitzed-by-ddos-attack.aspx&lt;/a></description>      <pubDate>Mon, 24 May 2010 13:54:42 -0400</pubDate>      <ddb:attackedentityfield>Politics</ddb:attackedentityfield>      <ddb:attackedentitygeography>Australia</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>February 10, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-13: Australian Government websites blitzed by DDoS attack</ddb:entrytitle>      <ddb:incidentdescription>The websites of Senator Stephen Conroy and the Australian Parliament House were inaccessible this morning after the 'Anonymous' group of hackers claimed credit for a Distributed Denial of Service (DDoS) attack on Australian Government web sites.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Downtime</ddb:outcome>      <ddb:reference>http://www.securecomputing.net.au/News/166860,australian-government-websites-blitzed-by-ddos-attack.aspx</ddb:reference>      <ddb:whidid>2010-13</ddb:whidid>    </item>    <item>      <title>WHID 2010-5: City of Albertville's web site hacked</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=42130</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-5: City of Albertville's web site hacked&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-5&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;March 18, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Defacement&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;The website of the Mayor of Albertsville, AL was defaced with profanity.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;Alabama, USA&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Politics&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;Alabama, USA&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://www.waff.com/Global/story.asp?S=12166330&quot;&gt;http://www.waff.com/Global/story.asp?S=12166330&lt;/a></description>      <pubDate>Mon, 24 May 2010 13:54:42 -0400</pubDate>      <ddb:attackedentityfield>Politics</ddb:attackedentityfield>      <ddb:attackedentitygeography>Alabama, USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography>Alabama, USA</ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>March 18, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-5: City of Albertville's web site hacked</ddb:entrytitle>      <ddb:incidentdescription>The website of the Mayor of Albertsville, AL was defaced with profanity.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Defacement</ddb:outcome>      <ddb:reference>http://www.waff.com/Global/story.asp?S=12166330</ddb:reference>      <ddb:whidid>2010-5</ddb:whidid>    </item>    <item>      <title>WHID 2009-50: Iranian hacker attack: What will it cost Twitter?</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=43473</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2009-50: Iranian hacker attack: What will it cost Twitter?&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2009-50&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;December 17, 2009&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Defacement&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;A new attack by hackers Dec. 17 redirected Twitter users to a page from a previously unknown group called the Iranian Cyber Army.  Most computer attacks are relatively straightforward denial-of-service attacks, where computers overwhelm a website with data to bring it down. Thursday night's attack against Twitter was more serious because the hackers gained access to part of Twitter's network and were able to redirect users to a page with a photo of a flag with Farsi script. Near the top of the page ran a bold red headline in English: &quot;This site has been hacked by Iranian Cyber Army.&quot;&lt;br&gt;Hackers for several days have attacked the websites of opponents of Iran's regime and posted the same image. The opponents have used social-media sites like Twitter to organize street protests this year. &lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;Iran&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Web 2.0&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://www.csmonitor.com/Money/2009/1218/Iranian-hacker-attack-What-will-it-cost-Twitter&quot;&gt;http://www.csmonitor.com/Money/2009/1218/Iranian-hacker-attack-What-will-it-cost-Twitter&lt;/a></description>      <pubDate>Wed, 16 Jun 2010 14:12:13 -0400</pubDate>      <ddb:attackedentityfield>Web 2.0</ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography>Iran</ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>December 17, 2009</ddb:dateoccured>      <ddb:entrytitle>WHID 2009-50: Iranian hacker attack: What will it cost Twitter?</ddb:entrytitle>      <ddb:incidentdescription>A new attack by hackers Dec. 17 redirected Twitter users to a page from a previously unknown group called the Iranian Cyber Army.  Most computer attacks are relatively straightforward denial-of-service attacks, where computers overwhelm a website with data to bring it down. Thursday night's attack against Twitter was more serious because the hackers gained access to part of Twitter's network and were able to redirect users to a page with a photo of a flag with Farsi script. Near the top of the page ran a bold red headline in English: &quot;This site has been hacked by Iranian Cyber Army.&quot;&#13;&#10;&#13;&#10;Hackers for several days have attacked the websites of opponents of Iran's regime and posted the same image. The opponents have used social-media sites like Twitter to organize street protests this year. </ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Defacement</ddb:outcome>      <ddb:reference>http://www.csmonitor.com/Money/2009/1218/Iranian-hacker-attack-What-will-it-cost-Twitter</ddb:reference>      <ddb:whidid>2009-50</ddb:whidid>    </item>    <item>      <title>WHID 2010-23: Beware: Malware Attacks Facebook, B-Ball &amp; Gossip Sites</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=43010</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-23: Beware: Malware Attacks Facebook, B-Ball &amp; Gossip Sites&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-23&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;March 19, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Planting of Malware&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;At a time when college basketball fans are going wild, cybercriminals are actively pursuing opportunities for scams. Basketball fans go online to fill out bracket selections, and when they do, hackers are also playing their own game of spamdexing, i.e. manipulating search results to promote sites, according to James Duldulao, a security researcher at McAfee. In this case, he explained, cybercriminals are spamdexing malware-infected sites.&lt;br&gt;This week, the top results for terms like &quot;ncaa bracket&quot; and &quot;march madness predictions&quot; were poisoned. McAfee reports that five out of the first 10 hot searches on Google Trends are being promoted by a network Relevant Products/Services of legitimate sites that were hacked to serve malware. One site had an embedded Flash file that downloads malware from another site and installs it without user interaction Relevant Products/Services. &lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Information Services&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://www.toptechnews.com/story.xhtml?story_id=11000CA733W8&amp;full_skip=1&quot;&gt;http://www.toptechnews.com/story.xhtml?story_id=11000CA733W8&amp;full_skip=1&lt;/a></description>      <pubDate>Mon, 24 May 2010 13:54:42 -0400</pubDate>      <ddb:attackedentityfield>Information Services</ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>March 19, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-23: Beware: Malware Attacks Facebook, B-Ball &amp; Gossip Sites</ddb:entrytitle>      <ddb:incidentdescription>At a time when college basketball fans are going wild, cybercriminals are actively pursuing opportunities for scams. Basketball fans go online to fill out bracket selections, and when they do, hackers are also playing their own game of spamdexing, i.e. manipulating search results to promote sites, according to James Duldulao, a security researcher at McAfee. In this case, he explained, cybercriminals are spamdexing malware-infected sites.&#13;&#10;&#13;&#10;This week, the top results for terms like &quot;ncaa bracket&quot; and &quot;march madness predictions&quot; were poisoned. McAfee reports that five out of the first 10 hot searches on Google Trends are being promoted by a network Relevant Products/Services of legitimate sites that were hacked to serve malware. One site had an embedded Flash file that downloads malware from another site and installs it without user interaction Relevant Products/Services. </ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Planting of Malware</ddb:outcome>      <ddb:reference>http://www.toptechnews.com/story.xhtml?story_id=11000CA733W8&amp;full_skip=1</ddb:reference>      <ddb:whidid>2010-23</ddb:whidid>    </item>    <item>      <title>WHID 2010-18: Hackers crash Aussie charity websites</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=42836</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-18: Hackers crash Aussie charity websites&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-18&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;March 22, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Downtime&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt; The internet services of two Australian autism support organisations have been crashed by computer hackers and a third may also have fallen victim, raising fears of a targeted attack to coincide with autism month.&lt;br&gt;Austism Spectrum Australia (ASPECT), the country's autism service provider, is losing hundreds of dollars in online donations each day after its website was hit by hackers early on Sunday.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;USA&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Health&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;Australia&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://www.stuff.co.nz/technology/3486923/Hackers-crash-Aussie-charity-websites&quot;&gt;http://www.stuff.co.nz/technology/3486923/Hackers-crash-Aussie-charity-websites&lt;/a></description>      <pubDate>Mon, 24 May 2010 21:13:07 -0400</pubDate>      <ddb:attackedentityfield>Health</ddb:attackedentityfield>      <ddb:attackedentitygeography>Australia</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography>USA</ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>March 22, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-18: Hackers crash Aussie charity websites</ddb:entrytitle>      <ddb:incidentdescription> The internet services of two Australian autism support organisations have been crashed by computer hackers and a third may also have fallen victim, raising fears of a targeted attack to coincide with autism month.&#13;&#10;&#13;&#10;Austism Spectrum Australia (ASPECT), the country's autism service provider, is losing hundreds of dollars in online donations each day after its website was hit by hackers early on Sunday.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Downtime</ddb:outcome>      <ddb:reference>http://www.stuff.co.nz/technology/3486923/Hackers-crash-Aussie-charity-websites</ddb:reference>      <ddb:whidid>2010-18</ddb:whidid>    </item>    <item>      <title>WHID 2010-39: Tesda Website hacked again; users directed to Smartmatic</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=44145</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-39: Tesda Website hacked again; users directed to Smartmatic&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-39&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;January 11, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Defacement&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;Even before its administrators could fix the problem, the website of the Technical Education and Skills Development Authority was hacked again early Monday, this time redirecting visitors to the website of Smartmatic, the contractor tasked to implement the automated elections this May.  A check of the hacked TESDA website's homepage showed the hackers left instructions for the site to redirect to Smartmatic's website in 20 seconds.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Government&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;Phillipines&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://www.gmanews.tv/story/181244/tesda-website-hacked-again-users-redirected-to-smartmatic&quot;&gt;http://www.gmanews.tv/story/181244/tesda-website-hacked-again-users-redirected-to-smartmatic&lt;/a></description>      <pubDate>Mon, 24 May 2010 21:10:45 -0400</pubDate>      <ddb:attackedentityfield>Government</ddb:attackedentityfield>      <ddb:attackedentitygeography>Phillipines</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>January 11, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-39: Tesda Website hacked again; users directed to Smartmatic</ddb:entrytitle>      <ddb:incidentdescription>Even before its administrators could fix the problem, the website of the Technical Education and Skills Development Authority was hacked again early Monday, this time redirecting visitors to the website of Smartmatic, the contractor tasked to implement the automated elections this May.  A check of the hacked TESDA website's homepage showed the hackers left instructions for the site to redirect to Smartmatic's website in 20 seconds.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Defacement</ddb:outcome>      <ddb:reference>http://www.gmanews.tv/story/181244/tesda-website-hacked-again-users-redirected-to-smartmatic</ddb:reference>      <ddb:whidid>2010-39</ddb:whidid>    </item>    <item>      <title>WHID 2010-48: Hackers brute force their way into galeton.com website containing names, credit card numbers</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=45426</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-48: Hackers brute force their way into galeton.com website containing names, credit card numbers&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-48&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;February 8, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Credit Card Leakage&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;Hackers used brute force to log into web accounts of users at www.galeton.com.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Retail&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://datalossdb.org/incidents/2692-hackers-brute-force-their-way-into-website-containing-names-credit-card-numbers&quot;&gt;http://datalossdb.org/incidents/2692-hackers-brute-force-their-way-into-website-containing-names-credit-card-numbers&lt;/a></description>      <pubDate>Thu, 17 Jun 2010 14:25:18 -0400</pubDate>      <ddb:attackedentityfield>Retail</ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>February 8, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-48: Hackers brute force their way into galeton.com website containing names, credit card numbers</ddb:entrytitle>      <ddb:incidentdescription>Hackers used brute force to log into web accounts of users at www.galeton.com.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Credit Card Leakage</ddb:outcome>      <ddb:reference>http://datalossdb.org/incidents/2692-hackers-brute-force-their-way-into-website-containing-names-credit-card-numbers</ddb:reference>      <ddb:whidid>2010-48</ddb:whidid>    </item>    <item>      <title>WHID 2009-47: Morrison says 'new baby' story a hoax by web hacker</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=42538</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2009-47: Morrison says 'new baby' story a hoax by web hacker&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2009-47&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;December 29, 2009&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Disinformation&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;A hoax, posted by a hacker on Van Morrison's website, falsely claimed the singer (64) had a baby with a woman called Gigi Lee.&lt;br&gt;But the reclusive singer issued a statement on New Year's Eve saying he is happily married to former model Michelle Rocca.&lt;br&gt;The earlier reports were carried by news organisations worldwide after a Los Angeles based public relations consultant, who has represented Morrison in the past, apparently confirmed the claim on Tuesday.&lt;br&gt;However, the statement issued by Van Morrison said: &quot;I have asked my management team to carry out an immediate investigation into a hacking attack which took place on my website on December 29th last.&lt;br&gt;&quot;This is the second occasion on which the website has been hacked into during the last three months. In this most recent incident, claims were made relating to my personal life in a &quot;statement'' purporting to come from me. &lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Entertainment&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://www.independent.ie/national-news/morrison-says-new-baby-story-a-hoax-by-web-hacker-1996333.html&quot;&gt;http://www.independent.ie/national-news/morrison-says-new-baby-story-a-hoax-by-web-hacker-1996333.html&lt;/a></description>      <pubDate>Wed, 16 Jun 2010 14:12:28 -0400</pubDate>      <ddb:attackedentityfield>Entertainment</ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>December 29, 2009</ddb:dateoccured>      <ddb:entrytitle>WHID 2009-47: Morrison says 'new baby' story a hoax by web hacker</ddb:entrytitle>      <ddb:incidentdescription>A hoax, posted by a hacker on Van Morrison's website, falsely claimed the singer (64) had a baby with a woman called Gigi Lee.&#13;&#10;&#13;&#10;But the reclusive singer issued a statement on New Year's Eve saying he is happily married to former model Michelle Rocca.&#13;&#10;&#13;&#10;The earlier reports were carried by news organisations worldwide after a Los Angeles based public relations consultant, who has represented Morrison in the past, apparently confirmed the claim on Tuesday.&#13;&#10;&#13;&#10;However, the statement issued by Van Morrison said: &quot;I have asked my management team to carry out an immediate investigation into a hacking attack which took place on my website on December 29th last.&#13;&#10;&#13;&#10;&quot;This is the second occasion on which the website has been hacked into during the last three months. In this most recent incident, claims were made relating to my personal life in a &quot;statement'' purporting to come from me. </ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Disinformation</ddb:outcome>      <ddb:reference>http://www.independent.ie/national-news/morrison-says-new-baby-story-a-hoax-by-web-hacker-1996333.html</ddb:reference>      <ddb:whidid>2009-47</ddb:whidid>    </item>    <item>      <title>WHID 2010-4: Shopping website hacked with malware</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=42093</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-4: Shopping website hacked with malware&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-4&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;March 19, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Planting of Malware&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;Australian retailer DealsDirect.com.au started serving malware to clients through a compromised partner advertising system.  It seems that end users were made aware of malware due to Google Safe Browsing plugins in Google Chrome, Firefox and Internet Explorer browsers as they were alerted with the &quot;This site may harm your computer&quot; warning.  It is a shame that web sites themselves aren't doing better at analyzing outbound data they are serving to ensure that it is not malicious.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Retail&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;Australia&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://news.ninemsn.com.au/technology/1029568/shopping-website-hacked-with-malware&quot;&gt;http://news.ninemsn.com.au/technology/1029568/shopping-website-hacked-with-malware&lt;/a></description>      <pubDate>Mon, 24 May 2010 13:54:42 -0400</pubDate>      <ddb:attackedentityfield>Retail</ddb:attackedentityfield>      <ddb:attackedentitygeography>Australia</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>March 19, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-4: Shopping website hacked with malware</ddb:entrytitle>      <ddb:incidentdescription>Australian retailer DealsDirect.com.au started serving malware to clients through a compromised partner advertising system.  It seems that end users were made aware of malware due to Google Safe Browsing plugins in Google Chrome, Firefox and Internet Explorer browsers as they were alerted with the &quot;This site may harm your computer&quot; warning.  It is a shame that web sites themselves aren't doing better at analyzing outbound data they are serving to ensure that it is not malicious.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Planting of Malware</ddb:outcome>      <ddb:reference>http://news.ninemsn.com.au/technology/1029568/shopping-website-hacked-with-malware</ddb:reference>      <ddb:whidid>2010-4</ddb:whidid>    </item>    <item>      <title>WHID 2010-28: Bank sues victim of $800,000 cybertheft</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=43669</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-28: Bank sues victim of $800,000 cybertheft&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-28&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;January 26, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Monetary Loss&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;A Texas bank is suing a customer hit by an $800,000 cybertheft incident in a case that could test the extent to which customers should be held responsible for protecting their online accounts from compromises.&lt;br&gt;The incident, which was first reported by blogger Brian Krebs this week, involves Lubbock-based PlainsCapital bank and its customer Hillary Machinery Inc. of Plano.&lt;br&gt;In November, unknown attackers based in Romania and Italy initiated a series of unauthorized wire transfers from Hillary's bank accounts and depleted it by $801,495. About $600,000 of the amount was later recovered by PlainsCapital.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;Romania&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Finance&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;TX, USA&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://www.computerworld.com/s/article/9149218/Bank_sues_victim_of_800_000_cybertheft&quot;&gt;http://www.computerworld.com/s/article/9149218/Bank_sues_victim_of_800_000_cybertheft&lt;/a></description>      <pubDate>Mon, 24 May 2010 13:54:42 -0400</pubDate>      <ddb:attackedentityfield>Finance</ddb:attackedentityfield>      <ddb:attackedentitygeography>TX, USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography>Romania</ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>January 26, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-28: Bank sues victim of $800,000 cybertheft</ddb:entrytitle>      <ddb:incidentdescription>A Texas bank is suing a customer hit by an $800,000 cybertheft incident in a case that could test the extent to which customers should be held responsible for protecting their online accounts from compromises.&#13;&#10;&#13;&#10;The incident, which was first reported by blogger Brian Krebs this week, involves Lubbock-based PlainsCapital bank and its customer Hillary Machinery Inc. of Plano.&#13;&#10;&#13;&#10;In November, unknown attackers based in Romania and Italy initiated a series of unauthorized wire transfers from Hillary's bank accounts and depleted it by $801,495. About $600,000 of the amount was later recovered by PlainsCapital.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Monetary Loss</ddb:outcome>      <ddb:reference>http://www.computerworld.com/s/article/9149218/Bank_sues_victim_of_800_000_cybertheft</ddb:reference>      <ddb:whidid>2010-28</ddb:whidid>    </item>    <item>      <title>WHID 2010-36: Durex condom orders leak on web – customer (update 1)</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=44021</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-36: Durex condom orders leak on web – customer (update 1)&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-36&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;March 22, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;Last week, this site received a lead about a security problem involving the web site of a Durex product. On March 5, a customer reportedly discovered that anyone could view his and other customers’ orders on the kohinoorpassion.com web site by simply inserting a different order ID number in the url without any login required. Names, addresses, phone numbers, and type of products ordered were all there for ready viewing.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Retail&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;India&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://www.databreaches.net/?p=10726&quot;&gt;http://www.databreaches.net/?p=10726&lt;/a></description>      <pubDate>Mon, 24 May 2010 13:54:42 -0400</pubDate>      <ddb:attackedentityfield>Retail</ddb:attackedentityfield>      <ddb:attackedentitygeography>India</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>March 22, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-36: Durex condom orders leak on web – customer (update 1)</ddb:entrytitle>      <ddb:incidentdescription>Last week, this site received a lead about a security problem involving the web site of a Durex product. On March 5, a customer reportedly discovered that anyone could view his and other customers’ orders on the kohinoorpassion.com web site by simply inserting a different order ID number in the url without any login required. Names, addresses, phone numbers, and type of products ordered were all there for ready viewing.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference>http://www.databreaches.net/?p=10726</ddb:reference>      <ddb:whidid>2010-36</ddb:whidid>    </item>    <item>      <title>WHID 2010-19: Hacked personal data originating from China</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=42874</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-19: Hacked personal data originating from China&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-19&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;March 22, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;According to police, Chinese hackers have been targeting Web sites of Korean department stores and other frequently visited sites. The hackers offer the Korean information for sale on the Internet.  Last September, a used-car trading Web site and the Internet home page for a car navigation manufacturer were victims of Chinese hackers who stole names and residential registration numbers of 910,000 online members. Hackers can use the stolen registration numbers to become members of certain Web sites that send spam messages, or sell the numbers to other hackers.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Retail&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;Korea&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://joongangdaily.joins.com/article/view.asp?aid=2918142&quot;&gt;http://joongangdaily.joins.com/article/view.asp?aid=2918142&lt;/a></description>      <pubDate>Mon, 24 May 2010 21:12:35 -0400</pubDate>      <ddb:attackedentityfield>Retail</ddb:attackedentityfield>      <ddb:attackedentitygeography>Korea</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>March 22, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-19: Hacked personal data originating from China</ddb:entrytitle>      <ddb:incidentdescription>According to police, Chinese hackers have been targeting Web sites of Korean department stores and other frequently visited sites. The hackers offer the Korean information for sale on the Internet.  Last September, a used-car trading Web site and the Internet home page for a car navigation manufacturer were victims of Chinese hackers who stole names and residential registration numbers of 910,000 online members. Hackers can use the stolen registration numbers to become members of certain Web sites that send spam messages, or sell the numbers to other hackers.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference>http://joongangdaily.joins.com/article/view.asp?aid=2918142</ddb:reference>      <ddb:whidid>2010-19</ddb:whidid>    </item>    <item>      <title>WHID 2010-24: Singapore's biggest forum, Hardwarezone Forums, gets hacked (friendly)</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=42086</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-24: Singapore's biggest forum, Hardwarezone Forums, gets hacked (friendly)&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-24&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;March 18, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Defacement&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;Yesterday, at 8pm past, a member &quot;gameboyz&quot; discovered pretty quickly that he could inject HTML code into the Tag Board Chat, and posted a script which changed the contents of the page where the tagboard would appear, with a message below, when one accessed certain sections of the site.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Retail&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;Singapore</description>      <pubDate>Mon, 24 May 2010 13:54:42 -0400</pubDate>      <ddb:attackedentityfield>Retail</ddb:attackedentityfield>      <ddb:attackedentitygeography>Singapore</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>March 18, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-24: Singapore's biggest forum, Hardwarezone Forums, gets hacked (friendly)</ddb:entrytitle>      <ddb:incidentdescription>Yesterday, at 8pm past, a member &quot;gameboyz&quot; discovered pretty quickly that he could inject HTML code into the Tag Board Chat, and posted a script which changed the contents of the page where the tagboard would appear, with a message below, when one accessed certain sections of the site.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Defacement</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2010-24</ddb:whidid>    </item>    <item>      <title>WHID 2010-46: Microsoft's Larry &quot;Major Nelson&quot; Hryb has online account hijacked through Xbox.com as part of underground group's publicity bid.</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=45280</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-46: Microsoft's Larry &quot;Major Nelson&quot; Hryb has online account hijacked through Xbox.com as part of underground group's publicity bid.&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-46&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;March 29, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;Xbox Live director of programming Larry Hryb has for some time now been the face of Microsoft's online platform for the Xbox 360, thanks in large part to his Major Nelson persona. Unfortunately, Xbox Live's figurehead saw his gamertag defaced over the weekend after a hacker was able to log into Hryb's account.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Entertainment&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://www.gamespot.com/news/6254330.html&quot;&gt;http://www.gamespot.com/news/6254330.html&lt;/a></description>      <pubDate>Mon, 24 May 2010 21:04:51 -0400</pubDate>      <ddb:attackedentityfield>Entertainment</ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>March 29, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-46: Microsoft's Larry &quot;Major Nelson&quot; Hryb has online account hijacked through Xbox.com as part of underground group's publicity bid.</ddb:entrytitle>      <ddb:incidentdescription>Xbox Live director of programming Larry Hryb has for some time now been the face of Microsoft's online platform for the Xbox 360, thanks in large part to his Major Nelson persona. Unfortunately, Xbox Live's figurehead saw his gamertag defaced over the weekend after a hacker was able to log into Hryb's account.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference>http://www.gamespot.com/news/6254330.html</ddb:reference>      <ddb:whidid>2010-46</ddb:whidid>    </item>    <item>      <title>WHID 2010-10: FBI, police ID Boulder synagogue Web site hacker</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=42369</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-10: FBI, police ID Boulder synagogue Web site hacker&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-10&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;January 2, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Defacement&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;Boulder police and the FBI announced Friday that they have identified the individual who hacked into the Web sites of two Boulder synagogues and the Boulder Rabbinic Council last week and defaced them with anti-Semitic messages.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Religious&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;Boulder, CO&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://www.dailycamera.com/ci_14150610?source=most_emailed#axzz0ieLUTxxC&quot;&gt;http://www.dailycamera.com/ci_14150610?source=most_emailed#axzz0ieLUTxxC&lt;/a></description>      <pubDate>Mon, 24 May 2010 21:15:39 -0400</pubDate>      <ddb:attackedentityfield>Religious</ddb:attackedentityfield>      <ddb:attackedentitygeography>Boulder, CO</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>January 2, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-10: FBI, police ID Boulder synagogue Web site hacker</ddb:entrytitle>      <ddb:incidentdescription>Boulder police and the FBI announced Friday that they have identified the individual who hacked into the Web sites of two Boulder synagogues and the Boulder Rabbinic Council last week and defaced them with anti-Semitic messages.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Defacement</ddb:outcome>      <ddb:reference>http://www.dailycamera.com/ci_14150610?source=most_emailed#axzz0ieLUTxxC</ddb:reference>      <ddb:whidid>2010-10</ddb:whidid>    </item>    <item>      <title>WHID 2010-43: Sleuths Trace Digital Clues to Predict iPad Sales</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=44380</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-43: Sleuths Trace Digital Clues to Predict iPad Sales&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-43&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;March 19, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;To get the ball rolling on the iPad estimate, Mr. Tello asked participants on a private message board for Apple watchers, AAPL Sanity, to share the order number that the Apple Store assigns to each online purchase and includes on the order's email confirmation.&lt;br&gt;The first order submitted, from a user named Joe, had an eight-digit order number 68,715,XXX (the last three digits have been excised) at 8:30 a.m. Eastern time on March 12, the first day iPad orders could be placed. Another order placed five days later, by a user named Israel, was numbered 68,937,XXX. That is a difference of about 222,000.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Retail&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://online.wsj.com/article/SB10001424052748704207504575130351672451186.html&quot;&gt;http://online.wsj.com/article/SB10001424052748704207504575130351672451186.html&lt;/a></description>      <pubDate>Mon, 24 May 2010 21:09:13 -0400</pubDate>      <ddb:attackedentityfield>Retail</ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>March 19, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-43: Sleuths Trace Digital Clues to Predict iPad Sales</ddb:entrytitle>      <ddb:incidentdescription>To get the ball rolling on the iPad estimate, Mr. Tello asked participants on a private message board for Apple watchers, AAPL Sanity, to share the order number that the Apple Store assigns to each online purchase and includes on the order's email confirmation.&#13;&#10;&#13;&#10;The first order submitted, from a user named Joe, had an eight-digit order number 68,715,XXX (the last three digits have been excised) at 8:30 a.m. Eastern time on March 12, the first day iPad orders could be placed. Another order placed five days later, by a user named Israel, was numbered 68,937,XXX. That is a difference of about 222,000.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference>http://online.wsj.com/article/SB10001424052748704207504575130351672451186.html</ddb:reference>      <ddb:whidid>2010-43</ddb:whidid>    </item>    <item>      <title>WHID 2010-22: Hackers target SDP leaders</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=42972</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-22: Hackers target SDP leaders&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-22&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;March 21, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Defacement&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;At least two leading figures in the opposition Social Democratic Party were attacked by computer hackers during the weekend.&lt;br&gt;      On Sunday, the web pages of the party’s Parliamentary group chairman Eero Heinäluoma were hacked, and on Saturday evening it was the turn of the party’s chairwoman Jutta Urpilainen.&lt;br&gt;     &lt;br&gt;Strange pictures and text had appeared on Heinäluoma’s page www.heinaluoma.net on Sunday, and shortly before 4 p.m. his web page was no longer accessible.&lt;br&gt;      On Saturday evening, Urpilainen’s page had been targeted with obscene messages and child pornography.&lt;br&gt;      The pages crashed at about 10:00 p.m. &lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Politics&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;Finland&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://www.hs.fi/english/article/Hackers+target+SDP+leaders+/1135254873196&quot;&gt;http://www.hs.fi/english/article/Hackers+target+SDP+leaders+/1135254873196&lt;/a></description>      <pubDate>Mon, 24 May 2010 21:11:26 -0400</pubDate>      <ddb:attackedentityfield>Politics</ddb:attackedentityfield>      <ddb:attackedentitygeography>Finland</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>March 21, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-22: Hackers target SDP leaders</ddb:entrytitle>      <ddb:incidentdescription>At least two leading figures in the opposition Social Democratic Party were attacked by computer hackers during the weekend.&#13;&#10;      On Sunday, the web pages of the party’s Parliamentary group chairman Eero Heinäluoma were hacked, and on Saturday evening it was the turn of the party’s chairwoman Jutta Urpilainen.&#13;&#10;     &#13;&#10;Strange pictures and text had appeared on Heinäluoma’s page www.heinaluoma.net on Sunday, and shortly before 4 p.m. his web page was no longer accessible.&#13;&#10;      On Saturday evening, Urpilainen’s page had been targeted with obscene messages and child pornography.&#13;&#10;      The pages crashed at about 10:00 p.m. </ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Defacement</ddb:outcome>      <ddb:reference>http://www.hs.fi/english/article/Hackers+target+SDP+leaders+/1135254873196</ddb:reference>      <ddb:whidid>2010-22</ddb:whidid>    </item>    <item>      <title>WHID 2009-51: Hacker Hits RBS WorldPay Systems Database</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=43528</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2009-51: Hacker Hits RBS WorldPay Systems Database&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2009-51&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;September 11, 2009&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;A Romanian hacker well-known for discovering SQL injection vulnerabilities in high-profile Websites has struck again -- this time on RBS WorldPay's site, where he says he hit the jackpot, the company's database.&lt;br&gt;The hacker, who goes by &quot;Unu,&quot; says he accessed RBS WorldPay's database via a SQL injection flaw in one of its Web applications. RBS WorldPay maintains Unu accessed a test database that didn't carry any live data, and that no merchant or cardholder data accounts were compromised. The company has since taken down the pages.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;Romania&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Finance&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;Georgia, USA&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://www.darkreading.com/database_security/security/app-security/showArticle.jhtml?articleID=220000005&quot;&gt;http://www.darkreading.com/database_security/security/app-security/showArticle.jhtml?articleID=220000005&lt;/a></description>      <pubDate>Wed, 16 Jun 2010 14:09:34 -0400</pubDate>      <ddb:attackedentityfield>Finance</ddb:attackedentityfield>      <ddb:attackedentitygeography>Georgia, USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography>Romania</ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>September 11, 2009</ddb:dateoccured>      <ddb:entrytitle>WHID 2009-51: Hacker Hits RBS WorldPay Systems Database</ddb:entrytitle>      <ddb:incidentdescription>A Romanian hacker well-known for discovering SQL injection vulnerabilities in high-profile Websites has struck again -- this time on RBS WorldPay's site, where he says he hit the jackpot, the company's database.&#13;&#10;&#13;&#10;The hacker, who goes by &quot;Unu,&quot; says he accessed RBS WorldPay's database via a SQL injection flaw in one of its Web applications. RBS WorldPay maintains Unu accessed a test database that didn't carry any live data, and that no merchant or cardholder data accounts were compromised. The company has since taken down the pages.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference>http://www.darkreading.com/database_security/security/app-security/showArticle.jhtml?articleID=220000005</ddb:reference>      <ddb:whidid>2009-51</ddb:whidid>    </item>    <item>      <title>WHID 2010-54: MyPilotStore.com hack results in false charges on customers’ cards</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=45948</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-54: MyPilotStore.com hack results in false charges on customers’ cards&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-54&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;February 18, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Credit Card Leakage&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;On February 18, MyPlane, dba MyPilotStore.com, discovered that their database containing their customers’ names, addresses, telephone numbers, e-mail addresses, and credit card information had been hacked. According to the firm, some customers received a “nominal fake charge to their credit card by a company not associated with us.”&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Retail&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://www.databreaches.net/?p=10990&quot;&gt;http://www.databreaches.net/?p=10990&lt;/a></description>      <pubDate>Thu, 17 Jun 2010 14:25:00 -0400</pubDate>      <ddb:attackedentityfield>Retail</ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>February 18, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-54: MyPilotStore.com hack results in false charges on customers’ cards</ddb:entrytitle>      <ddb:incidentdescription>On February 18, MyPlane, dba MyPilotStore.com, discovered that their database containing their customers’ names, addresses, telephone numbers, e-mail addresses, and credit card information had been hacked. According to the firm, some customers received a “nominal fake charge to their credit card by a company not associated with us.”</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Credit Card Leakage</ddb:outcome>      <ddb:reference>http://www.databreaches.net/?p=10990</ddb:reference>      <ddb:whidid>2010-54</ddb:whidid>    </item>    <item>      <title>WHID 2010-51: Woman worms into D.C. taxpayer accounts</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=45836</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-51: Woman worms into D.C. taxpayer accounts&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-51&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;February 5, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;A mentally ill woman exploited a loophole in D.C. tax office online systems to gain unauthorized access to taxpayer accounts, establish herself as the owner of dozens of businesses and file returns on their behalf.  The FR-500 forms were not submitted for review before processing, BDO found, and no verification checks were performed.  The loophole was a glitch, OTR explained. The agency's Integrated Tax System was supposed to deny ownership changes requested through the FR-500 function, but &quot;faulty logic&quot; allowed the updates automatically. Umansky said a fix is now in place and &quot;that can't happen again.&quot;&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Government&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;Washington DC, USA&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://www.washingtonexaminer.com/local/Woman-worms-into-D_C_-taxpayer-accounts-83589257.html&quot;&gt;http://www.washingtonexaminer.com/local/Woman-worms-into-D_C_-taxpayer-accounts-83589257.html&lt;/a></description>      <pubDate>Mon, 24 May 2010 13:54:42 -0400</pubDate>      <ddb:attackedentityfield>Government</ddb:attackedentityfield>      <ddb:attackedentitygeography>Washington DC, USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>February 5, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-51: Woman worms into D.C. taxpayer accounts</ddb:entrytitle>      <ddb:incidentdescription>A mentally ill woman exploited a loophole in D.C. tax office online systems to gain unauthorized access to taxpayer accounts, establish herself as the owner of dozens of businesses and file returns on their behalf.  The FR-500 forms were not submitted for review before processing, BDO found, and no verification checks were performed.  The loophole was a glitch, OTR explained. The agency's Integrated Tax System was supposed to deny ownership changes requested through the FR-500 function, but &quot;faulty logic&quot; allowed the updates automatically. Umansky said a fix is now in place and &quot;that can't happen again.&quot;&#13;
</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference>http://www.washingtonexaminer.com/local/Woman-worms-into-D_C_-taxpayer-accounts-83589257.html</ddb:reference>      <ddb:whidid>2010-51</ddb:whidid>    </item>    <item>      <title>WHID 2010-59: Orange Regional Website Hacked</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=46417</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-59: Orange Regional Website Hacked&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-59&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;February 9, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;A Lebanese hacker claims to have hacked Orange's regional website in Cote d'Ivoire (Ivory Coast) through SQL injection. The attack allegedly gave him access to the website's administration interface and information on almost 60,000 customers.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;Lebanon&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Information Services&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;Ivory Coast&lt;br&gt;&lt;b&gt;Number of Records: &lt;/b&gt;60,000&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://news.softpedia.com/news/Orange-Regional-Website-Hacked-134467.shtml&quot;&gt;http://news.softpedia.com/news/Orange-Regional-Website-Hacked-134467.shtml&lt;/a></description>      <pubDate>Mon, 24 May 2010 13:54:42 -0400</pubDate>      <ddb:attackedentityfield>Information Services</ddb:attackedentityfield>      <ddb:attackedentitygeography>Ivory Coast</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography>Lebanon</ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>February 9, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-59: Orange Regional Website Hacked</ddb:entrytitle>      <ddb:incidentdescription>A Lebanese hacker claims to have hacked Orange's regional website in Cote d'Ivoire (Ivory Coast) through SQL injection. The attack allegedly gave him access to the website's administration interface and information on almost 60,000 customers.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords>60,000</ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference>http://news.softpedia.com/news/Orange-Regional-Website-Hacked-134467.shtml</ddb:reference>      <ddb:whidid>2010-59</ddb:whidid>    </item>    <item>      <title>WHID 2010-1: Hacker Breaks Into 49 House Sites, Insults Obama</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=37792</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-1: Hacker Breaks Into 49 House Sites, Insults Obama&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-1&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;February 1, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Defacement&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;A hacker broke into 49 House Web sites of both political parties after President Obama's State of the Union address.  The websites were all managed by a private vendor -- GovTrends of Alexandria, Va.  The article mentions that &quot;GovTrends let its guard down while performing an update, allowing the hacker to penetrate sites of individual members and committees overnight&quot; which leads to WHID's Misconfiguration Attack Method designation. &lt;br&gt;Interesting note - 18 House sites managed by GovTrends were defaced last August.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Government&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://www.toptechnews.com/news/Hacker-Breaks-Into-49-House-Sites/story.xhtml?story_id=00100041BAO7&quot;&gt;http://www.toptechnews.com/news/Hacker-Breaks-Into-49-House-Sites/story.xhtml?story_id=00100041BAO7&lt;/a></description>      <pubDate>Mon, 24 May 2010 13:54:42 -0400</pubDate>      <ddb:attackedentityfield>Government</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>February 1, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-1: Hacker Breaks Into 49 House Sites, Insults Obama</ddb:entrytitle>      <ddb:incidentdescription>A hacker broke into 49 House Web sites of both political parties after President Obama's State of the Union address.  The websites were all managed by a private vendor -- GovTrends of Alexandria, Va.  The article mentions that &quot;GovTrends let its guard down while performing an update, allowing the hacker to penetrate sites of individual members and committees overnight&quot; which leads to WHID's Misconfiguration Attack Method designation. &#13;&#10;&#13;&#10;Interesting note - 18 House sites managed by GovTrends were defaced last August.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Defacement</ddb:outcome>      <ddb:reference>http://www.toptechnews.com/news/Hacker-Breaks-Into-49-House-Sites/story.xhtml?story_id=00100041BAO7</ddb:reference>      <ddb:whidid>2010-1</ddb:whidid>    </item>    <item>      <title>WHID 2010-27: Poughkeepsie, N.Y., slams bank for $378,000 online theft</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=43636</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-27: Poughkeepsie, N.Y., slams bank for $378,000 online theft&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-27&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;February 8, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Monetary Loss&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;The theft of $378,000 from the town of Poughkeepsie, N.Y., is prompting questions about the responsibility of banks to protect customer accounts from online criminals.&lt;br&gt;In a statement last week, a Poughkeepsie town official revealed that thieves had broken into the town's TD Bank NA account and transferred $378,000 to accounts in the Ukraine.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;Ukraine&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Finance&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;NY, USA&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://www.computerworld.com/s/article/9153598/Poughkeepsie_N.Y._slams_bank_for_378_000_online_theft&quot;&gt;http://www.computerworld.com/s/article/9153598/Poughkeepsie_N.Y._slams_bank_for_378_000_online_theft&lt;/a></description>      <pubDate>Mon, 24 May 2010 13:54:42 -0400</pubDate>      <ddb:attackedentityfield>Finance</ddb:attackedentityfield>      <ddb:attackedentitygeography>NY, USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography>Ukraine</ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>February 8, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-27: Poughkeepsie, N.Y., slams bank for $378,000 online theft</ddb:entrytitle>      <ddb:incidentdescription>The theft of $378,000 from the town of Poughkeepsie, N.Y., is prompting questions about the responsibility of banks to protect customer accounts from online criminals.&#13;&#10;&#13;&#10;In a statement last week, a Poughkeepsie town official revealed that thieves had broken into the town's TD Bank NA account and transferred $378,000 to accounts in the Ukraine.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Monetary Loss</ddb:outcome>      <ddb:reference>http://www.computerworld.com/s/article/9153598/Poughkeepsie_N.Y._slams_bank_for_378_000_online_theft</ddb:reference>      <ddb:whidid>2010-27</ddb:whidid>    </item>    <item>      <title>WHID 2010-50: Shared-password vulnerability may have exposed personal information in online account management system</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=45509</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-50: Shared-password vulnerability may have exposed personal information in online account management system&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-50&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;January 14, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;Lincoln National Corp. (LNC) last week disclosed a security vulnerability in its portfolio information system that could have compromised the account data of approximately 1.2 million customers.&lt;br&gt;In a disclosure letter (PDF) sent to the attorney general of New Hampshire Jan. 4, attorneys for the financial services firm revealed that a breach of the Lincoln portfolio information system had been reported to the Financial Industry Regulatory Authority (FINRA) by an unidentified source last August. The company was planning to issue notification to the affected customers on Jan. 6, the letter says.&lt;br&gt;The letter does not give technical details about the breach, but it indicates the unidentified source sent FINRA a username and password to the portfolio management system.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Finance&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA&lt;br&gt;&lt;b&gt;Number of Records: &lt;/b&gt;1,200,000&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://www.darkreading.com/vulnerability_management/security/privacy/showArticle.jhtml?articleID=222301034&quot;&gt;http://www.darkreading.com/vulnerability_management/security/privacy/showArticle.jhtml?articleID=222301034&lt;/a></description>      <pubDate>Mon, 24 May 2010 13:54:42 -0400</pubDate>      <ddb:attackedentityfield>Finance</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>January 14, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-50: Shared-password vulnerability may have exposed personal information in online account management system</ddb:entrytitle>      <ddb:incidentdescription>Lincoln National Corp. (LNC) last week disclosed a security vulnerability in its portfolio information system that could have compromised the account data of approximately 1.2 million customers.&#13;&#10;&#13;&#10;In a disclosure letter (PDF) sent to the attorney general of New Hampshire Jan. 4, attorneys for the financial services firm revealed that a breach of the Lincoln portfolio information system had been reported to the Financial Industry Regulatory Authority (FINRA) by an unidentified source last August. The company was planning to issue notification to the affected customers on Jan. 6, the letter says.&#13;&#10;&#13;&#10;The letter does not give technical details about the breach, but it indicates the unidentified source sent FINRA a username and password to the portfolio management system.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords>1,200,000</ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference>http://www.darkreading.com/vulnerability_management/security/privacy/showArticle.jhtml?articleID=222301034</ddb:reference>      <ddb:whidid>2010-50</ddb:whidid>    </item>    <item>      <title>WHID 2010-58: China journalist club shuts website after attack</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=46356</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-58: China journalist club shuts website after attack&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-58&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;April 1, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Downtime&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;The Foreign Correspondents Club of China said on Friday it had shut its website after a burst of hacker attacks, days after attacks on the Yahoo email accounts of some foreign journalists covering China were discovered.&lt;br&gt;&quot;We do not know who is behind the attacks or what their motivation is,&quot; the club's board said in an emailed statement explaining it had decided to shut down temporarily the site after two days of &quot;persistent&quot; attacks.&lt;br&gt;The club has traced the online assault to IP addresses in both China and the U.S., but added that these machines could have been taken over by hackers in other locations.&lt;br&gt;The hacking was the latest of several recent incidents that have brought to light the Internet vulnerabilities of people or groups whose work may raise hackles in China.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Media&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;China&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://www.reuters.com/assets/print?aid=USTOE63101R20100402&quot;&gt;http://www.reuters.com/assets/print?aid=USTOE63101R20100402&lt;/a></description>      <pubDate>Mon, 24 May 2010 13:54:42 -0400</pubDate>      <ddb:attackedentityfield>Media</ddb:attackedentityfield>      <ddb:attackedentitygeography>China</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>April 1, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-58: China journalist club shuts website after attack</ddb:entrytitle>      <ddb:incidentdescription>The Foreign Correspondents Club of China said on Friday it had shut its website after a burst of hacker attacks, days after attacks on the Yahoo email accounts of some foreign journalists covering China were discovered.&#13;&#10;&quot;We do not know who is behind the attacks or what their motivation is,&quot; the club's board said in an emailed statement explaining it had decided to shut down temporarily the site after two days of &quot;persistent&quot; attacks.&#13;&#10;The club has traced the online assault to IP addresses in both China and the U.S., but added that these machines could have been taken over by hackers in other locations.&#13;&#10;The hacking was the latest of several recent incidents that have brought to light the Internet vulnerabilities of people or groups whose work may raise hackles in China.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Downtime</ddb:outcome>      <ddb:reference>http://www.reuters.com/assets/print?aid=USTOE63101R20100402</ddb:reference>      <ddb:whidid>2010-58</ddb:whidid>    </item>    <item>      <title>WHID 2010-20: Jewish Community Assistance Group Website Hacked</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=42907</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-20: Jewish Community Assistance Group Website Hacked&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-20&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;March 21, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Defacement&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;The internet website of the Keren Kehilot organization was hacked Sunday morning by a gang of Muslim hackers, apparently from Turkey.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Religious&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;Israel&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://www.israelnationalnews.com/News/Flash.aspx/182976&quot;&gt;http://www.israelnationalnews.com/News/Flash.aspx/182976&lt;/a></description>      <pubDate>Mon, 24 May 2010 21:11:53 -0400</pubDate>      <ddb:attackedentityfield>Religious</ddb:attackedentityfield>      <ddb:attackedentitygeography>Israel</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>March 21, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-20: Jewish Community Assistance Group Website Hacked</ddb:entrytitle>      <ddb:incidentdescription>The internet website of the Keren Kehilot organization was hacked Sunday morning by a gang of Muslim hackers, apparently from Turkey.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Defacement</ddb:outcome>      <ddb:reference>http://www.israelnationalnews.com/News/Flash.aspx/182976</ddb:reference>      <ddb:whidid>2010-20</ddb:whidid>    </item>    <item>      <title>WHID 2010-37: ING Shareholder Data Exposed on Website</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=44059</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-37: ING Shareholder Data Exposed on Website&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-37&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;January 25, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;On January 25, an ING customer discovered that she could access client information on the ingfunds.com web site and notified her stockbroker. In investigating the situation, ING discovered that since August 2008, a file containing the names, addresses, Social Security numbers, and account numbers of 106 ING shareholders had been available on the web through a search engine. The company notified the New Hampshire Attorney General on February 3 that 17 residents of the state were affected.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;New Hampshire, USA&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Finance&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://doj.nh.gov/consumer/pdf/ing.pdf&quot;&gt;http://doj.nh.gov/consumer/pdf/ing.pdf&lt;/a></description>      <pubDate>Mon, 24 May 2010 13:54:42 -0400</pubDate>      <ddb:attackedentityfield>Finance</ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography>New Hampshire, USA</ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>January 25, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-37: ING Shareholder Data Exposed on Website</ddb:entrytitle>      <ddb:incidentdescription>On January 25, an ING customer discovered that she could access client information on the ingfunds.com web site and notified her stockbroker. In investigating the situation, ING discovered that since August 2008, a file containing the names, addresses, Social Security numbers, and account numbers of 106 ING shareholders had been available on the web through a search engine. The company notified the New Hampshire Attorney General on February 3 that 17 residents of the state were affected.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference>http://doj.nh.gov/consumer/pdf/ing.pdf</ddb:reference>      <ddb:whidid>2010-37</ddb:whidid>    </item>    <item>      <title>WHID 2010-11: U.S. Military Equipment Website Hacked</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=42411</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-11: U.S. Military Equipment Website Hacked&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-11&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;January 13, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;A Lebanese hacker is taking credit for a security breach on the PEO Soldier Army website. By exploiting an SQL injection vulnerability, he allegedly obtained full access to the underlying database and the information contained within.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;Lebanon&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Government&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://news.softpedia.com/news/U-S-Military-Equipment-Website-Hacked-131947.shtml&quot;&gt;http://news.softpedia.com/news/U-S-Military-Equipment-Website-Hacked-131947.shtml&lt;/a></description>      <pubDate>Mon, 24 May 2010 13:54:42 -0400</pubDate>      <ddb:attackedentityfield>Government</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography>Lebanon</ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>January 13, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-11: U.S. Military Equipment Website Hacked</ddb:entrytitle>      <ddb:incidentdescription>A Lebanese hacker is taking credit for a security breach on the PEO Soldier Army website. By exploiting an SQL injection vulnerability, he allegedly obtained full access to the underlying database and the information contained within.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference>http://news.softpedia.com/news/U-S-Military-Equipment-Website-Hacked-131947.shtml</ddb:reference>      <ddb:whidid>2010-11</ddb:whidid>    </item>    <item>      <title>WHID 2010-53: Google says Vietnam political blogs hacked</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=45911</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-53: Google says Vietnam political blogs hacked&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-53&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;March 31, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Downtime&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt; Internet giant Google says Vietnamese computer users have been spied on and political blogs hacked in attacks which a leading web security firm suspects are linked to the Vietnamese government.&lt;br&gt;The incidents recall cyber attacks in China that Google in January said had struck it and other unidentified firms in an apparent bid to hack into the email accounts of Chinese human rights activists.&lt;br&gt;&quot;These infected machines have been used both to spy on their owners as well as participate in distributed denial of service attacks against blogs containing messages of political dissent,&quot; said Neel Mehta of Google's security team in the firm's Online Security Blog.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Web 2.0&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;Vietnam&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://news.yahoo.com/s/afp/20100331/tc_afp/vietnammediainternetrightsgooglemcafee&amp;a=Technology%20News&amp;x=1&quot;&gt;http://news.yahoo.com/s/afp/20100331/tc_afp/vietnammediainternetrightsgooglemcafee&amp;a=Technology%20News&amp;x=1&lt;/a></description>      <pubDate>Mon, 24 May 2010 13:54:42 -0400</pubDate>      <ddb:attackedentityfield>Web 2.0</ddb:attackedentityfield>      <ddb:attackedentitygeography>Vietnam</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>March 31, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-53: Google says Vietnam political blogs hacked</ddb:entrytitle>      <ddb:incidentdescription> Internet giant Google says Vietnamese computer users have been spied on and political blogs hacked in attacks which a leading web security firm suspects are linked to the Vietnamese government.&#13;&#10;&#13;&#10;The incidents recall cyber attacks in China that Google in January said had struck it and other unidentified firms in an apparent bid to hack into the email accounts of Chinese human rights activists.&#13;&#10;&#13;&#10;&quot;These infected machines have been used both to spy on their owners as well as participate in distributed denial of service attacks against blogs containing messages of political dissent,&quot; said Neel Mehta of Google's security team in the firm's Online Security Blog.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Downtime</ddb:outcome>      <ddb:reference>http://news.yahoo.com/s/afp/20100331/tc_afp/vietnammediainternetrightsgooglemcafee&amp;a=Technology%20News&amp;x=1</ddb:reference>      <ddb:whidid>2010-53</ddb:whidid>    </item>    <item>      <title>WHID 2010-12: Army Website Compromised Through SQL Injection</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=42453</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-12: Army Website Compromised Through SQL Injection&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-12&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;January 9, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;A Romanian grey hat hacker has disclosed an SQL inject (SQLi) vulnerability on a website belonging to the United States Army, which leads to full database compromise. The website, called Army Housing OneStop, is used to provide information about military housing facilities to soldiers.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;Romania&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Government&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://news.softpedia.com/news/Army-Website-Compromised-Through-SQL-Injection-131649.shtml&quot;&gt;http://news.softpedia.com/news/Army-Website-Compromised-Through-SQL-Injection-131649.shtml&lt;/a></description>      <pubDate>Mon, 24 May 2010 13:54:42 -0400</pubDate>      <ddb:attackedentityfield>Government</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography>Romania</ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>January 9, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-12: Army Website Compromised Through SQL Injection</ddb:entrytitle>      <ddb:incidentdescription>A Romanian grey hat hacker has disclosed an SQL inject (SQLi) vulnerability on a website belonging to the United States Army, which leads to full database compromise. The website, called Army Housing OneStop, is used to provide information about military housing facilities to soldiers.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference>http://news.softpedia.com/news/Army-Website-Compromised-Through-SQL-Injection-131649.shtml</ddb:reference>      <ddb:whidid>2010-12</ddb:whidid>    </item>    <item>      <title>WHID 2010-52: 3000 Small Dog Electronics customers' credit card details compromised</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=45868</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-52: 3000 Small Dog Electronics customers' credit card details compromised&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-52&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;February 18, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Credit Card Leakage&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;lectronics retailer Small Dog Electronics has suffered from a systems breach that left 3000 customers' credit card details compromised.&lt;br&gt;The data theft, which left the credit card details exposed from late December to almost the end of January, used a security hole in the in-house web application that had been developed to manage Smalldog's ecommerce system.&lt;br&gt;Don Mayer, CEO of Small Dog Electronics, explained that the company is PCI compliant, and that it had been subjected to a penetration test by a third party, which he would not name. The flaw in the code has now been rectified, and Small Dog is investigating the issue with the pen tester, added Mayer, who did not know what language the ecommerce system had been written in.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Retail&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA&lt;br&gt;&lt;b&gt;Number of Records: &lt;/b&gt;3,000&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://www.infosecurity-us.com/view/7411/3000-small-dog-electronics-customers-credit-card-details-compromised/&quot;&gt;http://www.infosecurity-us.com/view/7411/3000-small-dog-electronics-customers-credit-card-details-compromised/&lt;/a></description>      <pubDate>Thu, 17 Jun 2010 14:25:14 -0400</pubDate>      <ddb:attackedentityfield>Retail</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>February 18, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-52: 3000 Small Dog Electronics customers' credit card details compromised</ddb:entrytitle>      <ddb:incidentdescription>lectronics retailer Small Dog Electronics has suffered from a systems breach that left 3000 customers' credit card details compromised.&#13;&#10;&#13;&#10;The data theft, which left the credit card details exposed from late December to almost the end of January, used a security hole in the in-house web application that had been developed to manage Smalldog's ecommerce system.&#13;&#10;&#13;&#10;Don Mayer, CEO of Small Dog Electronics, explained that the company is PCI compliant, and that it had been subjected to a penetration test by a third party, which he would not name. The flaw in the code has now been rectified, and Small Dog is investigating the issue with the pen tester, added Mayer, who did not know what language the ecommerce system had been written in.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords>3,000</ddb:numberofrecords>      <ddb:outcome>Credit Card Leakage</ddb:outcome>      <ddb:reference>http://www.infosecurity-us.com/view/7411/3000-small-dog-electronics-customers-credit-card-details-compromised/</ddb:reference>      <ddb:whidid>2010-52</ddb:whidid>    </item>    <item>      <title>WHID 2010-26: Russia Arrests Alleged Mastermind of RBS WorldPay Hack</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=43570</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-26: Russia Arrests Alleged Mastermind of RBS WorldPay Hack&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-26&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Monetary Loss&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;A fascinating story about a group of hackers who broke into the RBS WorldPay DBs through SQL Injection.  Russian authorities have nabbed the man accused of masterminding a coordinated global ATM heist of $9.5 million from Atlanta-based card processing company RBS WorldPay.  The hackers compromised RBS WorldPay’s database encryption to raise the amount of funds available on the compromised cards, and boost their daily withdrawal limits. In some case, the hackers raised the limits to $500,000.  According to the indictment, Tsurikov conducted reconnaissance of the RBS network after Covelin provided him with information about vulnerabilities in the system. Pleshchuk and Covelin then worked on exploiting the vulnerabilities to obtain access. Pleschuk allegedly developed the method for reverse engineering the encrypted PINs.  Once the hackers raised the account limits, they provided an army of cashers with 44 cards programmed with the account details. On November 8 that year, the cashers simultaneously hit more than 2,000 ATMs, netting about $9.5 million in less than 12 hours.&lt;br&gt;The story did not specify the exact vulnerabilities exploited to manipulate the DB however the Indictment PDF (in the reference) lists actual SQL commands sent to the DBs (pages 10-11).&lt;br&gt;If you then cross-reference this story with WHID entry 2009-51 where the Romania Hacker Unu released SQL Injection vulns in RBS WorldPay web applications, it seems most plausible that these Russian Hackers used similar vulnerabilities.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;Russia&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Finance&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;Georgia, USA&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://www.wired.com/threatlevel/2010/03/alleged-rbs-hacker-arrested&quot;&gt;http://www.wired.com/threatlevel/2010/03/alleged-rbs-hacker-arrested&lt;/a></description>      <pubDate>Mon, 24 May 2010 13:54:42 -0400</pubDate>      <ddb:attackedentityfield>Finance</ddb:attackedentityfield>      <ddb:attackedentitygeography>Georgia, USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography>Russia</ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured></ddb:dateoccured>      <ddb:entrytitle>WHID 2010-26: Russia Arrests Alleged Mastermind of RBS WorldPay Hack</ddb:entrytitle>      <ddb:incidentdescription>A fascinating story about a group of hackers who broke into the RBS WorldPay DBs through SQL Injection.  Russian authorities have nabbed the man accused of masterminding a coordinated global ATM heist of $9.5 million from Atlanta-based card processing company RBS WorldPay.  The hackers compromised RBS WorldPay’s database encryption to raise the amount of funds available on the compromised cards, and boost their daily withdrawal limits. In some case, the hackers raised the limits to $500,000.  According to the indictment, Tsurikov conducted reconnaissance of the RBS network after Covelin provided him with information about vulnerabilities in the system. Pleshchuk and Covelin then worked on exploiting the vulnerabilities to obtain access. Pleschuk allegedly developed the method for reverse engineering the encrypted PINs.  Once the hackers raised the account limits, they provided an army of cashers with 44 cards programmed with the account details. On November 8 that year, the cashers simultaneously hit more than 2,000 ATMs, netting about $9.5 million in less than 12 hours.&#13;&#10;&#13;&#10;The story did not specify the exact vulnerabilities exploited to manipulate the DB however the Indictment PDF (in the reference) lists actual SQL commands sent to the DBs (pages 10-11).&#13;&#10;&#13;&#10;If you then cross-reference this story with WHID entry 2009-51 where the Romania Hacker Unu released SQL Injection vulns in RBS WorldPay web applications, it seems most plausible that these Russian Hackers used similar vulnerabilities.&#13;&#10;&#13;&#10;&#13;&#10;&#13;&#10;&#13;
</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Monetary Loss</ddb:outcome>      <ddb:reference>http://www.wired.com/threatlevel/2010/03/alleged-rbs-hacker-arrested</ddb:reference>      <ddb:whidid>2010-26</ddb:whidid>    </item>    <item>      <title>WHID 2010-42: Frenchman Arrested After Hacking Into Obama's Twitter Accounts</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=44343</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-42: Frenchman Arrested After Hacking Into Obama's Twitter Accounts&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-42&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;March 25, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;A Frenchman will face trial after hacking into Twitter accounts, including that of U.S President Barack Obama, a French prosecutor said.&lt;br&gt;The 24-year-old man from central France was arrested on Tuesday and could face up to two years in prison in France for fraudulent access to a computer system. The arrest followed a joint operation between the Federal Bureau of Investigation and the French police, according to French state prosecutor Jean-Yves Coquillat.&lt;br&gt;The man, whose name hasn't been release, is charged with having hacked into the Twitter Inc. social-networking accounts of famous people. He did this in April 2009 after posing as a site administrator, said Mr. Coquillat. As well as Mr. Obama's account, he hacked into that of singer Britney Spears, he said.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;France&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Web 2.0&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA&lt;br&gt;&lt;b&gt;Attacked System Technology: &lt;/b&gt;Twitter&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://online.wsj.com/article/SB10001424052748704094104575143391819054502.html&quot;&gt;http://online.wsj.com/article/SB10001424052748704094104575143391819054502.html&lt;/a></description>      <pubDate>Mon, 24 May 2010 13:54:42 -0400</pubDate>      <ddb:attackedentityfield>Web 2.0</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology>Twitter</ddb:attackedsystemtechnology>      <ddb:attacksourcegeography>France</ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>March 25, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-42: Frenchman Arrested After Hacking Into Obama's Twitter Accounts</ddb:entrytitle>      <ddb:incidentdescription>A Frenchman will face trial after hacking into Twitter accounts, including that of U.S President Barack Obama, a French prosecutor said.&#13;&#10;&#13;&#10;The 24-year-old man from central France was arrested on Tuesday and could face up to two years in prison in France for fraudulent access to a computer system. The arrest followed a joint operation between the Federal Bureau of Investigation and the French police, according to French state prosecutor Jean-Yves Coquillat.&#13;&#10;&#13;&#10;The man, whose name hasn't been release, is charged with having hacked into the Twitter Inc. social-networking accounts of famous people. He did this in April 2009 after posing as a site administrator, said Mr. Coquillat. As well as Mr. Obama's account, he hacked into that of singer Britney Spears, he said.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference>http://online.wsj.com/article/SB10001424052748704094104575143391819054502.html</ddb:reference>      <ddb:whidid>2010-42</ddb:whidid>    </item>    <item>      <title>WHID 2010-38: Cross-Site Scripting through Flash in Gmail Based Services</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=44107</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-38: Cross-Site Scripting through Flash in Gmail Based Services&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-38&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;March 22, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;IBM Security Researcher outlines the XSS vuln he found that exploits a Flash upload file movie by passing Javascript within external parameters.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Information Services&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://blog.watchfire.com/wfblog/2010/03/cross-site-scripting-through-flash-in-gmail-based-services.html&quot;&gt;http://blog.watchfire.com/wfblog/2010/03/cross-site-scripting-through-flash-in-gmail-based-services.html&lt;/a></description>      <pubDate>Mon, 24 May 2010 13:54:42 -0400</pubDate>      <ddb:attackedentityfield>Information Services</ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>March 22, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-38: Cross-Site Scripting through Flash in Gmail Based Services</ddb:entrytitle>      <ddb:incidentdescription>IBM Security Researcher outlines the XSS vuln he found that exploits a Flash upload file movie by passing Javascript within external parameters.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference>http://blog.watchfire.com/wfblog/2010/03/cross-site-scripting-through-flash-in-gmail-based-services.html</ddb:reference>      <ddb:whidid>2010-38</ddb:whidid>    </item>    <item>      <title>WHID 2010-21: Wiseguys Tickets charged with hacking into Ticketmaster, LiveNation to illegally grab best seats</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=42939</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2010-21: Wiseguys Tickets charged with hacking into Ticketmaster, LiveNation to illegally grab best seats&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2010-21&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;March 1, 2010&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Loss of Sales&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;This entry is related to WHID 2008-48 (http://www.xiom.com/whid-2008-48) however it expands beyond only TicketMaster to include LiveNation.&lt;br&gt;Prosecutors said the men hired a hacker in Bulgaria  to program a way around the &quot;CAPTCHA&quot; technology that requires ticket buyers to read and retype two distorted random words to prove they are people, not a computer program.  In a spectacular irony, the defendents managed to take a process meant to distinguish between a human and a machine - and automate it.  The indictment said they even programmed their bots to make mistakes so they would appear to be human ticket buyers.  When the bots swarmed a Web site, they were able to fill out the CAPTCHA fields in a twinkling, beating any real human buyers.&lt;br&gt;Read more: http://www.nydailynews.com/news/ny_crime/2010/03/01/2010-03-01_wiseguys_tickets_charged_with_hacking_into_ticketmaster_livenation_to_illegally_.html?page=1#ixzz0iumX65AV&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;Bulgaria&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Entertainment&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://www.nydailynews.com/news/ny_crime/2010/03/01/2010-03-01_wiseguys_tickets_charged_with_hacking_into_ticketmaster_livenation_to_illegally_.html&quot;&gt;http://www.nydailynews.com/news/ny_crime/2010/03/01/2010-03-01_wiseguys_tickets_charged_with_hacking_into_ticketmaster_livenation_to_illegally_.html&lt;/a></description>      <pubDate>Mon, 24 May 2010 13:54:42 -0400</pubDate>      <ddb:attackedentityfield>Entertainment</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography>Bulgaria</ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>March 1, 2010</ddb:dateoccured>      <ddb:entrytitle>WHID 2010-21: Wiseguys Tickets charged with hacking into Ticketmaster, LiveNation to illegally grab best seats</ddb:entrytitle>      <ddb:incidentdescription>This entry is related to WHID 2008-48 (http://www.xiom.com/whid-2008-48) however it expands beyond only TicketMaster to include LiveNation.&#13;&#10;&#13;&#10;Prosecutors said the men hired a hacker in Bulgaria  to program a way around the &quot;CAPTCHA&quot; technology that requires ticket buyers to read and retype two distorted random words to prove they are people, not a computer program.  In a spectacular irony, the defendents managed to take a process meant to distinguish between a human and a machine - and automate it.  The indictment said they even programmed their bots to make mistakes so they would appear to be human ticket buyers.  When the bots swarmed a Web site, they were able to fill out the CAPTCHA fields in a twinkling, beating any real human buyers.&#13;&#10;&#13;&#10;Read more: http://www.nydailynews.com/news/ny_crime/2010/03/01/2010-03-01_wiseguys_tickets_charged_with_hacking_into_ticketmaster_livenation_to_illegally_.html?page=1#ixzz0iumX65AV&#13;
</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Loss of Sales</ddb:outcome>      <ddb:reference>http://www.nydailynews.com/news/ny_crime/2010/03/01/2010-03-01_wiseguys_tickets_charged_with_hacking_into_ticketmaster_livenation_to_illegally_.html</ddb:reference>      <ddb:whidid>2010-21</ddb:whidid>    </item>    <item>      <title>WHID 2009-46: Clickjacking Attack Hit Facebook</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=42506</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2009-46: Clickjacking Attack Hit Facebook&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2009-46&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;December 23, 2009&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Worm&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;The Facebook clickjacking assault appeared as a comment posted to the account of a user along with a photograph, which enticed him to hit it. On clicking the link, it led the user to a web-page, which pretended to be a CAPTCHA test. It also prompted him to hit a blue colored button namely &quot;Share&quot; embedded in the Facebook web-page.&lt;br&gt;But on clicking it, the victim was diverted to a YouTube video appeared on his Facebook account. Consequently, the victim and his contacts were infected. Krzysztof Kotowicz, a freelance security researcher, states that presently the attack is effective merely in Chrome and Firefox Web-browsers, as reported by Help Net Security on December 22, 2009.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Web 2.0&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://www.spamfighter.com/News-13684-Clickjacking-Attack-Hit-Facebook.htm&quot;&gt;http://www.spamfighter.com/News-13684-Clickjacking-Attack-Hit-Facebook.htm&lt;/a></description>      <pubDate>Wed, 16 Jun 2010 14:13:01 -0400</pubDate>      <ddb:attackedentityfield>Web 2.0</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>December 23, 2009</ddb:dateoccured>      <ddb:entrytitle>WHID 2009-46: Clickjacking Attack Hit Facebook</ddb:entrytitle>      <ddb:incidentdescription>The Facebook clickjacking assault appeared as a comment posted to the account of a user along with a photograph, which enticed him to hit it. On clicking the link, it led the user to a web-page, which pretended to be a CAPTCHA test. It also prompted him to hit a blue colored button namely &quot;Share&quot; embedded in the Facebook web-page.&#13;&#10;&#13;&#10;But on clicking it, the victim was diverted to a YouTube video appeared on his Facebook account. Consequently, the victim and his contacts were infected. Krzysztof Kotowicz, a freelance security researcher, states that presently the attack is effective merely in Chrome and Firefox Web-browsers, as reported by Help Net Security on December 22, 2009.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Worm</ddb:outcome>      <ddb:reference>http://www.spamfighter.com/News-13684-Clickjacking-Attack-Hit-Facebook.htm</ddb:reference>      <ddb:whidid>2009-46</ddb:whidid>    </item>    <item>      <title>WHID 2007-23: Office of Nation&amp;#039;s Top Spy Inadvertently Reveals Key to Classified National Intel Budget</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34377</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2007-23: Office of Nation&amp;#039;s Top Spy Inadvertently Reveals Key to Classified National Intel Budget&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2007-23&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;June 12, 2007&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;A spreadsheet left on the web site of the US office of national intelligence includes secret information on the total budget of the US intelligence. Interestingly the not all the required information appears in the document, but combined with other pieces of information made available prior, the total number can be calculated.&lt;br&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;This is a very interesting example of the sensitivity of partial data or small pieces of information and not just the big secrets.&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.thespywhobilledme.com/the_spy_who_billed_me/2007/06/exclusive_offic.html&quot;&gt;Office of Nation's Top Spy Inadvertently Reveals Key to Classified National Intel Budget&lt;/a&gt; [The Spy Who Billed Me, Jun 3 2007]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Security &amp;amp; Law Enforcement&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA</description>      <pubDate>Wed, 16 Jun 2010 15:58:32 -0400</pubDate>      <ddb:attackedentityfield>Security &amp;amp; Law Enforcement</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>June 12, 2007</ddb:dateoccured>      <ddb:entrytitle>WHID 2007-23: Office of Nation&amp;#039;s Top Spy Inadvertently Reveals Key to Classified National Intel Budget</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;A spreadsheet left on the web site of the US office of national intelligence includes secret information on the total budget of the US intelligence. Interestingly the not all the required information appears in the document, but combined with other pieces of information made available prior, the total number can be calculated.&#13;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;This is a very interesting example of the sensitivity of partial data or small pieces of information and not just the big secrets.&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.thespywhobilledme.com/the_spy_who_billed_me/2007/06/exclusive_offic.html&quot;&gt;Office of Nation's Top Spy Inadvertently Reveals Key to Classified National Intel Budget&lt;/a&gt; [The Spy Who Billed Me, Jun 3 2007]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2007-23</ddb:whidid>    </item>    <item>      <title>WHID 2007-24: Hackers access personal info on faculty members at Univ. of Virginia</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34382</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2007-24: Hackers access personal info on faculty members at Univ. of Virginia&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2007-24&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;June 12, 2007&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;An undisclosed vulnerability in a web application at the University of Virginia allowed hackers to access names, social security numbers and birth dates of faculty members from May 2005 until April of 2007. Approximately 5700 records where stolen in 54 distinct break-ins.&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;taxonomyId=17&amp;amp;articleId=9024279&amp;amp;intsrc=hm_topic&quot;&gt;Hackers access personal info on faculty members at Univ. of Virginia&lt;/a&gt; [Computer World, Jun 11 2007]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.informationweek.com/software/showArticle.jhtml?articleID=199903218&amp;amp;cid=RSSfeed_IWK_News&quot;&gt;Two Universities Hit By Security Breaches&lt;/a&gt; [Information Week, Jun 11 2007]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.virginia.edu/uvatoday/newsRelease.php?id=2217&quot;&gt;U.Va. Faculty Names, SSN Security Breach&lt;/a&gt; [Univ. of Va., Jun 8 2007]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Education&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA</description>      <pubDate>Wed, 16 Jun 2010 15:57:55 -0400</pubDate>      <ddb:attackedentityfield>Education</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>June 12, 2007</ddb:dateoccured>      <ddb:entrytitle>WHID 2007-24: Hackers access personal info on faculty members at Univ. of Virginia</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;An undisclosed vulnerability in a web application at the University of Virginia allowed hackers to access names, social security numbers and birth dates of faculty members from May 2005 until April of 2007. Approximately 5700 records where stolen in 54 distinct break-ins.&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;taxonomyId=17&amp;amp;articleId=9024279&amp;amp;intsrc=hm_topic&quot;&gt;Hackers access personal info on faculty members at Univ. of Virginia&lt;/a&gt; [Computer World, Jun 11 2007]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.informationweek.com/software/showArticle.jhtml?articleID=199903218&amp;amp;cid=RSSfeed_IWK_News&quot;&gt;Two Universities Hit By Security Breaches&lt;/a&gt; [Information Week, Jun 11 2007]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.virginia.edu/uvatoday/newsRelease.php?id=2217&quot;&gt;U.Va. Faculty Names, SSN Security Breach&lt;/a&gt; [Univ. of Va., Jun 8 2007]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2007-24</ddb:whidid>    </item>    <item>      <title>WHID 2007-25: University of Iowa Molecular and Cellular Biology Program Security Incident</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34387</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2007-25: University of Iowa Molecular and Cellular Biology Program Security Incident&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2007-25&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;June 12, 2007&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Approximately 1100 students and faculty members' personal information records which includes social security numbers were exposed by a vulnerable web application at the Molecular and Cellular Biology program at the University of Iowa. The report suggests that the application was actually compromised.&lt;/p&gt;&lt;br&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://news-releases.uiowa.edu/2007/june/060807website-breach.html&quot;&gt;UI Notifies Graduate Program Students, Faculty About Security Breach&lt;/a&gt; [Univ. Of Iowa, May 19 2007]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.informationweek.com/news/showArticle.jhtml?articleID=199903218&quot;&gt;Two Universities Hit By Security Breaches&lt;/a&gt; [Information Week, Jun 11 2007]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Education&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA</description>      <pubDate>Wed, 16 Jun 2010 15:57:27 -0400</pubDate>      <ddb:attackedentityfield>Education</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>June 12, 2007</ddb:dateoccured>      <ddb:entrytitle>WHID 2007-25: University of Iowa Molecular and Cellular Biology Program Security Incident</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Approximately 1100 students and faculty members' personal information records which includes social security numbers were exposed by a vulnerable web application at the Molecular and Cellular Biology program at the University of Iowa. The report suggests that the application was actually compromised.&lt;/p&gt;&#13;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://news-releases.uiowa.edu/2007/june/060807website-breach.html&quot;&gt;UI Notifies Graduate Program Students, Faculty About Security Breach&lt;/a&gt; [Univ. Of Iowa, May 19 2007]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.informationweek.com/news/showArticle.jhtml?articleID=199903218&quot;&gt;Two Universities Hit By Security Breaches&lt;/a&gt; [Information Week, Jun 11 2007]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2007-25</ddb:whidid>    </item>    <item>      <title>WHID 2007-26:  $1,000,000 CNBC stock trading contest hacked</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34392</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2007-26:  $1,000,000 CNBC stock trading contest hacked&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2007-26&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;June 12, 2007&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Disinformation&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;The CNBC stock trading reality TV show was even more real than contenders thought it would be.  It seems that players learned to cheat the game by opening a browser form to by a stock before closing and issuing the transaction, at the set price, only after closing, when more information is already available.&lt;br&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;The interesting anecdote is that the person who discovered the issue has used a different, but also questionable technique of maintaining a very large number of portfolios automatically managed by automated programs using the fact that the game allowed a user to have any number of portfolios but only the best one is counted. Kosher, but stinks.&lt;br&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;This story remind &lt;a href=&quot; http://www.webappsec.org/projects/whid/list_id_2005-36.shtml&quot;&gt;an older story&lt;/a&gt; about  a predictable delay in a poker game that enabled gamblers to beat the house.&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://jeremiahgrossman.blogspot.com/2007/06/1000000-cnbc-stock-trading-contest.html&quot;&gt; $1,000,000 CNBC stock trading contest hacked&lt;/a&gt; [ Jeremiah Grossman, Jun 11 2007]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.businessweek.com/bwdaily/dnflash/content/jun2007/db20070607_007145.htm&quot;&gt;CNBC's Easy Money&lt;/a&gt; [Business Week, Jun 7 2007]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Media&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA</description>      <pubDate>Wed, 16 Jun 2010 15:56:58 -0400</pubDate>      <ddb:attackedentityfield>Media</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>June 12, 2007</ddb:dateoccured>      <ddb:entrytitle>WHID 2007-26:  $1,000,000 CNBC stock trading contest hacked</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;The CNBC stock trading reality TV show was even more real than contenders thought it would be.  It seems that players learned to cheat the game by opening a browser form to by a stock before closing and issuing the transaction, at the set price, only after closing, when more information is already available.&#13;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;The interesting anecdote is that the person who discovered the issue has used a different, but also questionable technique of maintaining a very large number of portfolios automatically managed by automated programs using the fact that the game allowed a user to have any number of portfolios but only the best one is counted. Kosher, but stinks.&#13;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;This story remind &lt;a href=&quot; http://www.webappsec.org/projects/whid/list_id_2005-36.shtml&quot;&gt;an older story&lt;/a&gt; about  a predictable delay in a poker game that enabled gamblers to beat the house.&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://jeremiahgrossman.blogspot.com/2007/06/1000000-cnbc-stock-trading-contest.html&quot;&gt; $1,000,000 CNBC stock trading contest hacked&lt;/a&gt; [ Jeremiah Grossman, Jun 11 2007]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.businessweek.com/bwdaily/dnflash/content/jun2007/db20070607_007145.htm&quot;&gt;CNBC's Easy Money&lt;/a&gt; [Business Week, Jun 7 2007]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Disinformation</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2007-26</ddb:whidid>    </item>    <item>      <title>WHID 2007-27: Files From Google On the Streets</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34398</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2007-27: Files From Google On the Streets&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2007-27&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;June 12, 2007&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Google left some files at the wrong place at the wrong time. These files includes, surprisingly, database connection strings, including a user name and a password. Hardly news, but this time it is Google.&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.0x000000.com/?i=319&quot;&gt;Breaking News: Files From Google On the Streets&lt;/a&gt; [The Hacker Webzine, May 30 2007]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Internet&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA</description>      <pubDate>Wed, 16 Jun 2010 15:55:41 -0400</pubDate>      <ddb:attackedentityfield>Internet</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>June 12, 2007</ddb:dateoccured>      <ddb:entrytitle>WHID 2007-27: Files From Google On the Streets</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Google left some files at the wrong place at the wrong time. These files includes, surprisingly, database connection strings, including a user name and a password. Hardly news, but this time it is Google.&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.0x000000.com/?i=319&quot;&gt;Breaking News: Files From Google On the Streets&lt;/a&gt; [The Hacker Webzine, May 30 2007]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2007-27</ddb:whidid>    </item>    <item>      <title>WHID 2007-22: Hacking of CM&amp;#039;s website: Interpol&amp;#039;s help sought</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34372</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2007-22: Hacking of CM&amp;#039;s website: Interpol&amp;#039;s help sought&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2007-22&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;June 12, 2007&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Defacement&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;The web site of the chief minister of Kerala (an Indian State) was hacked and defaced. The local police has contacted the Interpol to help in finding who is behind the web site hacking.&lt;/p&gt;&lt;br&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.newindpress.com/NewsItems.asp?ID=IEO20070609142217&amp;amp;Page=O&amp;amp;Title=Thiruvananthapuram&amp;amp;Topic=0&quot;&gt;Hacking of CM's website: Interpol's help sought&lt;/a&gt; [NewindPress, Jun 10 2007]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Government&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;India</description>      <pubDate>Wed, 16 Jun 2010 15:58:56 -0400</pubDate>      <ddb:attackedentityfield>Government</ddb:attackedentityfield>      <ddb:attackedentitygeography>India</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>June 12, 2007</ddb:dateoccured>      <ddb:entrytitle>WHID 2007-22: Hacking of CM&amp;#039;s website: Interpol&amp;#039;s help sought</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;The web site of the chief minister of Kerala (an Indian State) was hacked and defaced. The local police has contacted the Interpol to help in finding who is behind the web site hacking.&lt;/p&gt;&#13;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.newindpress.com/NewsItems.asp?ID=IEO20070609142217&amp;amp;Page=O&amp;amp;Title=Thiruvananthapuram&amp;amp;Topic=0&quot;&gt;Hacking of CM's website: Interpol's help sought&lt;/a&gt; [NewindPress, Jun 10 2007]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Defacement</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2007-22</ddb:whidid>    </item>    <item>      <title>WHID 2007-21: Belgian Defense Ministry site defaced by Turks</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34367</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2007-21: Belgian Defense Ministry site defaced by Turks&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2007-21&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;May 17, 2007&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Defacement&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;The site of the Belgian Defense Ministry was defaced by Turks who protested a pro-Kurdish remarks by the Belgian government.&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.armenian.ch/forum/phpBB2/viewtopic.php?=&amp;amp;p=10536&quot;&gt;Belgian defense ministry web site remains off line after weekend hacking&lt;/a&gt; [Associated Press, Jan 15 2007]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;Turkey&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Security &amp;amp; Law Enforcement&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;Belgium</description>      <pubDate>Wed, 16 Jun 2010 15:58:58 -0400</pubDate>      <ddb:attackedentityfield>Security &amp;amp; Law Enforcement</ddb:attackedentityfield>      <ddb:attackedentitygeography>Belgium</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography>Turkey</ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>May 17, 2007</ddb:dateoccured>      <ddb:entrytitle>WHID 2007-21: Belgian Defense Ministry site defaced by Turks</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;The site of the Belgian Defense Ministry was defaced by Turks who protested a pro-Kurdish remarks by the Belgian government.&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.armenian.ch/forum/phpBB2/viewtopic.php?=&amp;amp;p=10536&quot;&gt;Belgian defense ministry web site remains off line after weekend hacking&lt;/a&gt; [Associated Press, Jan 15 2007]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Defacement</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2007-21</ddb:whidid>    </item>    <item>      <title>WHID 2007-28: US Embassy probes hacking of online visa appointment system</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34403</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2007-28: US Embassy probes hacking of online visa appointment system&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2007-28&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;June 17, 2007&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Disinformation&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;If you live in a country from which you need a Visa to get to the states, you knew this would happen. The US online Visa appointment system is very open. Indeed too open. Someone in Jamaica took advantage of this to pre-allocate appointments.&lt;br&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;While this might be classified as a business process design flaw, isn't security also about this?&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.rjr94fm.com/news/story.php?category=2&amp;amp;story=36819&quot;&gt;US Embassy probes hacking of online visa appointment system&lt;/a&gt; [RJR 94FM, Jun 13 2007]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Government</description>      <pubDate>Wed, 16 Jun 2010 16:05:00 -0400</pubDate>      <ddb:attackedentityfield>Government</ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>June 17, 2007</ddb:dateoccured>      <ddb:entrytitle>WHID 2007-28: US Embassy probes hacking of online visa appointment system</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;If you live in a country from which you need a Visa to get to the states, you knew this would happen. The US online Visa appointment system is very open. Indeed too open. Someone in Jamaica took advantage of this to pre-allocate appointments.&#13;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;While this might be classified as a business process design flaw, isn't security also about this?&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.rjr94fm.com/news/story.php?category=2&amp;amp;story=36819&quot;&gt;US Embassy probes hacking of online visa appointment system&lt;/a&gt; [RJR 94FM, Jun 13 2007]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Disinformation</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2007-28</ddb:whidid>    </item>    <item>      <title>WHID 2007-29: Teen arrested for hacking Belgian police website</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34409</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2007-29: Teen arrested for hacking Belgian police website&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2007-29&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;June 26, 2007&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Defacement&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;As you may know, defacement usually do not find their way to WHID, especially if the method used is not known. However, since in this case the victim was the Belgian police, I though it is worth including.&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.physorg.com/news101998423.html&quot;&gt;Teen arrested for hacking Belgian police website&lt;/a&gt; [Physorg.org, Jun 25 2007]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Security &amp;amp; Law Enforcement&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;Belgium</description>      <pubDate>Wed, 16 Jun 2010 15:53:25 -0400</pubDate>      <ddb:attackedentityfield>Security &amp;amp; Law Enforcement</ddb:attackedentityfield>      <ddb:attackedentitygeography>Belgium</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>June 26, 2007</ddb:dateoccured>      <ddb:entrytitle>WHID 2007-29: Teen arrested for hacking Belgian police website</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;As you may know, defacement usually do not find their way to WHID, especially if the method used is not known. However, since in this case the victim was the Belgian police, I though it is worth including.&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.physorg.com/news101998423.html&quot;&gt;Teen arrested for hacking Belgian police website&lt;/a&gt; [Physorg.org, Jun 25 2007]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Defacement</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2007-29</ddb:whidid>    </item>    <item>      <title>WHID 2007-20: Pirate Bay breach leaks database</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34362</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2007-20: Pirate Bay breach leaks database&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2007-20&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;May 14, 2007&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Private Bay is a BitTorrent information exchange blog site. Hackers used an SQL Injection vulnerability in the web site to steal 1.6 million users and passwords of the site. At least the passwords where hashed, which means that the hacker would need a cracking software and only the lame passwords will be found.&lt;br /&gt;This incident highlights the Web authentication problem. Just think how many of those users use the same username and password in many other sites.&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.securityfocus.com/brief/499&quot;&gt;Pirate Bay breach leaks database&lt;/a&gt; [Security Focus, May 14 2007]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://thepiratebay.org/blog/68&quot;&gt;User data stolen but not unsecured&lt;/a&gt; [Private Bay, May 11 2007]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.theinquirer.net/default.aspx?article=39604&quot;&gt;Pirate Bay says stolen database safe&lt;/a&gt; [The Inquierer, May 14 2007]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Internet&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;Sweden</description>      <pubDate>Wed, 16 Jun 2010 15:59:06 -0400</pubDate>      <ddb:attackedentityfield>Internet</ddb:attackedentityfield>      <ddb:attackedentitygeography>Sweden</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>May 14, 2007</ddb:dateoccured>      <ddb:entrytitle>WHID 2007-20: Pirate Bay breach leaks database</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Private Bay is a BitTorrent information exchange blog site. Hackers used an SQL Injection vulnerability in the web site to steal 1.6 million users and passwords of the site. At least the passwords where hashed, which means that the hacker would need a cracking software and only the lame passwords will be found.&lt;br /&gt;This incident highlights the Web authentication problem. Just think how many of those users use the same username and password in many other sites.&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.securityfocus.com/brief/499&quot;&gt;Pirate Bay breach leaks database&lt;/a&gt; [Security Focus, May 14 2007]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://thepiratebay.org/blog/68&quot;&gt;User data stolen but not unsecured&lt;/a&gt; [Private Bay, May 11 2007]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.theinquirer.net/default.aspx?article=39604&quot;&gt;Pirate Bay says stolen database safe&lt;/a&gt; [The Inquierer, May 14 2007]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2007-20</ddb:whidid>    </item>    <item>      <title>WHID 2007-19: Hacker accessed data at University of Missouri</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34357</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2007-19: Hacker accessed data at University of Missouri&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2007-19&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;May 9, 2007&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;A report within the help desk system used to track the status of open service calls created a file that was a accessible to everyone. A hacker abused the problem to get information regarding 22,000 current and former students.&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.msnbc.msn.com/id/18561756/&quot;&gt;Hacker accessed data at University of Missouri&lt;/a&gt; [MSNBC, May 8 2007]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;taxonomyName=cybercrime_and_hacking&amp;amp;articleId=9018982&amp;amp;taxonomyId=82&amp;amp;intsrc=kc_top&quot;&gt;One-at-a-time hacker grabs 22,000 IDs from Univ. of Missouri&lt;/a&gt; [Computerworld, May 9 2007]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://doit.missouri.edu/computersecurity/&quot;&gt;May 2007 Security Incident&lt;/a&gt; [University of Missouri, May 8 2007]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Education&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA</description>      <pubDate>Wed, 16 Jun 2010 15:59:34 -0400</pubDate>      <ddb:attackedentityfield>Education</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>May 9, 2007</ddb:dateoccured>      <ddb:entrytitle>WHID 2007-19: Hacker accessed data at University of Missouri</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;A report within the help desk system used to track the status of open service calls created a file that was a accessible to everyone. A hacker abused the problem to get information regarding 22,000 current and former students.&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.msnbc.msn.com/id/18561756/&quot;&gt;Hacker accessed data at University of Missouri&lt;/a&gt; [MSNBC, May 8 2007]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;taxonomyName=cybercrime_and_hacking&amp;amp;articleId=9018982&amp;amp;taxonomyId=82&amp;amp;intsrc=kc_top&quot;&gt;One-at-a-time hacker grabs 22,000 IDs from Univ. of Missouri&lt;/a&gt; [Computerworld, May 9 2007]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://doit.missouri.edu/computersecurity/&quot;&gt;May 2007 Security Incident&lt;/a&gt; [University of Missouri, May 8 2007]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2007-19</ddb:whidid>    </item>    <item>      <title>WHID 2007-30: Microsoft UK site defaced</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34414</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2007-30: Microsoft UK site defaced&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2007-30&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;July 1, 2007&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Defacement&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Yet another defacement, but with a very high profile target, and a detailed description of the attack which took advantage of an SQL injection vulnerability. The report even includes a video recording of the attack.&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.pcworld.com/article/id,133583-c,hackers/article.html&quot;&gt;Microsoft.co.uk Succumbs to SQL Injection Attack&lt;/a&gt; [PC world, Jun 29 2007]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.zone-h.org/content/view/14780/31/&quot;&gt;Microsoft Defaced, again!&lt;/a&gt; [Zone-H, Jun 27 2007]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.unbase.com/n/5725974396&quot;&gt;Video Recording of the Attack&lt;/a&gt; [Hacker, Jun 27 2007]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Technology&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;UK</description>      <pubDate>Wed, 16 Jun 2010 15:53:14 -0400</pubDate>      <ddb:attackedentityfield>Technology</ddb:attackedentityfield>      <ddb:attackedentitygeography>UK</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>July 1, 2007</ddb:dateoccured>      <ddb:entrytitle>WHID 2007-30: Microsoft UK site defaced</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Yet another defacement, but with a very high profile target, and a detailed description of the attack which took advantage of an SQL injection vulnerability. The report even includes a video recording of the attack.&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.pcworld.com/article/id,133583-c,hackers/article.html&quot;&gt;Microsoft.co.uk Succumbs to SQL Injection Attack&lt;/a&gt; [PC world, Jun 29 2007]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.zone-h.org/content/view/14780/31/&quot;&gt;Microsoft Defaced, again!&lt;/a&gt; [Zone-H, Jun 27 2007]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.unbase.com/n/5725974396&quot;&gt;Video Recording of the Attack&lt;/a&gt; [Hacker, Jun 27 2007]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Defacement</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2007-30</ddb:whidid>    </item>    <item>      <title>WHID 2007-31: Hackers Make Off With Personal Info On Applicants At UC Davis</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34419</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2007-31: Hackers Make Off With Personal Info On Applicants At UC Davis&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2007-31&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;July 1, 2007&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Somebody snitched names, social security number and birth dates of approximately 1500 students at the vet school of UC Davis. Indication is that the web application used by the students was as fault. The school's web site described the incident as a result of &quot;the computer attacker being able to manipulate a university computing application to accept unauthorized commands&quot;. A disgruntled cow?&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.informationweek.com/industries/showArticle.jhtml?articleID=200001374&quot;&gt;Hackers Make Off With Personal Info On Applicants At UC Davis&lt;/a&gt; [Information Week, Jun 28 2007]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.vetmed.ucdavis.edu/computer%5Fsecurity/&quot;&gt;UC David Vet School Web Site&lt;/a&gt; [UC Davis, Jun 28 2007]&lt;/li&gt;&lt;br&gt;&lt;/ul></description>      <pubDate>Wed, 16 Jun 2010 15:53:13 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>July 1, 2007</ddb:dateoccured>      <ddb:entrytitle>WHID 2007-31: Hackers Make Off With Personal Info On Applicants At UC Davis</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Somebody snitched names, social security number and birth dates of approximately 1500 students at the vet school of UC Davis. Indication is that the web application used by the students was as fault. The school's web site described the incident as a result of &quot;the computer attacker being able to manipulate a university computing application to accept unauthorized commands&quot;. A disgruntled cow?&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.informationweek.com/industries/showArticle.jhtml?articleID=200001374&quot;&gt;Hackers Make Off With Personal Info On Applicants At UC Davis&lt;/a&gt; [Information Week, Jun 28 2007]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.vetmed.ucdavis.edu/computer%5Fsecurity/&quot;&gt;UC David Vet School Web Site&lt;/a&gt; [UC Davis, Jun 28 2007]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2007-31</ddb:whidid>    </item>    <item>      <title>WHID 2007-18: Microsoft.com defaced</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34352</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2007-18: Microsoft.com defaced&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2007-18&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;May 6, 2007&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Defacement&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;This incredible story from our friends at Zone-H shed light on one of those defacement attacks, which usually go unexplained. This time an infamous Saudi-Arabian hacker abused SQL injection vulnerability in Internet Explorer Administration Kit web site. And guess what type of SQL injection: A login form SQL injection!&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.zone-h.org/content/view/14734/31/&quot;&gt;Microsoft.com defaced&lt;/a&gt; [zone-H, May 3 2007]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;Saudi Arabia&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Technology&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA</description>      <pubDate>Wed, 16 Jun 2010 15:59:41 -0400</pubDate>      <ddb:attackedentityfield>Technology</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography>Saudi Arabia</ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>May 6, 2007</ddb:dateoccured>      <ddb:entrytitle>WHID 2007-18: Microsoft.com defaced</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;This incredible story from our friends at Zone-H shed light on one of those defacement attacks, which usually go unexplained. This time an infamous Saudi-Arabian hacker abused SQL injection vulnerability in Internet Explorer Administration Kit web site. And guess what type of SQL injection: A login form SQL injection!&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.zone-h.org/content/view/14734/31/&quot;&gt;Microsoft.com defaced&lt;/a&gt; [zone-H, May 3 2007]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Defacement</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2007-18</ddb:whidid>    </item>    <item>      <title>WHID 2007-32: XSS vulnerability on various German online banking sites</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34424</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2007-32: XSS vulnerability on various German online banking sites&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2007-32&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;July 1, 2007&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;I seldom add disclosures anymore to WHID, even less XSS disclosures, but since this time they were discovered in banking sites, I thought it was worth it. After all, too many times people think that application vulnerabilities are found only at less &quot;serious&quot; or less &quot;important&quot; web sites where no real damage can occur.&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://seclists.org/fulldisclosure/2007/May/0274.html&quot;&gt;XSS vulnerability on various german online banking sites&lt;/a&gt; [Full Disclosure, May 17 2007]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Finance&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;Germany</description>      <pubDate>Wed, 16 Jun 2010 15:52:43 -0400</pubDate>      <ddb:attackedentityfield>Finance</ddb:attackedentityfield>      <ddb:attackedentitygeography>Germany</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>July 1, 2007</ddb:dateoccured>      <ddb:entrytitle>WHID 2007-32: XSS vulnerability on various German online banking sites</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;I seldom add disclosures anymore to WHID, even less XSS disclosures, but since this time they were discovered in banking sites, I thought it was worth it. After all, too many times people think that application vulnerabilities are found only at less &quot;serious&quot; or less &quot;important&quot; web sites where no real damage can occur.&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://seclists.org/fulldisclosure/2007/May/0274.html&quot;&gt;XSS vulnerability on various german online banking sites&lt;/a&gt; [Full Disclosure, May 17 2007]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2007-32</ddb:whidid>    </item>    <item>      <title>WHID 2007-33: THAILAND: ICT Ministry website sabotaged by hacker</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34429</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2007-33: THAILAND: ICT Ministry website sabotaged by hacker&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2007-33&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;July 22, 2007&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Defacement&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;While defacements are usually not the bread and butter of this database, when it hits an important government site, especially of a ministry in charge of information technology, it is worth mentioning it.&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.asiamedia.ucla.edu/article.asp?parentid=74329&quot;&gt;THAILAND: ICT Ministry website sabotaged by hacker&lt;/a&gt; [Bangkok Times, Jul 20 2007]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://64.233.183.104/search?q=cache:4emUUaBp2L8J:www.asiamedia.ucla.edu/article.asp%3Fparentid%3D74329+www.asiamedia.ucla.edu/article.asp%3Fparentid%3D74329&amp;amp;hl=en&amp;amp;ct=clnk&amp;amp;cd=1&amp;amp;client=firefox-a&quot;&gt;Cached Version&lt;/a&gt; [Bangkok Times (Google Cache), Jul 20 2008]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Government&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;Thailand</description>      <pubDate>Wed, 16 Jun 2010 15:52:26 -0400</pubDate>      <ddb:attackedentityfield>Government</ddb:attackedentityfield>      <ddb:attackedentitygeography>Thailand</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>July 22, 2007</ddb:dateoccured>      <ddb:entrytitle>WHID 2007-33: THAILAND: ICT Ministry website sabotaged by hacker</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;While defacements are usually not the bread and butter of this database, when it hits an important government site, especially of a ministry in charge of information technology, it is worth mentioning it.&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.asiamedia.ucla.edu/article.asp?parentid=74329&quot;&gt;THAILAND: ICT Ministry website sabotaged by hacker&lt;/a&gt; [Bangkok Times, Jul 20 2007]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://64.233.183.104/search?q=cache:4emUUaBp2L8J:www.asiamedia.ucla.edu/article.asp%3Fparentid%3D74329+www.asiamedia.ucla.edu/article.asp%3Fparentid%3D74329&amp;amp;hl=en&amp;amp;ct=clnk&amp;amp;cd=1&amp;amp;client=firefox-a&quot;&gt;Cached Version&lt;/a&gt; [Bangkok Times (Google Cache), Jul 20 2008]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Defacement</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2007-33</ddb:whidid>    </item>    <item>      <title>WHID 2007-17: Big Brother&amp;#039;s big bother</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34347</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2007-17: Big Brother&amp;#039;s big bother&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2007-17&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;April 26, 2007&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;The site of &quot;Big Brother&quot;, a reality show in Australia issued duplicate session IDs to different users since the session ID pool was exhausted. Naturally, the 2nd person to get the same session ID got to see all the details of the 1st one!&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.theage.com.au/news/tv--radio/porn-privacy-glitches-hit-big-bro/2007/04/23/1177180548617.html&quot;&gt;Porn and privacy: Big Brother's big bother&lt;/a&gt; [The Age, Apr 23 2007]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Media&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;Australia</description>      <pubDate>Wed, 16 Jun 2010 16:02:43 -0400</pubDate>      <ddb:attackedentityfield>Media</ddb:attackedentityfield>      <ddb:attackedentitygeography>Australia</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>April 26, 2007</ddb:dateoccured>      <ddb:entrytitle>WHID 2007-17: Big Brother&amp;#039;s big bother</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;The site of &quot;Big Brother&quot;, a reality show in Australia issued duplicate session IDs to different users since the session ID pool was exhausted. Naturally, the 2nd person to get the same session ID got to see all the details of the 1st one!&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.theage.com.au/news/tv--radio/porn-privacy-glitches-hit-big-bro/2007/04/23/1177180548617.html&quot;&gt;Porn and privacy: Big Brother's big bother&lt;/a&gt; [The Age, Apr 23 2007]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2007-17</ddb:whidid>    </item>    <item>      <title>WHID 2007-34: Fox News leaks secret files</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34434</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2007-34: Fox News leaks secret files&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2007-34&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;July 25, 2007&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Fox News left non public files on a directory accessible to everyone on their web server.&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.0x000000.com/?i=398&quot;&gt;Foxnews File Disclosure&lt;/a&gt; [The Hacker Webzine, Jul 23 2007]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.theinquirer.net/default.aspx?article=41187&quot;&gt;Fox News leaks secret files&lt;/a&gt; [The Inquierer, Jul 24 2007]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Media&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA</description>      <pubDate>Wed, 16 Jun 2010 15:52:08 -0400</pubDate>      <ddb:attackedentityfield>Media</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>July 25, 2007</ddb:dateoccured>      <ddb:entrytitle>WHID 2007-34: Fox News leaks secret files</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Fox News left non public files on a directory accessible to everyone on their web server.&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.0x000000.com/?i=398&quot;&gt;Foxnews File Disclosure&lt;/a&gt; [The Hacker Webzine, Jul 23 2007]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.theinquirer.net/default.aspx?article=41187&quot;&gt;Fox News leaks secret files&lt;/a&gt; [The Inquierer, Jul 24 2007]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2007-34</ddb:whidid>    </item>    <item>      <title>WHID 2007-16: USDA admits data breach, thousands of social security numbers revealed</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34342</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2007-16: USDA admits data breach, thousands of social security numbers revealed&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2007-16&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;April 23, 2007&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Details about 63,000 loans granted to farmers by USDA (The US department of agriculture) where posted online by mistake.&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.axcessnews.com/index.php/articles/show/id/10832&quot;&gt;USDA admits data breach, thousands of social security numbers revealed&lt;/a&gt; [Axcess News, Apr 23 2007]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Government&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA</description>      <pubDate>Wed, 16 Jun 2010 16:03:09 -0400</pubDate>      <ddb:attackedentityfield>Government</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>April 23, 2007</ddb:dateoccured>      <ddb:entrytitle>WHID 2007-16: USDA admits data breach, thousands of social security numbers revealed</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Details about 63,000 loans granted to farmers by USDA (The US department of agriculture) where posted online by mistake.&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.axcessnews.com/index.php/articles/show/id/10832&quot;&gt;USDA admits data breach, thousands of social security numbers revealed&lt;/a&gt; [Axcess News, Apr 23 2007]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2007-16</ddb:whidid>    </item>    <item>      <title>WHID 2007-35: Data lapse involved 51,000 at a hospital</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34439</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2007-35: Data lapse involved 51,000 at a hospital&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2007-35&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;July 30, 2007&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;In a classic case of lack of proper separation between the production and development sites, an application under production with lack of proper authentication and authorization was installed on a hospital's public web site, enabling anyone to query a database of 51,000 names, addresses and social security numbers.&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.indystar.com/apps/pbcs.dll/article?AID=2007707250428&quot;&gt;Data lapse involved 51,000, St. Vincent says&lt;/a&gt; [Indy Star, Jul 25 2007]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Health&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA</description>      <pubDate>Wed, 16 Jun 2010 15:51:50 -0400</pubDate>      <ddb:attackedentityfield>Health</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>July 30, 2007</ddb:dateoccured>      <ddb:entrytitle>WHID 2007-35: Data lapse involved 51,000 at a hospital</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;In a classic case of lack of proper separation between the production and development sites, an application under production with lack of proper authentication and authorization was installed on a hospital's public web site, enabling anyone to query a database of 51,000 names, addresses and social security numbers.&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.indystar.com/apps/pbcs.dll/article?AID=2007707250428&quot;&gt;Data lapse involved 51,000, St. Vincent says&lt;/a&gt; [Indy Star, Jul 25 2007]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2007-35</ddb:whidid>    </item>    <item>      <title>WHID 2007-36: Server hacked through holes in Confixx management software</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34444</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2007-36: Server hacked through holes in Confixx management software&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2007-36&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;August 12, 2007&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Downtime&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;A command injection vulnerability at 1&amp;amp;1, a large German hosting provider, lead to denial of service and possible home page modification at 30 servers and up to 1700 web sites. &lt;/p&gt;&lt;br&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.heise-security.co.uk/news/93642&quot;&gt;Server hacked through holes in Confixx management software&lt;/a&gt; [Heise Security, Aug 1 2007]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Service Providers&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;Germany&lt;br&gt;&lt;b&gt;Attacked System Technology: &lt;/b&gt;Confixx</description>      <pubDate>Wed, 16 Jun 2010 15:51:36 -0400</pubDate>      <ddb:attackedentityfield>Service Providers</ddb:attackedentityfield>      <ddb:attackedentitygeography>Germany</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology>Confixx</ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>August 12, 2007</ddb:dateoccured>      <ddb:entrytitle>WHID 2007-36: Server hacked through holes in Confixx management software</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;A command injection vulnerability at 1&amp;amp;1, a large German hosting provider, lead to denial of service and possible home page modification at 30 servers and up to 1700 web sites. &lt;/p&gt;&#13;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.heise-security.co.uk/news/93642&quot;&gt;Server hacked through holes in Confixx management software&lt;/a&gt; [Heise Security, Aug 1 2007]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Downtime</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2007-36</ddb:whidid>    </item>    <item>      <title>WHID 2007-73: Brokerage Firm Fined $375,000 for Unsecured Data</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=48246</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2007-73: Brokerage Firm Fined $375,000 for Unsecured Data&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2007-73&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;December 26, 2007&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Monetary Loss&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;Brokerage firm DA Davidson has agreed to pay a fine of $375,000 for failing to protect confidential client data from Latvian hackers who breached the company in 2007 in an online extortion scheme.&lt;br&gt;The hackers used a SQL injection attack to obtain access to the company’s database on Dec. 25 and 26, 2007.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;Latvia&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Finance&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA&lt;br&gt;&lt;b&gt;Cost: &lt;/b&gt;$375,000.00&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://www.wired.com/threatlevel/2010/04/brokerage-firm-fined&quot;&gt;http://www.wired.com/threatlevel/2010/04/brokerage-firm-fined&lt;/a></description>      <pubDate>Mon, 24 May 2010 13:54:42 -0400</pubDate>      <ddb:attackedentityfield>Finance</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography>Latvia</ddb:attacksourcegeography>      <ddb:cost>$375,000.00</ddb:cost>      <ddb:dateoccured>December 26, 2007</ddb:dateoccured>      <ddb:entrytitle>WHID 2007-73: Brokerage Firm Fined $375,000 for Unsecured Data</ddb:entrytitle>      <ddb:incidentdescription>Brokerage firm DA Davidson has agreed to pay a fine of $375,000 for failing to protect confidential client data from Latvian hackers who breached the company in 2007 in an online extortion scheme.&#13;&#10;&#13;&#10;The hackers used a SQL injection attack to obtain access to the company’s database on Dec. 25 and 26, 2007.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Monetary Loss</ddb:outcome>      <ddb:reference>http://www.wired.com/threatlevel/2010/04/brokerage-firm-fined</ddb:reference>      <ddb:whidid>2007-73</ddb:whidid>    </item>    <item>      <title>WHID 2008-52: The Hannaford Breach</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=35045</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2008-52: The Hannaford Breach&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2008-52&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;March 17, 2008&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Monetary Loss&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;While the &lt;a href=&quot;http://securosis.com/2008/03/18/picking-apart-the-hannaford-breach-what-might-have-happened/&quot;&gt;Hannaford Breach&lt;/a&gt; which resulted in 4.2 stolen credit cards and 1800 known fraud cases may not be a web hack, a &lt;a href=&quot;http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;taxonomyName=Disaster+Recovery&amp;amp;articleId=9068999&amp;amp;taxonomyId=151&amp;amp;pageNumber=1&quot;&gt;Computer World article mentioned&lt;/a&gt; that the company's web site was off line following the breach. Even if the breach itself was not a result of web site issues, such issues where probably found in the security review to follow the Breach making the incident a worthy addition to WHID.&lt;/p&gt;&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Retail&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA</description>      <pubDate>Wed, 16 Jun 2010 14:37:14 -0400</pubDate>      <ddb:attackedentityfield>Retail</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>March 17, 2008</ddb:dateoccured>      <ddb:entrytitle>WHID 2008-52: The Hannaford Breach</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;While the &lt;a href=&quot;http://securosis.com/2008/03/18/picking-apart-the-hannaford-breach-what-might-have-happened/&quot;&gt;Hannaford Breach&lt;/a&gt; which resulted in 4.2 stolen credit cards and 1800 known fraud cases may not be a web hack, a &lt;a href=&quot;http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;taxonomyName=Disaster+Recovery&amp;amp;articleId=9068999&amp;amp;taxonomyId=151&amp;amp;pageNumber=1&quot;&gt;Computer World article mentioned&lt;/a&gt; that the company's web site was off line following the breach. Even if the breach itself was not a result of web site issues, such issues where probably found in the security review to follow the Breach making the incident a worthy addition to WHID.&lt;/p></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Monetary Loss</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2008-52</ddb:whidid>    </item>    <item>      <title>WHID 2007-15: High School Hackers Cancel School With Fake Snow Day</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34332</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2007-15: High School Hackers Cancel School With Fake Snow Day&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2007-15&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;April 5, 2007&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Disinformation&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Two girls modified a schools home page by adding a note that school was closed due to a snow storm. The attack was probably done using a rouge admin accounts.&lt;/p&gt;&lt;br&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.firstcoastnews.com/news/strange/news-article.aspx?storyid=75657&quot;&gt;High School Hackers Cancel School With Fake Snow Day&lt;/a&gt; [http://www.firstcoastnews.com/news/strange/news-article.aspx?storyid=75657, Feb 9 2007]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Education&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA</description>      <pubDate>Wed, 16 Jun 2010 16:03:39 -0400</pubDate>      <ddb:attackedentityfield>Education</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>April 5, 2007</ddb:dateoccured>      <ddb:entrytitle>WHID 2007-15: High School Hackers Cancel School With Fake Snow Day</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Two girls modified a schools home page by adding a note that school was closed due to a snow storm. The attack was probably done using a rouge admin accounts.&lt;/p&gt;&#13;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.firstcoastnews.com/news/strange/news-article.aspx?storyid=75657&quot;&gt;High School Hackers Cancel School With Fake Snow Day&lt;/a&gt; [http://www.firstcoastnews.com/news/strange/news-article.aspx?storyid=75657, Feb 9 2007]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Disinformation</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2007-15</ddb:whidid>    </item>    <item>      <title>WHID 2007-37: United Nations VS SQL Injections</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34450</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2007-37: United Nations VS SQL Injections&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2007-37&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;August 13, 2007&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Defacement&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Defacements are usually beyond the scope of the Web Hacking Incidents Database. We only publish those that stand out, and this one certainly stands out.&lt;/p&gt;&lt;br&gt;&lt;p&gt;The site of the United Nations was broken into and defaced using a pretty basic SQL injection technique, and the referenced article has all the details&lt;/p&gt;&lt;br&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://hackademix.net/2007/08/12/united-nations-vs-sql-injections/&quot;&gt;United Nations VS SQL Injections&lt;/a&gt; [Hackademix, Aug 12 2007]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://news.bbc.co.uk/2/hi/technology/6943385.stm&quot;&gt;UN's website breached by hackers&lt;/a&gt; [BBC, Aug 13 2007]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Government&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;United Nations</description>      <pubDate>Wed, 16 Jun 2010 15:50:56 -0400</pubDate>      <ddb:attackedentityfield>Government</ddb:attackedentityfield>      <ddb:attackedentitygeography>United Nations</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>August 13, 2007</ddb:dateoccured>      <ddb:entrytitle>WHID 2007-37: United Nations VS SQL Injections</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Defacements are usually beyond the scope of the Web Hacking Incidents Database. We only publish those that stand out, and this one certainly stands out.&lt;/p&gt;&#13;&lt;p&gt;The site of the United Nations was broken into and defaced using a pretty basic SQL injection technique, and the referenced article has all the details&lt;/p&gt;&#13;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://hackademix.net/2007/08/12/united-nations-vs-sql-injections/&quot;&gt;United Nations VS SQL Injections&lt;/a&gt; [Hackademix, Aug 12 2007]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://news.bbc.co.uk/2/hi/technology/6943385.stm&quot;&gt;UN's website breached by hackers&lt;/a&gt; [BBC, Aug 13 2007]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Defacement</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2007-37</ddb:whidid>    </item>    <item>      <title>WHID 2007-14: Your Free MacWorld Expo Platinum Pass</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34327</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2007-14: Your Free MacWorld Expo Platinum Pass&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2007-14&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;April 2, 2007&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Loss of Sales&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;A priority code, used to get free platinum pass to MacWorld Expo, was validated on the client and enabled anyone get the pass for free. While &quot;grutz&quot; informed the organizers about it, when going over their log files they found out that others abused the vulnerability without letting anyone know about it.&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://news.com.com/2100-1002_3-6149994.html?part=rss&amp;amp;tag=2547-1_3-0-5&amp;amp;subj=news&quot;&gt;Macworld crack offers VIP passes, hacker says&lt;/a&gt; [CNet, Jan 12 2007]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://grutztopia.jingojango.net/2007/01/your-free-macworld-expo-platinum-pass_11.html&quot;&gt;Your Free MacWorld Expo Platinum Pass (valued at $1,695)&lt;/a&gt; [Grutz, Jan 11 2007]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Technology&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA</description>      <pubDate>Wed, 16 Jun 2010 16:04:05 -0400</pubDate>      <ddb:attackedentityfield>Technology</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>April 2, 2007</ddb:dateoccured>      <ddb:entrytitle>WHID 2007-14: Your Free MacWorld Expo Platinum Pass</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;A priority code, used to get free platinum pass to MacWorld Expo, was validated on the client and enabled anyone get the pass for free. While &quot;grutz&quot; informed the organizers about it, when going over their log files they found out that others abused the vulnerability without letting anyone know about it.&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://news.com.com/2100-1002_3-6149994.html?part=rss&amp;amp;tag=2547-1_3-0-5&amp;amp;subj=news&quot;&gt;Macworld crack offers VIP passes, hacker says&lt;/a&gt; [CNet, Jan 12 2007]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://grutztopia.jingojango.net/2007/01/your-free-macworld-expo-platinum-pass_11.html&quot;&gt;Your Free MacWorld Expo Platinum Pass (valued at $1,695)&lt;/a&gt; [Grutz, Jan 11 2007]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Loss of Sales</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2007-14</ddb:whidid>    </item>    <item>      <title>WHID 2006-47: Santa brought to Zone-H a brand new defacement</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34322</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2006-47: Santa brought to Zone-H a brand new defacement&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2006-47&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;April 2, 2007&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Defacement&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Zone-h is one of the best (well, the best, not just one of them) web sites to follow if you interested in what the bad guys do. Their account of how their own web site was defaced is a classic. And no, it was not their fault. The incident shows how a seemingly minor vulnerability in a major web site (a hotmail XSS bug), can be used to deface another, unrelated site in a very elaborate and targeted attack.&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.zone-h.org/content/view/14458/31/&quot;&gt;Santa brought to Zone-H a brand new defacement&lt;/a&gt; [Zone-H, Dec 22 2006]&lt;/li&gt;&lt;br&gt;&lt;/ul></description>      <pubDate>Wed, 16 Jun 2010 16:08:50 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>April 2, 2007</ddb:dateoccured>      <ddb:entrytitle>WHID 2006-47: Santa brought to Zone-H a brand new defacement</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Zone-h is one of the best (well, the best, not just one of them) web sites to follow if you interested in what the bad guys do. Their account of how their own web site was defaced is a classic. And no, it was not their fault. The incident shows how a seemingly minor vulnerability in a major web site (a hotmail XSS bug), can be used to deface another, unrelated site in a very elaborate and targeted attack.&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.zone-h.org/content/view/14458/31/&quot;&gt;Santa brought to Zone-H a brand new defacement&lt;/a&gt; [Zone-H, Dec 22 2006]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Defacement</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2006-47</ddb:whidid>    </item>    <item>      <title>WHID 2007-13: Hackers hit Georgia Tech and steal personal info</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34317</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2007-13: Hackers hit Georgia Tech and steal personal info&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2007-13&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;April 2, 2007&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;The personal information of about 3,000 current and former Georgia Tech employees may have been compromised. The informatoin included names, addresses, Social Security numbers and other sensitive information, including about 400 state purchasing card numbers.&lt;/p&gt;&lt;br&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://atlanta.bizjournals.com/atlanta/stories/2007/02/19/daily20.html?t=printable&quot;&gt;Hackers hit Georgia Tech and steal personal info&lt;/a&gt; [Atlanta Business Chronicle, Feb 21 2007]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Education&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA</description>      <pubDate>Wed, 16 Jun 2010 16:04:55 -0400</pubDate>      <ddb:attackedentityfield>Education</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>April 2, 2007</ddb:dateoccured>      <ddb:entrytitle>WHID 2007-13: Hackers hit Georgia Tech and steal personal info</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;The personal information of about 3,000 current and former Georgia Tech employees may have been compromised. The informatoin included names, addresses, Social Security numbers and other sensitive information, including about 400 state purchasing card numbers.&lt;/p&gt;&#13;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://atlanta.bizjournals.com/atlanta/stories/2007/02/19/daily20.html?t=printable&quot;&gt;Hackers hit Georgia Tech and steal personal info&lt;/a&gt; [Atlanta Business Chronicle, Feb 21 2007]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2007-13</ddb:whidid>    </item>    <item>      <title>WHID 2007-12: SQL injection at knorr.de login page</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34311</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2007-12: SQL injection at knorr.de login page&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2007-12&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;April 2, 2007&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;While vulnerabilities in public web sites are dime a dozen this days and rarely included in WHID, a classic SQL injection in the login form on the home page of the web site of a very big company is worth an entry. In my presentation I usually claim that such vulnerabilities have disappeared years ago and then go on to show advanced SQL injection techniques. It seems that they exit.&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://blog.gjl-network.net/blog/index.php?/archives/78-Knorr.de-SQL-Injection-and-XSS-Vulnerabilities.html&quot;&gt;Knorr.de SQL Injection and XSS Vulnerabilities&lt;/a&gt; [Sebastian Bauer, Mar 2 2007]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Retail&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;Germany</description>      <pubDate>Thu, 17 Jun 2010 18:23:06 -0400</pubDate>      <ddb:attackedentityfield>Retail</ddb:attackedentityfield>      <ddb:attackedentitygeography>Germany</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>April 2, 2007</ddb:dateoccured>      <ddb:entrytitle>WHID 2007-12: SQL injection at knorr.de login page</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;While vulnerabilities in public web sites are dime a dozen this days and rarely included in WHID, a classic SQL injection in the login form on the home page of the web site of a very big company is worth an entry. In my presentation I usually claim that such vulnerabilities have disappeared years ago and then go on to show advanced SQL injection techniques. It seems that they exit.&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://blog.gjl-network.net/blog/index.php?/archives/78-Knorr.de-SQL-Injection-and-XSS-Vulnerabilities.html&quot;&gt;Knorr.de SQL Injection and XSS Vulnerabilities&lt;/a&gt; [Sebastian Bauer, Mar 2 2007]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2007-12</ddb:whidid>    </item>    <item>      <title>WHID 2007-38: Gentoo takes server offline due to security vulnerabilities</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34460</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2007-38: Gentoo takes server offline due to security vulnerabilities&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2007-38&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;August 30, 2007&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Downtime&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;This gem is very interesting since it happened on Gentoo servers. It therefore combines transparency into the incident that only an open source project can offer with the importance and resource of a large one. As a result we have a detailed report about the vulnerability, exploit attempts and event people shouting at each other during the patching process. &lt;br /&gt;What can we learn from this? That no server is secure, and that patching is hard.&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;https://bugs.gentoo.org/show_bug.cgi?id=187971&quot;&gt;Bugzilla Bug 187971 - Gentoo Website Command Injection Issue&lt;/a&gt; [Gentoo, Aug 7 2007]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.gentoo.org/proj/en/infrastructure/nuthatch-writeup/&quot;&gt;Analysis and Timeline of the Nuthatch exploitation attempts&lt;/a&gt; [Gentoo, ]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.gentoo.org/proj/en/infrastructure/nuthatch-writeup/apache-log-extract.txt&quot;&gt;Log of all usages of the exploit&lt;/a&gt; [Gentoo, ]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.theregister.co.uk/2007/08/17/gentoo_disconnects_vulnerable_server/&quot;&gt;Gentoo cuts key parts of itself from net for its own good&lt;/a&gt; [The Register, Aug 17 2007]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Technology</description>      <pubDate>Wed, 16 Jun 2010 15:50:56 -0400</pubDate>      <ddb:attackedentityfield>Technology</ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>August 30, 2007</ddb:dateoccured>      <ddb:entrytitle>WHID 2007-38: Gentoo takes server offline due to security vulnerabilities</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;This gem is very interesting since it happened on Gentoo servers. It therefore combines transparency into the incident that only an open source project can offer with the importance and resource of a large one. As a result we have a detailed report about the vulnerability, exploit attempts and event people shouting at each other during the patching process. &lt;br /&gt;What can we learn from this? That no server is secure, and that patching is hard.&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;https://bugs.gentoo.org/show_bug.cgi?id=187971&quot;&gt;Bugzilla Bug 187971 - Gentoo Website Command Injection Issue&lt;/a&gt; [Gentoo, Aug 7 2007]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.gentoo.org/proj/en/infrastructure/nuthatch-writeup/&quot;&gt;Analysis and Timeline of the Nuthatch exploitation attempts&lt;/a&gt; [Gentoo, ]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.gentoo.org/proj/en/infrastructure/nuthatch-writeup/apache-log-extract.txt&quot;&gt;Log of all usages of the exploit&lt;/a&gt; [Gentoo, ]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.theregister.co.uk/2007/08/17/gentoo_disconnects_vulnerable_server/&quot;&gt;Gentoo cuts key parts of itself from net for its own good&lt;/a&gt; [The Register, Aug 17 2007]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Downtime</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2007-38</ddb:whidid>    </item>    <item>      <title>WHID 2006-46: Hacker Redirects Bank Customers To Phony Site</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34306</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2006-46: Hacker Redirects Bank Customers To Phony Site&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2006-46&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;March 30, 2007&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Phishing&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;A small credit union web site was hacked and the traffic redirected to a pharming site. About  180 users where redirected, out of which 12 where tricked into providing their personal information to the attackers. $500 are known to have been stolen from one of the victims.&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.thekansascitychannel.com/news/10408223/detail.html&quot;&gt;Hacker Redirects Bank Customers To Phony Site&lt;/a&gt; [The Kensas City Channel, Nov 27 2006]&lt;/li&gt;&lt;br&gt;&lt;/ul></description>      <pubDate>Wed, 16 Jun 2010 16:44:12 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>March 30, 2007</ddb:dateoccured>      <ddb:entrytitle>WHID 2006-46: Hacker Redirects Bank Customers To Phony Site</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;A small credit union web site was hacked and the traffic redirected to a pharming site. About  180 users where redirected, out of which 12 where tricked into providing their personal information to the attackers. $500 are known to have been stolen from one of the victims.&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.thekansascitychannel.com/news/10408223/detail.html&quot;&gt;Hacker Redirects Bank Customers To Phony Site&lt;/a&gt; [The Kensas City Channel, Nov 27 2006]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Phishing</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2006-46</ddb:whidid>    </item>    <item>      <title>WHID 2007-39: Hacker sabotages Peru president&amp;#039;s Web site</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34466</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2007-39: Hacker sabotages Peru president&amp;#039;s Web site&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2007-39&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;August 30, 2007&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Defacement&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Defacements seem to start dominating this list. Alas, they are the most obvious web site hacks out there. While not every defacement is reported in the Web Hacking Incidents Database, key ones are.  I included this one since the attacked web site is significant, and since it emphasizes what is becoming a major goal of attacking: politics and international affairs. &lt;br /&gt;As a side note, this incident is also interesting because it was repeated after discovered and presumably fixed, which goes a long way to show how much effort there is in protecting web sites and how difficult it cab be.&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.metimes.com/storyview.php?StoryID=20070726-053627-3518r&quot;&gt;Hacker sabotages Peru president's Web site&lt;/a&gt; [Middle East Times, Jul 26 2007]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Politics&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;Peru</description>      <pubDate>Wed, 16 Jun 2010 15:50:56 -0400</pubDate>      <ddb:attackedentityfield>Politics</ddb:attackedentityfield>      <ddb:attackedentitygeography>Peru</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>August 30, 2007</ddb:dateoccured>      <ddb:entrytitle>WHID 2007-39: Hacker sabotages Peru president&amp;#039;s Web site</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Defacements seem to start dominating this list. Alas, they are the most obvious web site hacks out there. While not every defacement is reported in the Web Hacking Incidents Database, key ones are.  I included this one since the attacked web site is significant, and since it emphasizes what is becoming a major goal of attacking: politics and international affairs. &lt;br /&gt;As a side note, this incident is also interesting because it was repeated after discovered and presumably fixed, which goes a long way to show how much effort there is in protecting web sites and how difficult it cab be.&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.metimes.com/storyview.php?StoryID=20070726-053627-3518r&quot;&gt;Hacker sabotages Peru president's Web site&lt;/a&gt; [Middle East Times, Jul 26 2007]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Defacement</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2007-39</ddb:whidid>    </item>    <item>      <title>WHID 2006-45: Man arrested for hacking Internet shopping malls</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34303</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2006-45: Man arrested for hacking Internet shopping malls&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2006-45&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;March 30, 2007&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Monetary Loss&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;A Korean shopping system was vulnerable to hidden field manipulation and a determined hacker purchased $6000 worth of merchandize at 45 stores for much less.&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://english.hani.co.kr/arti/english_edition/e_national/178464.html&quot;&gt;Man arrested for hacking Internet shopping malls&lt;/a&gt; [The Hankyorea, Dec 17 2006]&lt;/li&gt;&lt;br&gt;&lt;/ul></description>      <pubDate>Wed, 16 Jun 2010 16:46:41 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>March 30, 2007</ddb:dateoccured>      <ddb:entrytitle>WHID 2006-45: Man arrested for hacking Internet shopping malls</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;A Korean shopping system was vulnerable to hidden field manipulation and a determined hacker purchased $6000 worth of merchandize at 45 stores for much less.&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://english.hani.co.kr/arti/english_edition/e_national/178464.html&quot;&gt;Man arrested for hacking Internet shopping malls&lt;/a&gt; [The Hankyorea, Dec 17 2006]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Monetary Loss</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2006-45</ddb:whidid>    </item>    <item>      <title>WHID 2007-40: County&amp;#039;s Web site hacked; no data lost</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34471</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2007-40: County&amp;#039;s Web site hacked; no data lost&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2007-40&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;September 2, 2007&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Defacement&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Defacements seem to dominate the list recently, probably because they reach everywhere. Two important conclusions from this particular one are that patch management is a key problem and that it is a problem mainly at government sites across the world.&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.journalgazette.net/apps/pbcs.dll/article?AID=/20070828/LOCAL/708280400/1002/LOCAL&quot;&gt;County's Web site hacked; no data lost&lt;/a&gt; [Journal Gazetter, Aug 28 2007]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Government&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA</description>      <pubDate>Wed, 16 Jun 2010 15:50:56 -0400</pubDate>      <ddb:attackedentityfield>Government</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>September 2, 2007</ddb:dateoccured>      <ddb:entrytitle>WHID 2007-40: County&amp;#039;s Web site hacked; no data lost</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Defacements seem to dominate the list recently, probably because they reach everywhere. Two important conclusions from this particular one are that patch management is a key problem and that it is a problem mainly at government sites across the world.&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.journalgazette.net/apps/pbcs.dll/article?AID=/20070828/LOCAL/708280400/1002/LOCAL&quot;&gt;County's Web site hacked; no data lost&lt;/a&gt; [Journal Gazetter, Aug 28 2007]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Defacement</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2007-40</ddb:whidid>    </item>    <item>      <title>WHID 2007-41: Hackers hit New Zealand Herald website</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34476</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2007-41: Hackers hit New Zealand Herald website&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2007-41&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;September 2, 2007&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Defacement&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Still defacement but this time with a twist. This was a genuine XSS rewriting attack, and was carried out by well known people as a stunt. No information is provided on how the XSS vector found its way to the victim computers.&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.stuff.co.nz/stuff/4182914a28.html&quot;&gt;Hackers hit New Zealand Herald website&lt;/a&gt; [Stuff, Aug 29 2007]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Media</description>      <pubDate>Wed, 16 Jun 2010 15:50:56 -0400</pubDate>      <ddb:attackedentityfield>Media</ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>September 2, 2007</ddb:dateoccured>      <ddb:entrytitle>WHID 2007-41: Hackers hit New Zealand Herald website</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Still defacement but this time with a twist. This was a genuine XSS rewriting attack, and was carried out by well known people as a stunt. No information is provided on how the XSS vector found its way to the victim computers.&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.stuff.co.nz/stuff/4182914a28.html&quot;&gt;Hackers hit New Zealand Herald website&lt;/a&gt; [Stuff, Aug 29 2007]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Defacement</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2007-41</ddb:whidid>    </item>    <item>      <title>WHID 2007-11: Nokia defaced by XSS</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34296</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2007-11: Nokia defaced by XSS&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2007-11&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;March 30, 2007&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Defacement&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Nokia's Canadian Web Site was defaced using an XSS attack.&lt;/p&gt;&lt;br&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.mad4mobilephones.com/news/383/&quot;&gt;Nokia website hacked&lt;/a&gt; [Mad4mobilephones, Jan 29 2007]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Technology&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;Canada</description>      <pubDate>Wed, 16 Jun 2010 16:05:26 -0400</pubDate>      <ddb:attackedentityfield>Technology</ddb:attackedentityfield>      <ddb:attackedentitygeography>Canada</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>March 30, 2007</ddb:dateoccured>      <ddb:entrytitle>WHID 2007-11: Nokia defaced by XSS</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Nokia's Canadian Web Site was defaced using an XSS attack.&lt;/p&gt;&#13;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.mad4mobilephones.com/news/383/&quot;&gt;Nokia website hacked&lt;/a&gt; [Mad4mobilephones, Jan 29 2007]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Defacement</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2007-11</ddb:whidid>    </item>    <item>      <title>WHID 2007-42: Bank of India seriously compromised</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34482</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2007-42: Bank of India seriously compromised&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2007-42&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;September 3, 2007&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Planting of Malware&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;This very serious hacking incident provides insight into a lot&lt;br /&gt;of the failures information security in general and web application&lt;br /&gt;security particularly beyond the simple fact that the web site of the&lt;br /&gt;largest state owned bank in India was invisibly defaced with Trojan&lt;br /&gt;inflicting code.&lt;/p&gt;&lt;br&gt;&lt;p&gt;Firstly, the entire discussion in the references is about the&lt;br /&gt;Trojan payload, with no word about the vulnerability that led to the&lt;br /&gt;defacement. Actually a reviewer on the SiteAdvisor report gives the&lt;br /&gt;green mark to the web site after the Trojan is removed, without&lt;br /&gt;requiring any information about the actual problem.&lt;/p&gt;&lt;br&gt;&lt;p&gt;Secondly, most trust systems, including SiteAdvisor,&lt;br /&gt;completely fail to detect the breach. Which makes me think about those&lt;br /&gt;trust models: they check that the site was not breached, while they&lt;br /&gt;should check that the site is not vulnerable. I guess the reason is&lt;br /&gt;that their primary goal is to detect intentionally malicious sites and&lt;br /&gt;not breaches is normative sites, but others use them to assess the&lt;br /&gt;level of security of the later.&lt;br /&gt;&lt;/p&gt;&lt;br&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://sunbeltblog.blogspot.com/2007/08/breaking-bank-of-india-seriously.html&quot;&gt;Breaking: Bank of India seriously compromised&lt;/a&gt; [Sunblet Blog, Sep 2 2007]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.siteadvisor.com/sites/bankofindia.com&quot;&gt;McAfee SiteAdvisor&lt;/a&gt; [McAfee, ]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Finance&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;India</description>      <pubDate>Wed, 16 Jun 2010 15:50:56 -0400</pubDate>      <ddb:attackedentityfield>Finance</ddb:attackedentityfield>      <ddb:attackedentitygeography>India</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>September 3, 2007</ddb:dateoccured>      <ddb:entrytitle>WHID 2007-42: Bank of India seriously compromised</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;This very serious hacking incident provides insight into a lot&lt;br /&gt;of the failures information security in general and web application&lt;br /&gt;security particularly beyond the simple fact that the web site of the&lt;br /&gt;largest state owned bank in India was invisibly defaced with Trojan&lt;br /&gt;inflicting code.&lt;/p&gt;&#13;&lt;p&gt;Firstly, the entire discussion in the references is about the&lt;br /&gt;Trojan payload, with no word about the vulnerability that led to the&lt;br /&gt;defacement. Actually a reviewer on the SiteAdvisor report gives the&lt;br /&gt;green mark to the web site after the Trojan is removed, without&lt;br /&gt;requiring any information about the actual problem.&lt;/p&gt;&#13;&lt;p&gt;Secondly, most trust systems, including SiteAdvisor,&lt;br /&gt;completely fail to detect the breach. Which makes me think about those&lt;br /&gt;trust models: they check that the site was not breached, while they&lt;br /&gt;should check that the site is not vulnerable. I guess the reason is&lt;br /&gt;that their primary goal is to detect intentionally malicious sites and&lt;br /&gt;not breaches is normative sites, but others use them to assess the&lt;br /&gt;level of security of the later.&lt;br /&gt;&lt;/p&gt;&#13;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://sunbeltblog.blogspot.com/2007/08/breaking-bank-of-india-seriously.html&quot;&gt;Breaking: Bank of India seriously compromised&lt;/a&gt; [Sunblet Blog, Sep 2 2007]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.siteadvisor.com/sites/bankofindia.com&quot;&gt;McAfee SiteAdvisor&lt;/a&gt; [McAfee, ]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Planting of Malware</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2007-42</ddb:whidid>    </item>    <item>      <title>WHID 2007-43: Hacker attacks the Ministry for Housing website as Spanish mortgages come under the international spotlight</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34487</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2007-43: Hacker attacks the Ministry for Housing website as Spanish mortgages come under the international spotlight&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2007-43&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;September 3, 2007&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Defacement&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Yet another defacement, and as usual in the political arena.&lt;br /&gt;However, this one is worth a note as the attack is very targeted, while&lt;br /&gt;usually such political defacements are carried quote randomly against&lt;br /&gt;sites loosely related to the opponent and usually has little to do with&lt;br /&gt;the actual message the attackers want to convey. In this case the&lt;br /&gt;defacement seems to be a direct response to the hot debate about&lt;br /&gt;housing prices in Spain.&lt;br /&gt;&lt;/p&gt;&lt;br&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.typicallyspanish.com/news/publish/article_12212.shtml&quot;&gt;Hacker attacks the Ministry for Housing website as Spanish mortgages come under the international spotlight&lt;/a&gt; [Typically Spanish, Aug 30 2007]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Government&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;Spain</description>      <pubDate>Wed, 16 Jun 2010 15:50:56 -0400</pubDate>      <ddb:attackedentityfield>Government</ddb:attackedentityfield>      <ddb:attackedentitygeography>Spain</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>September 3, 2007</ddb:dateoccured>      <ddb:entrytitle>WHID 2007-43: Hacker attacks the Ministry for Housing website as Spanish mortgages come under the international spotlight</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Yet another defacement, and as usual in the political arena.&lt;br /&gt;However, this one is worth a note as the attack is very targeted, while&lt;br /&gt;usually such political defacements are carried quote randomly against&lt;br /&gt;sites loosely related to the opponent and usually has little to do with&lt;br /&gt;the actual message the attackers want to convey. In this case the&lt;br /&gt;defacement seems to be a direct response to the hot debate about&lt;br /&gt;housing prices in Spain.&lt;br /&gt;&lt;/p&gt;&#13;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.typicallyspanish.com/news/publish/article_12212.shtml&quot;&gt;Hacker attacks the Ministry for Housing website as Spanish mortgages come under the international spotlight&lt;/a&gt; [Typically Spanish, Aug 30 2007]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Defacement</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2007-43</ddb:whidid>    </item>    <item>      <title>WHID 2007-10: Super Bowl Site Hacked with Trojan, Key logger</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34291</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2007-10: Super Bowl Site Hacked with Trojan, Key logger&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2007-10&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;March 30, 2007&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Planting of Malware&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Hackers penetrated the Dolphins stadium web site just days before the Super Bowl was held there and modified the home page to include a Trojan inflecting script.&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://cbs.sportsline.com/nfl/story/9971314&quot;&gt;Hacker installs malicious code on Dolphin Stadium website&lt;/a&gt; [CBS/AP, Feb 2 2007]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.websense.com/securitylabs/alerts/alert.php?AlertID=733&quot;&gt;Malicious Website: Super Bowl XLI / Dolphin Stadium&lt;/a&gt; [WebSense, Feb 2 2007]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://eset.com/threat-center/blog/?p=39&quot;&gt;Super Bowl Dolphin Stadium Website Trojan&lt;/a&gt; [eSet, Feb 2 2007]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.securityfocus.com/brief/473&quot;&gt;Chinese servers host malicious cursor attacks&lt;/a&gt; [Security Focus, Mar 30 2007]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Sports&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA</description>      <pubDate>Wed, 16 Jun 2010 16:05:40 -0400</pubDate>      <ddb:attackedentityfield>Sports</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>March 30, 2007</ddb:dateoccured>      <ddb:entrytitle>WHID 2007-10: Super Bowl Site Hacked with Trojan, Key logger</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Hackers penetrated the Dolphins stadium web site just days before the Super Bowl was held there and modified the home page to include a Trojan inflecting script.&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://cbs.sportsline.com/nfl/story/9971314&quot;&gt;Hacker installs malicious code on Dolphin Stadium website&lt;/a&gt; [CBS/AP, Feb 2 2007]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.websense.com/securitylabs/alerts/alert.php?AlertID=733&quot;&gt;Malicious Website: Super Bowl XLI / Dolphin Stadium&lt;/a&gt; [WebSense, Feb 2 2007]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://eset.com/threat-center/blog/?p=39&quot;&gt;Super Bowl Dolphin Stadium Website Trojan&lt;/a&gt; [eSet, Feb 2 2007]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.securityfocus.com/brief/473&quot;&gt;Chinese servers host malicious cursor attacks&lt;/a&gt; [Security Focus, Mar 30 2007]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Planting of Malware</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2007-10</ddb:whidid>    </item>    <item>      <title>WHID 2007-09: Former Fruit of the Loom workers&amp;#039; identities compromised</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34286</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2007-09: Former Fruit of the Loom workers&amp;#039; identities compromised&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2007-09&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;March 29, 2007&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Names and social security numbers of former employees of Fruit of the Loom where available for download from the company's web site.&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.thenortheastgeorgian.com/articles/2007/02/23/news/business/01business.prt&quot;&gt;Former Fruit of the Loom workers' identities compromised&lt;/a&gt; [The Northwest Georgian, Feb 23 2007]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Retail&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA</description>      <pubDate>Wed, 16 Jun 2010 16:06:01 -0400</pubDate>      <ddb:attackedentityfield>Retail</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>March 29, 2007</ddb:dateoccured>      <ddb:entrytitle>WHID 2007-09: Former Fruit of the Loom workers&amp;#039; identities compromised</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Names and social security numbers of former employees of Fruit of the Loom where available for download from the company's web site.&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.thenortheastgeorgian.com/articles/2007/02/23/news/business/01business.prt&quot;&gt;Former Fruit of the Loom workers' identities compromised&lt;/a&gt; [The Northwest Georgian, Feb 23 2007]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2007-09</ddb:whidid>    </item>    <item>      <title>WHID 2007-44: Hacker Breaks Into eBay Server, Locks Users Out</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34492</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2007-44: Hacker Breaks Into eBay Server, Locks Users Out&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2007-44&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;October 10, 2007&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Downtime&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;A hacker exploited a leftover admin function on eBay to block users and close sales.&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.pcworld.com/article/id,138193-c,hackers/article.html&quot;&gt;Hacker Breaks Into eBay Server, Locks Users Out&lt;/a&gt; [PC World, Oct 8 2007]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.auctionbytes.com/cab/abn/y07/m10/i09/s01&quot;&gt;eBay Explains Security Hole Used by Hacker&lt;/a&gt; [Action Bytes, Oct 9 2007]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Retail&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA</description>      <pubDate>Wed, 16 Jun 2010 15:50:56 -0400</pubDate>      <ddb:attackedentityfield>Retail</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>October 10, 2007</ddb:dateoccured>      <ddb:entrytitle>WHID 2007-44: Hacker Breaks Into eBay Server, Locks Users Out</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;A hacker exploited a leftover admin function on eBay to block users and close sales.&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.pcworld.com/article/id,138193-c,hackers/article.html&quot;&gt;Hacker Breaks Into eBay Server, Locks Users Out&lt;/a&gt; [PC World, Oct 8 2007]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.auctionbytes.com/cab/abn/y07/m10/i09/s01&quot;&gt;eBay Explains Security Hole Used by Hacker&lt;/a&gt; [Action Bytes, Oct 9 2007]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Downtime</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2007-44</ddb:whidid>    </item>    <item>      <title>WHID 2007-45: XSS flaw makes PM say: &amp;quot;I want to suck your blood&amp;quot;</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34497</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2007-45: XSS flaw makes PM say: &amp;quot;I want to suck your blood&amp;quot;&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2007-45&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;October 10, 2007&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Defacement&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Using XSS on the sites of both Australian major political parties a security researcher nicknamed Bsoric caused the Liberal Party's Web site to read: &quot;John Howard says: I want to suck your blood&quot;, while another script caused a window to pop up on the Labor Party's Web site, urging viewers to &quot;Vote Liberal!&quot;&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.builderau.com.au/news/soa/XSS-flaw-makes-PM-say-I-want-to-suck-your-blood-/0,339028227,339282682,00.htm&quot;&gt;XSS flaw makes PM say: &quot;I want to suck your blood&quot;&lt;/a&gt; [Builder.AU, Oct 9 2007]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Politics&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;Australia</description>      <pubDate>Wed, 16 Jun 2010 15:50:56 -0400</pubDate>      <ddb:attackedentityfield>Politics</ddb:attackedentityfield>      <ddb:attackedentitygeography>Australia</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>October 10, 2007</ddb:dateoccured>      <ddb:entrytitle>WHID 2007-45: XSS flaw makes PM say: &amp;quot;I want to suck your blood&amp;quot;</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Using XSS on the sites of both Australian major political parties a security researcher nicknamed Bsoric caused the Liberal Party's Web site to read: &quot;John Howard says: I want to suck your blood&quot;, while another script caused a window to pop up on the Labor Party's Web site, urging viewers to &quot;Vote Liberal!&quot;&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.builderau.com.au/news/soa/XSS-flaw-makes-PM-say-I-want-to-suck-your-blood-/0,339028227,339282682,00.htm&quot;&gt;XSS flaw makes PM say: &quot;I want to suck your blood&quot;&lt;/a&gt; [Builder.AU, Oct 9 2007]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Defacement</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2007-45</ddb:whidid>    </item>    <item>      <title>WHID 2007-08: WordPress Backdoor</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34281</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2007-08: WordPress Backdoor&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2007-08&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;March 29, 2007&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Planting of Malware&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Backdoor was planted in a new official release of WordPress, the most popular blogging software in the world. It was available for download for a few days before the backdoor was located.&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://wordpress.org/development/2007/03/upgrade-212/&quot;&gt;WodPress dangerous, Upgrade&lt;/a&gt; [, Mar 2 2007]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://news.com.com/Intruder+adds+backdoor+to+WordPress+blog+software/2100-7349_3-6164967.html&quot;&gt;Intruder adds back door to WordPress blog software&lt;/a&gt; [News.com, Mar 6 2007]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attacked System Technology: &lt;/b&gt;WordPress</description>      <pubDate>Wed, 16 Jun 2010 16:06:39 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology>WordPress</ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>March 29, 2007</ddb:dateoccured>      <ddb:entrytitle>WHID 2007-08: WordPress Backdoor</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Backdoor was planted in a new official release of WordPress, the most popular blogging software in the world. It was available for download for a few days before the backdoor was located.&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://wordpress.org/development/2007/03/upgrade-212/&quot;&gt;WodPress dangerous, Upgrade&lt;/a&gt; [, Mar 2 2007]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://news.com.com/Intruder+adds+backdoor+to+WordPress+blog+software/2100-7349_3-6164967.html&quot;&gt;Intruder adds back door to WordPress blog software&lt;/a&gt; [News.com, Mar 6 2007]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Planting of Malware</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2007-08</ddb:whidid>    </item>    <item>      <title>WHID 2007-46: School Web site breached? Personal info of Pembroke workers, volunteers accessible for months</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34502</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2007-46: School Web site breached? Personal info of Pembroke workers, volunteers accessible for months&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2007-46&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;October 11, 2007&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Personal information on anyone who worked or volunteered for the Pembroke schools in the last four years was accessible via the Internet because of a weakness in the district's computer system. The information, including names, birth dates and Social Security numbers, was available from May until Oct. 2, when school officials learned of the problem.&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.patriotledger.com/articles/2007/10/09/news/news01.txt&quot;&gt;School Web site breached? Personal info of Pembroke workers, volunteers accessible for months&lt;/a&gt; [Patriot Ledger, Oct 11 2007]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Education&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA</description>      <pubDate>Wed, 16 Jun 2010 15:50:56 -0400</pubDate>      <ddb:attackedentityfield>Education</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>October 11, 2007</ddb:dateoccured>      <ddb:entrytitle>WHID 2007-46: School Web site breached? Personal info of Pembroke workers, volunteers accessible for months</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Personal information on anyone who worked or volunteered for the Pembroke schools in the last four years was accessible via the Internet because of a weakness in the district's computer system. The information, including names, birth dates and Social Security numbers, was available from May until Oct. 2, when school officials learned of the problem.&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.patriotledger.com/articles/2007/10/09/news/news01.txt&quot;&gt;School Web site breached? Personal info of Pembroke workers, volunteers accessible for months&lt;/a&gt; [Patriot Ledger, Oct 11 2007]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2007-46</ddb:whidid>    </item>    <item>      <title>WHID 2007-47: Commerce Bank, a US regional bank, hacked</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34507</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2007-47: Commerce Bank, a US regional bank, hacked&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2007-47&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;October 12, 2007&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;3,000 records were exposed and 20 actually stolen at Commerce Bank, a small bank in Central USA. While the vulnerability exploited is not clear, SQL injection was mentioned. Therefore the record is uncertain and based on further information, it might be withdrawn.&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.theregister.co.uk/2007/10/11/commerce_bank_hack/&quot;&gt;US regional bank hacked&lt;/a&gt; [The Register, ]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://columbiatribune.com/2007/Oct/20071010Busi001.asp&quot;&gt;Customer information compromised at bank&lt;/a&gt; [Columbia Tribune, Oct 10 2007]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Finance&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA</description>      <pubDate>Wed, 16 Jun 2010 15:50:56 -0400</pubDate>      <ddb:attackedentityfield>Finance</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>October 12, 2007</ddb:dateoccured>      <ddb:entrytitle>WHID 2007-47: Commerce Bank, a US regional bank, hacked</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;3,000 records were exposed and 20 actually stolen at Commerce Bank, a small bank in Central USA. While the vulnerability exploited is not clear, SQL injection was mentioned. Therefore the record is uncertain and based on further information, it might be withdrawn.&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.theregister.co.uk/2007/10/11/commerce_bank_hack/&quot;&gt;US regional bank hacked&lt;/a&gt; [The Register, ]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://columbiatribune.com/2007/Oct/20071010Busi001.asp&quot;&gt;Customer information compromised at bank&lt;/a&gt; [Columbia Tribune, Oct 10 2007]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2007-47</ddb:whidid>    </item>    <item>      <title>WHID 2007-07: Westerly Hospital data breach affects 2,000</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34276</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2007-07: Westerly Hospital data breach affects 2,000&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2007-07&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;March 29, 2007&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Personal information about 2,000 patients was mistakenly published on the hospital's web site. The leakage was discovered only when a patient found her information when &quot;Googling&quot; herself.&lt;br&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;The information included personal data such as social security numbers, birth dates, address, phone number, insurance numbers and in some cases the reason for the visit.&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.pbn.com/stories/23678.html&quot;&gt;Westerly Hospital data breach affects 2,000&lt;/a&gt; [Providence Business News, Mar 2 2007]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.westerlyhospital.com/news_events/patient_data_incident_report.htm&quot;&gt;Patient Data Incident&lt;/a&gt; [, Mar 5 2007]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Health&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA</description>      <pubDate>Wed, 16 Jun 2010 16:06:46 -0400</pubDate>      <ddb:attackedentityfield>Health</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>March 29, 2007</ddb:dateoccured>      <ddb:entrytitle>WHID 2007-07: Westerly Hospital data breach affects 2,000</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Personal information about 2,000 patients was mistakenly published on the hospital's web site. The leakage was discovered only when a patient found her information when &quot;Googling&quot; herself.&#13;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;The information included personal data such as social security numbers, birth dates, address, phone number, insurance numbers and in some cases the reason for the visit.&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.pbn.com/stories/23678.html&quot;&gt;Westerly Hospital data breach affects 2,000&lt;/a&gt; [Providence Business News, Mar 2 2007]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.westerlyhospital.com/news_events/patient_data_incident_report.htm&quot;&gt;Patient Data Incident&lt;/a&gt; [, Mar 5 2007]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2007-07</ddb:whidid>    </item>    <item>      <title>WHID 2007-48: MSU investigating hacking incident</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34512</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2007-48: MSU investigating hacking incident&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2007-48&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;October 17, 2007&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Information including birth date and social security number of 1400 students who enrolled online to the Montana State University has been stolen by hackers. While no technical explanation is provided, the fact that only students who enrolled online where affected points to a web site breach.&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.montanasnewsstation.com/Global/story.asp?S=7220235&amp;amp;nav=menu227_3&quot;&gt;MSU investigating hacking incident&lt;/a&gt; [Montana's News Station, Oct 16 2007]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Education&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA</description>      <pubDate>Wed, 16 Jun 2010 15:50:56 -0400</pubDate>      <ddb:attackedentityfield>Education</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>October 17, 2007</ddb:dateoccured>      <ddb:entrytitle>WHID 2007-48: MSU investigating hacking incident</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Information including birth date and social security number of 1400 students who enrolled online to the Montana State University has been stolen by hackers. While no technical explanation is provided, the fact that only students who enrolled online where affected points to a web site breach.&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.montanasnewsstation.com/Global/story.asp?S=7220235&amp;amp;nav=menu227_3&quot;&gt;MSU investigating hacking incident&lt;/a&gt; [Montana's News Station, Oct 16 2007]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2007-48</ddb:whidid>    </item>    <item>      <title>WHID 2007-49: Hackers Block Sale of Colorado Rockies World Series Tickets</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34517</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2007-49: Hackers Block Sale of Colorado Rockies World Series Tickets&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2007-49&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;October 25, 2007&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Loss of Sales&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;The site of the Rockies was taken down by a denial of service preventing fans from buying tickets for the World Series games.&lt;br&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;Like any DDoS attack, it is very hard to know if it was an application layer or network layer attack, but since this attack had a very significant financial impact by crippling a web site, we think it deserve a place in WHID.&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.associatedcontent.com/article/424906/hackers_block_sale_of_colorado_rockies.html&quot;&gt;Hackers Block Sale of Colorado Rockies World Series Tickets&lt;/a&gt; [Associated Content, Oct 24 2007]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Sports&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA</description>      <pubDate>Wed, 16 Jun 2010 15:50:56 -0400</pubDate>      <ddb:attackedentityfield>Sports</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>October 25, 2007</ddb:dateoccured>      <ddb:entrytitle>WHID 2007-49: Hackers Block Sale of Colorado Rockies World Series Tickets</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;The site of the Rockies was taken down by a denial of service preventing fans from buying tickets for the World Series games.&#13;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;Like any DDoS attack, it is very hard to know if it was an application layer or network layer attack, but since this attack had a very significant financial impact by crippling a web site, we think it deserve a place in WHID.&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.associatedcontent.com/article/424906/hackers_block_sale_of_colorado_rockies.html&quot;&gt;Hackers Block Sale of Colorado Rockies World Series Tickets&lt;/a&gt; [Associated Content, Oct 24 2007]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Loss of Sales</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2007-49</ddb:whidid>    </item>    <item>      <title>WHID 2007-06: Hackers swipe seed company&amp;#039;s customers&amp;#039; data</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34269</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2007-06: Hackers swipe seed company&amp;#039;s customers&amp;#039; data&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2007-06&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;March 29, 2007&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Monetary Loss&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;11,500 credit card numbers have been stolen from the web site of Johnny's Selected Seeds a small ($13M in revenue per annum) on line vendor of seeds in Main. 20 of these are known to have been abused. As usual, the hack was discovered because of fraudulent use of stolen credit cards rather than security measures used protect the web site.&lt;br&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;The direct cost of the breach, informing customers, researching the incident and upgrading the protection of the web site cost the company tens of thousands of dollars.&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://kennebecjournal.mainetoday.com/news/local/3676190.html&quot;&gt;Hackers swipe seed company's customers' data&lt;/a&gt; [Kennebec Journal, Mar 3 2007]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.realtime-itcompliance.com/privacy_incidents/2007/03/maine_seed_company_website_hac.htm&quot;&gt;Maine Seed Company Website Hacked: Demonstrates SMB Vulnerability &amp;amp; Questions Hacker Safe Seals&lt;/a&gt; [Realtime IT compliance, Mar 3 2007]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Retail&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA</description>      <pubDate>Wed, 16 Jun 2010 16:07:25 -0400</pubDate>      <ddb:attackedentityfield>Retail</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>March 29, 2007</ddb:dateoccured>      <ddb:entrytitle>WHID 2007-06: Hackers swipe seed company&amp;#039;s customers&amp;#039; data</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;11,500 credit card numbers have been stolen from the web site of Johnny's Selected Seeds a small ($13M in revenue per annum) on line vendor of seeds in Main. 20 of these are known to have been abused. As usual, the hack was discovered because of fraudulent use of stolen credit cards rather than security measures used protect the web site.&#13;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;The direct cost of the breach, informing customers, researching the incident and upgrading the protection of the web site cost the company tens of thousands of dollars.&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://kennebecjournal.mainetoday.com/news/local/3676190.html&quot;&gt;Hackers swipe seed company's customers' data&lt;/a&gt; [Kennebec Journal, Mar 3 2007]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.realtime-itcompliance.com/privacy_incidents/2007/03/maine_seed_company_website_hac.htm&quot;&gt;Maine Seed Company Website Hacked: Demonstrates SMB Vulnerability &amp;amp; Questions Hacker Safe Seals&lt;/a&gt; [Realtime IT compliance, Mar 3 2007]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Monetary Loss</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2007-06</ddb:whidid>    </item>    <item>      <title>WHID 2007-05: Hacking John McCain</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34264</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2007-05: Hacking John McCain&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2007-05&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;March 29, 2007&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Defacement&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;An open source developer virtually defaced John McCain's MySpace page. He did not have to commit any crime, because the page pulled an image directly from the open source developer's site.&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://mike.newsvine.com/_news/2007/03/27/633799-hacking-john-mccain&quot;&gt;Hacking John McCain&lt;/a&gt; [, Mar 27 2007]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://news.com.com/2061-10796_3-6170883.html&quot;&gt;Oops! John McCain's MySpace page gets pranked&lt;/a&gt; [CNet, Mar 27 2007]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Politics&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA</description>      <pubDate>Wed, 16 Jun 2010 16:07:38 -0400</pubDate>      <ddb:attackedentityfield>Politics</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>March 29, 2007</ddb:dateoccured>      <ddb:entrytitle>WHID 2007-05: Hacking John McCain</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;An open source developer virtually defaced John McCain's MySpace page. He did not have to commit any crime, because the page pulled an image directly from the open source developer's site.&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://mike.newsvine.com/_news/2007/03/27/633799-hacking-john-mccain&quot;&gt;Hacking John McCain&lt;/a&gt; [, Mar 27 2007]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://news.com.com/2061-10796_3-6170883.html&quot;&gt;Oops! John McCain's MySpace page gets pranked&lt;/a&gt; [CNet, Mar 27 2007]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Defacement</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2007-05</ddb:whidid>    </item>    <item>      <title>WHID 2007-04: College glitch avails student information to public</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34259</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2007-04: College glitch avails student information to public&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2007-04&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;March 27, 2007&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;A student at a community college in Sacramento who was &amp;quot;Googling&amp;quot; himself last month found his name, among 2000 others, in a file accidentally left by school staff online and picked by Google crawler.&lt;/p&gt;&lt;br&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.azcentral.com/arizonarepublic/business/articles/0310biz-googleshock0310.html&quot;&gt;College glitch avails student information to public&lt;/a&gt; [The Arizona Republic, Mar 10 2007]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Education&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA</description>      <pubDate>Wed, 16 Jun 2010 16:07:54 -0400</pubDate>      <ddb:attackedentityfield>Education</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>March 27, 2007</ddb:dateoccured>      <ddb:entrytitle>WHID 2007-04: College glitch avails student information to public</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;A student at a community college in Sacramento who was &amp;quot;Googling&amp;quot; himself last month found his name, among 2000 others, in a file accidentally left by school staff online and picked by Google crawler.&lt;/p&gt;&#13;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.azcentral.com/arizonarepublic/business/articles/0310biz-googleshock0310.html&quot;&gt;College glitch avails student information to public&lt;/a&gt; [The Arizona Republic, Mar 10 2007]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2007-04</ddb:whidid>    </item>    <item>      <title>WHID 2007-03: UI put staff data on Web</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34254</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2007-03: UI put staff data on Web&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2007-03&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;March 26, 2007&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Personal information for about 2,700 University of Idaho employees was inadvertently posted at the school's Web site for 19 days in February, though officials say it was not easy to access and there's no reason yet to believe it was misused.&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.spokesmanreview.com/tools/story_pf.asp?ID=178531&quot;&gt;UI put staff data on Web&lt;/a&gt; [Spokesman Review, Mar 10 2007]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.vandalidentity.net/default.aspx?pid=97037&quot;&gt;&lt;/a&gt; [Vandal Identity Resource Center, ]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Education&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA</description>      <pubDate>Wed, 16 Jun 2010 16:08:03 -0400</pubDate>      <ddb:attackedentityfield>Education</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>March 26, 2007</ddb:dateoccured>      <ddb:entrytitle>WHID 2007-03: UI put staff data on Web</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Personal information for about 2,700 University of Idaho employees was inadvertently posted at the school's Web site for 19 days in February, though officials say it was not easy to access and there's no reason yet to believe it was misused.&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.spokesmanreview.com/tools/story_pf.asp?ID=178531&quot;&gt;UI put staff data on Web&lt;/a&gt; [Spokesman Review, Mar 10 2007]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.vandalidentity.net/default.aspx?pid=97037&quot;&gt;&lt;/a&gt; [Vandal Identity Resource Center, ]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2007-03</ddb:whidid>    </item>    <item>      <title>WHID 2008-51: TrendMicro web site hit</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=35040</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2008-51: TrendMicro web site hit&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2008-51&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;March 15, 2008&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;The infamous &lt;a href=&quot;http://www.infoworld.com/article/08/03/14/Trend-Micro-hit-by-massive-Web-hack_1.html&quot;&gt;SQL injection bot has hit TrendMicro&lt;/a&gt;, worrying considering the fact that TrendMicro is there to protect us from malware. Unfortunately it seems that web security is still underrated  outside of a small group of experts, even though it fast becomes the modern day equivalent of the now declining viruses and worms.&lt;/p&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Technology&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;Japan</description>      <pubDate>Wed, 16 Jun 2010 14:37:38 -0400</pubDate>      <ddb:attackedentityfield>Technology</ddb:attackedentityfield>      <ddb:attackedentitygeography>Japan</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>March 15, 2008</ddb:dateoccured>      <ddb:entrytitle>WHID 2008-51: TrendMicro web site hit</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;The infamous &lt;a href=&quot;http://www.infoworld.com/article/08/03/14/Trend-Micro-hit-by-massive-Web-hack_1.html&quot;&gt;SQL injection bot has hit TrendMicro&lt;/a&gt;, worrying considering the fact that TrendMicro is there to protect us from malware. Unfortunately it seems that web security is still underrated  outside of a small group of experts, even though it fast becomes the modern day equivalent of the now declining viruses and worms.&lt;/p></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2008-51</ddb:whidid>    </item>    <item>      <title>WHID 2007-01: Credit Card Information stolen from Indiana&amp;#039;s Web Site</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34249</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2007-01: Credit Card Information stolen from Indiana&amp;#039;s Web Site&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2007-01&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;March 26, 2007&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;On January 3, a hacker broke into Indiana's government web site and made off with personal information for 71,000 health care aides who obtained certifications from the state, as well as 5,600 credit card numbers from people who had paid the state through the IN.gov web site.&lt;/p&gt;&lt;br&gt;&lt;p&gt;While officials in Indiana tried to write it off as a harmless prank played by a teenager, the U.S. Department of Justice has also been investigating the case, and they believe the same hacker is responsible for attempts on other state government web sites.&lt;/p&gt;&lt;br&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.informationweek.com/news/showArticle.jhtml?articleID=198500410&quot;&gt;Hacker Suspected Of Multistate Break-In Spree&lt;/a&gt; [Information Week, Mar 23 2007]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.theindychannel.com/news/10973406/detail.html&quot;&gt;Hacker Accesses Credit Card Info On State Web Site&lt;/a&gt; [The Indy Channel, Feb 9 2007]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.theindychannel.com/news/11315796/detail.html&quot;&gt;State Notifies 71,000 Workers Of Web Site Breach&lt;/a&gt; [The Indy Channel, Mar 21 2007]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.theindychannel.com/news/11334932/detail.html&quot;&gt;State: Web Site Breach May Have Been Prank&lt;/a&gt; [The Indy Channel, Mar 22 2007]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Government&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA</description>      <pubDate>Wed, 16 Jun 2010 16:08:18 -0400</pubDate>      <ddb:attackedentityfield>Government</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>March 26, 2007</ddb:dateoccured>      <ddb:entrytitle>WHID 2007-01: Credit Card Information stolen from Indiana&amp;#039;s Web Site</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;On January 3, a hacker broke into Indiana's government web site and made off with personal information for 71,000 health care aides who obtained certifications from the state, as well as 5,600 credit card numbers from people who had paid the state through the IN.gov web site.&lt;/p&gt;&#13;&lt;p&gt;While officials in Indiana tried to write it off as a harmless prank played by a teenager, the U.S. Department of Justice has also been investigating the case, and they believe the same hacker is responsible for attempts on other state government web sites.&lt;/p&gt;&#13;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.informationweek.com/news/showArticle.jhtml?articleID=198500410&quot;&gt;Hacker Suspected Of Multistate Break-In Spree&lt;/a&gt; [Information Week, Mar 23 2007]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.theindychannel.com/news/10973406/detail.html&quot;&gt;Hacker Accesses Credit Card Info On State Web Site&lt;/a&gt; [The Indy Channel, Feb 9 2007]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.theindychannel.com/news/11315796/detail.html&quot;&gt;State Notifies 71,000 Workers Of Web Site Breach&lt;/a&gt; [The Indy Channel, Mar 21 2007]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.theindychannel.com/news/11334932/detail.html&quot;&gt;State: Web Site Breach May Have Been Prank&lt;/a&gt; [The Indy Channel, Mar 22 2007]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2007-01</ddb:whidid>    </item>    <item>      <title>WHID 2006-42: Netscape.com hacked</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34244</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2006-42: Netscape.com hacked&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2006-42&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;July 27, 2006&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Defacement&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Most XSS vulnerabilities are benign. In many cases they are hardly exploitable. In this case Netscape's new digg like shared news site was hacked using a persistent XSS attack, so every viewer of the site was attacked, luckily only to show funny dialog boxes.&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.f-secure.com/weblog/archives/archive-072006.html#00000927&quot;&gt;Netscape.com hacked&lt;/a&gt; [F-Secure, Jul 26 2006]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://searchsecurity.techtarget.com/originalContent/0,289142,sid14_gci1204568,00.html&quot;&gt;Netscape.com hit with cross-site scripting attack&lt;/a&gt; [Search Security, Jul 26 2006]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.betanews.com/article/AOL_Fixes_Netscapecom_XSS_Hack/1153940441&quot;&gt;AOL Fixes Netscape.com XSS Hack&lt;/a&gt; [Beta News, Jul 26 2006]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.securitypronews.com/news/securitynews/spn-45-20060726NetscapeHackedProfessorDeniesSexinessClaims.html&quot;&gt;Netscape Hacked, Professor Denies Sexiness Claims&lt;/a&gt; [SecurityPro News, Jul 26 2006]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.threadwatch.org/node/7714&quot;&gt;NetScape.com - JavaScript Exploit Embaressment&lt;/a&gt; [Threadwatch.org, Jul 26 2006]&lt;/li&gt;&lt;br&gt;&lt;/ul></description>      <pubDate>Wed, 16 Jun 2010 17:06:16 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>July 27, 2006</ddb:dateoccured>      <ddb:entrytitle>WHID 2006-42: Netscape.com hacked</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Most XSS vulnerabilities are benign. In many cases they are hardly exploitable. In this case Netscape's new digg like shared news site was hacked using a persistent XSS attack, so every viewer of the site was attacked, luckily only to show funny dialog boxes.&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.f-secure.com/weblog/archives/archive-072006.html#00000927&quot;&gt;Netscape.com hacked&lt;/a&gt; [F-Secure, Jul 26 2006]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://searchsecurity.techtarget.com/originalContent/0,289142,sid14_gci1204568,00.html&quot;&gt;Netscape.com hit with cross-site scripting attack&lt;/a&gt; [Search Security, Jul 26 2006]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.betanews.com/article/AOL_Fixes_Netscapecom_XSS_Hack/1153940441&quot;&gt;AOL Fixes Netscape.com XSS Hack&lt;/a&gt; [Beta News, Jul 26 2006]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.securitypronews.com/news/securitynews/spn-45-20060726NetscapeHackedProfessorDeniesSexinessClaims.html&quot;&gt;Netscape Hacked, Professor Denies Sexiness Claims&lt;/a&gt; [SecurityPro News, Jul 26 2006]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.threadwatch.org/node/7714&quot;&gt;NetScape.com - JavaScript Exploit Embaressment&lt;/a&gt; [Threadwatch.org, Jul 26 2006]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Defacement</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2006-42</ddb:whidid>    </item>    <item>      <title>WHID 2007-50: Art.com says hacker accessed names, credit cards</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34528</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2007-50: Art.com says hacker accessed names, credit cards&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2007-50&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;October 29, 2007&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Credit Card Leakage&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;A hacker gained access to names and encrypted credit card numbers of Arts.com. While the reason is not known, since the information is known to belong to online shoppers who made transactions from July to September we assume it was a web site breach.&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.marketwatch.com/news/story/artcom-inc-hacker-accessed-some/story.aspx?guid=%7BAF391148-394C-4ED4-B9A0-01C7D2451E25%7D&amp;amp;dist=hplatest&quot;&gt;Art.com says hacker accessed names, credit cards&lt;/a&gt; [MarketWatch, Oct 28 2007]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Retail&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;Global</description>      <pubDate>Thu, 17 Jun 2010 18:22:57 -0400</pubDate>      <ddb:attackedentityfield>Retail</ddb:attackedentityfield>      <ddb:attackedentitygeography>Global</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>October 29, 2007</ddb:dateoccured>      <ddb:entrytitle>WHID 2007-50: Art.com says hacker accessed names, credit cards</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;A hacker gained access to names and encrypted credit card numbers of Arts.com. While the reason is not known, since the information is known to belong to online shoppers who made transactions from July to September we assume it was a web site breach.&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.marketwatch.com/news/story/artcom-inc-hacker-accessed-some/story.aspx?guid=%7BAF391148-394C-4ED4-B9A0-01C7D2451E25%7D&amp;amp;dist=hplatest&quot;&gt;Art.com says hacker accessed names, credit cards&lt;/a&gt; [MarketWatch, Oct 28 2007]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Credit Card Leakage</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2007-50</ddb:whidid>    </item>    <item>      <title>WHID 2006-41: Making money with MySpace bulletin system!</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34238</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2006-41: Making money with MySpace bulletin system!&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2006-41&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;July 24, 2006&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Worm&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;A bug in MySpace allowed a single click on an incoming bulletin by a person to forward it to all his contacts, making spreading a worm (or any content for that matter) too easy.&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.boogybonbon.com/2006/06/16/making-money-with-myspace-bulletin-system/&quot;&gt;Making money with Myspace bulletin system!&lt;/a&gt; [, Jun 16 2006]&lt;/li&gt;&lt;br&gt;&lt;/ul></description>      <pubDate>Wed, 16 Jun 2010 18:13:47 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>July 24, 2006</ddb:dateoccured>      <ddb:entrytitle>WHID 2006-41: Making money with MySpace bulletin system!</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;A bug in MySpace allowed a single click on an incoming bulletin by a person to forward it to all his contacts, making spreading a worm (or any content for that matter) too easy.&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.boogybonbon.com/2006/06/16/making-money-with-myspace-bulletin-system/&quot;&gt;Making money with Myspace bulletin system!&lt;/a&gt; [, Jun 16 2006]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Worm</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2006-41</ddb:whidid>    </item>    <item>      <title>WHID 2007-51: 570 Scarborough &amp;amp; Tweed customers&amp;#039; personal information accessed by SQL injection</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34533</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2007-51: 570 Scarborough &amp;amp; Tweed customers&amp;#039; personal information accessed by SQL injection&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2007-51&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;November 4, 2007&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;The web servers of Scarborough &amp;amp; Tweed, a company that does business online selling corporate gifts online, were compromised and information about 570 customers may have been accessed using an SQL injection attack. The information includes customers' names, addresses, telephone numbers, account numbers, and credit card numbers.&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.pogowasright.org/article.php?story=20071103140620396&quot;&gt;570 Scarborough &amp;amp; Tweed customers' personal information accessed by SQL injection&lt;/a&gt; [PogoWasRight.Org, Nov 3 2007]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://doj.nh.gov/consumer/pdf/ScarboroughTweed.pdf&quot;&gt;Scarborough &amp;amp; Tweed&lt;/a&gt; [State of New Hampshire, Oct 26 2007]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Retail&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA</description>      <pubDate>Wed, 16 Jun 2010 15:50:56 -0400</pubDate>      <ddb:attackedentityfield>Retail</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>November 4, 2007</ddb:dateoccured>      <ddb:entrytitle>WHID 2007-51: 570 Scarborough &amp;amp; Tweed customers&amp;#039; personal information accessed by SQL injection</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;The web servers of Scarborough &amp;amp; Tweed, a company that does business online selling corporate gifts online, were compromised and information about 570 customers may have been accessed using an SQL injection attack. The information includes customers' names, addresses, telephone numbers, account numbers, and credit card numbers.&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.pogowasright.org/article.php?story=20071103140620396&quot;&gt;570 Scarborough &amp;amp; Tweed customers' personal information accessed by SQL injection&lt;/a&gt; [PogoWasRight.Org, Nov 3 2007]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://doj.nh.gov/consumer/pdf/ScarboroughTweed.pdf&quot;&gt;Scarborough &amp;amp; Tweed&lt;/a&gt; [State of New Hampshire, Oct 26 2007]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2007-51</ddb:whidid>    </item>    <item>      <title>WHID 2006-40: Data Mining MySpace Bulletins</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34232</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2006-40: Data Mining MySpace Bulletins&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2006-40&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;July 24, 2006&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;MySpace bulletins, presumably accessible only to the social network of the originator can be access by anyone by iterating through a message id query parameter.&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://lists.grok.org.uk/pipermail/full-disclosure/2006-June/047579.html&quot;&gt;Data Mining Myspace Bulletins&lt;/a&gt; [Full Disclosure Mailing List, Jun 30 2006]&lt;/li&gt;&lt;br&gt;&lt;/ul></description>      <pubDate>Wed, 16 Jun 2010 18:17:21 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>July 24, 2006</ddb:dateoccured>      <ddb:entrytitle>WHID 2006-40: Data Mining MySpace Bulletins</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;MySpace bulletins, presumably accessible only to the social network of the originator can be access by anyone by iterating through a message id query parameter.&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://lists.grok.org.uk/pipermail/full-disclosure/2006-June/047579.html&quot;&gt;Data Mining Myspace Bulletins&lt;/a&gt; [Full Disclosure Mailing List, Jun 30 2006]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2006-40</ddb:whidid>    </item>    <item>      <title>WHID 2006-39: Another Google XSS</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34227</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2006-39: Another Google XSS&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2006-39&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;July 24, 2006&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;An XSS vulnerability in the feature allowing adding an arbitrary RSS to personal web pages. Since this page resides on the main &lt;a href=&quot;http://www.google.com&quot; title=&quot;www.google.com&quot;&gt;www.google.com&lt;/a&gt; host, the executed JavaScript can access any Google resource.&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://blog.outer-court.com/archive/2006-07-06-n81.html&quot;&gt;Google Fixes XSS Security Problem&lt;/a&gt; [Google Blogoscoped, Jul 6 2006]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://ha.ckers.org/blog/20060704/cross-site-scripting-vulnerability-in-google/&quot;&gt;Cross Site Scripting Vulnerability in Google&lt;/a&gt; [ha.ckers, Jul 4 2006]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://news.com.com/Google+fixes+security+flaw+in+Reader/2100-1002_3-6090974.html?part=rss&amp;amp;tag=6090974&amp;amp;subj=news&quot;&gt;Google fixes security flaw in Reader&lt;/a&gt; [News.com, Jul 5 2006]&lt;/li&gt;&lt;br&gt;&lt;/ul></description>      <pubDate>Wed, 16 Jun 2010 18:18:53 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>July 24, 2006</ddb:dateoccured>      <ddb:entrytitle>WHID 2006-39: Another Google XSS</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;An XSS vulnerability in the feature allowing adding an arbitrary RSS to personal web pages. Since this page resides on the main &lt;a href=&quot;http://www.google.com&quot; title=&quot;www.google.com&quot;&gt;www.google.com&lt;/a&gt; host, the executed JavaScript can access any Google resource.&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://blog.outer-court.com/archive/2006-07-06-n81.html&quot;&gt;Google Fixes XSS Security Problem&lt;/a&gt; [Google Blogoscoped, Jul 6 2006]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://ha.ckers.org/blog/20060704/cross-site-scripting-vulnerability-in-google/&quot;&gt;Cross Site Scripting Vulnerability in Google&lt;/a&gt; [ha.ckers, Jul 4 2006]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://news.com.com/Google+fixes+security+flaw+in+Reader/2100-1002_3-6090974.html?part=rss&amp;amp;tag=6090974&amp;amp;subj=news&quot;&gt;Google fixes security flaw in Reader&lt;/a&gt; [News.com, Jul 5 2006]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2006-39</ddb:whidid>    </item>    <item>      <title>WHID 2007-52: Hacker halts Rivkin auction of 37 watches</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34538</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2007-52: Hacker halts Rivkin auction of 37 watches&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2007-52&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;November 5, 2007&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Downtime&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Seems that the there is a new trend to disrupt on line bidding using denial of service attacks. In this case, an auction for 37 very expensive watches was halted 20 minutes before the end as the site crashed, in what official sources describe as a hacker attack that did not result in a site compromise.&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.news.com.au/heraldsun/story/0,21985,22703750-662,00.html&quot;&gt;Hacker halts Rivkin auction of 37 watches&lt;/a&gt; [Herald Sun, Nov 5 2007]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Retail&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;Australia</description>      <pubDate>Wed, 16 Jun 2010 15:50:56 -0400</pubDate>      <ddb:attackedentityfield>Retail</ddb:attackedentityfield>      <ddb:attackedentitygeography>Australia</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>November 5, 2007</ddb:dateoccured>      <ddb:entrytitle>WHID 2007-52: Hacker halts Rivkin auction of 37 watches</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Seems that the there is a new trend to disrupt on line bidding using denial of service attacks. In this case, an auction for 37 very expensive watches was halted 20 minutes before the end as the site crashed, in what official sources describe as a hacker attack that did not result in a site compromise.&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.news.com.au/heraldsun/story/0,21985,22703750-662,00.html&quot;&gt;Hacker halts Rivkin auction of 37 watches&lt;/a&gt; [Herald Sun, Nov 5 2007]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Downtime</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2007-52</ddb:whidid>    </item>    <item>      <title>WHID 2007-53: Google&amp;#039;s Advanced Search Operators Abused by Spammers</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34543</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2007-53: Google&amp;#039;s Advanced Search Operators Abused by Spammers&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2007-53&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;November 7, 2007&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Link Spam&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;While most WHID entries are about web site breaches, sometimes vulnerability in a web application is used indirectly. Redirection functions in web applications are commonly used by spammers and phishers. It allows them to include a honest looking URL in their e-mail, this way bypassing spam filters and observant users.&lt;/p&gt;&lt;br&gt;&lt;p&gt;Symantec response team found actively used alternative in the best known page on the internet: Google primary search page. By using the Google famous &quot;I feel lucky&quot; feature, the spammer can automatically lead the victim to the first result of a search. All the spammer is left with is finding a query for which his site would pop up first on Google.&lt;/p&gt;&lt;br&gt;&lt;p&gt;This method has another advantage over a redirection page, as the final target is specified by a search string and not by a URL, bypassing smarter filters that know, or learn, that a URL as a parameter of a URL is most probably redirection.&lt;/p&gt;&lt;br&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.symantec.com/enterprise/security_response/weblog/2007/11/googles_advanced_search_operat.html/&quot;&gt;Google's Advanced Search Operators Abused by Spammers&lt;/a&gt; [Symantec Response Team, Nov 2 2007]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Internet&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;Global</description>      <pubDate>Wed, 16 Jun 2010 15:50:56 -0400</pubDate>      <ddb:attackedentityfield>Internet</ddb:attackedentityfield>      <ddb:attackedentitygeography>Global</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>November 7, 2007</ddb:dateoccured>      <ddb:entrytitle>WHID 2007-53: Google&amp;#039;s Advanced Search Operators Abused by Spammers</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;While most WHID entries are about web site breaches, sometimes vulnerability in a web application is used indirectly. Redirection functions in web applications are commonly used by spammers and phishers. It allows them to include a honest looking URL in their e-mail, this way bypassing spam filters and observant users.&lt;/p&gt;&#13;&lt;p&gt;Symantec response team found actively used alternative in the best known page on the internet: Google primary search page. By using the Google famous &quot;I feel lucky&quot; feature, the spammer can automatically lead the victim to the first result of a search. All the spammer is left with is finding a query for which his site would pop up first on Google.&lt;/p&gt;&#13;&lt;p&gt;This method has another advantage over a redirection page, as the final target is specified by a search string and not by a URL, bypassing smarter filters that know, or learn, that a URL as a parameter of a URL is most probably redirection.&lt;/p&gt;&#13;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.symantec.com/enterprise/security_response/weblog/2007/11/googles_advanced_search_operat.html/&quot;&gt;Google's Advanced Search Operators Abused by Spammers&lt;/a&gt; [Symantec Response Team, Nov 2 2007]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Link Spam</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2007-53</ddb:whidid>    </item>    <item>      <title>WHID 2006-38: Convenience or just bad design?</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34222</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2006-38: Convenience or just bad design?&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2006-38&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;July 24, 2006&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Altiris seems to have designed their servers so that it is easy to both access their customers upload as well as find out their e-mail addresses.&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://seclists.org/lists/webappsec/2006/Jul-Sep/0052.html&quot;&gt;Convenience or just bad design?&lt;/a&gt; [WebAppSec, Jul 12 2006]&lt;/li&gt;&lt;br&gt;&lt;/ul></description>      <pubDate>Wed, 16 Jun 2010 18:19:56 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>July 24, 2006</ddb:dateoccured>      <ddb:entrytitle>WHID 2006-38: Convenience or just bad design?</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Altiris seems to have designed their servers so that it is easy to both access their customers upload as well as find out their e-mail addresses.&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://seclists.org/lists/webappsec/2006/Jul-Sep/0052.html&quot;&gt;Convenience or just bad design?&lt;/a&gt; [WebAppSec, Jul 12 2006]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2006-38</ddb:whidid>    </item>    <item>      <title>WHID 2007-54: Mistake Left Constables Open To ID theft</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34548</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2007-54: Mistake Left Constables Open To ID theft&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2007-54&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;November 7, 2007&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;An Excel spreadsheet was published on containing sensitive information regarding police officers in York, England. The information included Social Security numbers of 46 offices and the home addresses of 74 offices. As a result identities of 3 offices where stolen.&lt;/p&gt;&lt;br&gt;&lt;p&gt;While the information was pulled of line after a short period of time, it remained in the cache of several major search engines.&lt;/p&gt;&lt;br&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://nl.newsbank.com/nl-search/we/Archives?p_product=YKDB&amp;amp;p_theme=ykdb&amp;amp;p_action=search&amp;amp;p_maxdocs=200&amp;amp;s_dispstring=headline(Mistake%20left%20constables%20open%20to%20ID%20theft)%20AND%20date(2007)&amp;amp;p_field_date-0=YMD_date&amp;amp;p_params_date-0=date:B,E&amp;amp;p_text_date-0=2007&amp;amp;p_field_advanced-0=title&amp;amp;p_text_advanced-0=(&quot;Mistake%20left%20constables%20open%20to%20ID%20theft&quot;)&amp;amp;xcal_numdocs=20&amp;amp;p_perpage=10&amp;amp;p_sort=YMD_date:D&amp;amp;xcal_useweights=no0=&amp;amp;p_text_advanced-0=(&quot;Mistake%20left%20constables%20open%20to%20ID%20theft&quot;)&amp;amp;xcal_numdocs=20&amp;amp;p_perpage=10&amp;amp;p_sort=YMD_date:D&amp;amp;xcal_useweights=no&quot;&gt;Mistake left constables open to ID theft -- Clerk of Courts posted Social Security numbers online&lt;/a&gt; [York Dispatch, Sep 17 2007]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://breachblog.com/2007/09/18/yorkcountybreach.aspx&quot;&gt;Cache Comes Back to Bite York County Constables&lt;/a&gt; [The Breach Blog, Sep 18 2007]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Security &amp;amp; Law Enforcement&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;UK</description>      <pubDate>Wed, 16 Jun 2010 15:50:56 -0400</pubDate>      <ddb:attackedentityfield>Security &amp;amp; Law Enforcement</ddb:attackedentityfield>      <ddb:attackedentitygeography>UK</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>November 7, 2007</ddb:dateoccured>      <ddb:entrytitle>WHID 2007-54: Mistake Left Constables Open To ID theft</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;An Excel spreadsheet was published on containing sensitive information regarding police officers in York, England. The information included Social Security numbers of 46 offices and the home addresses of 74 offices. As a result identities of 3 offices where stolen.&lt;/p&gt;&#13;&lt;p&gt;While the information was pulled of line after a short period of time, it remained in the cache of several major search engines.&lt;/p&gt;&#13;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://nl.newsbank.com/nl-search/we/Archives?p_product=YKDB&amp;amp;p_theme=ykdb&amp;amp;p_action=search&amp;amp;p_maxdocs=200&amp;amp;s_dispstring=headline(Mistake%20left%20constables%20open%20to%20ID%20theft)%20AND%20date(2007)&amp;amp;p_field_date-0=YMD_date&amp;amp;p_params_date-0=date:B,E&amp;amp;p_text_date-0=2007&amp;amp;p_field_advanced-0=title&amp;amp;p_text_advanced-0=(&quot;Mistake%20left%20constables%20open%20to%20ID%20theft&quot;)&amp;amp;xcal_numdocs=20&amp;amp;p_perpage=10&amp;amp;p_sort=YMD_date:D&amp;amp;xcal_useweights=no0=&amp;amp;p_text_advanced-0=(&quot;Mistake%20left%20constables%20open%20to%20ID%20theft&quot;)&amp;amp;xcal_numdocs=20&amp;amp;p_perpage=10&amp;amp;p_sort=YMD_date:D&amp;amp;xcal_useweights=no&quot;&gt;Mistake left constables open to ID theft -- Clerk of Courts posted Social Security numbers online&lt;/a&gt; [York Dispatch, Sep 17 2007]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://breachblog.com/2007/09/18/yorkcountybreach.aspx&quot;&gt;Cache Comes Back to Bite York County Constables&lt;/a&gt; [The Breach Blog, Sep 18 2007]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2007-54</ddb:whidid>    </item>    <item>      <title>WHID 2007-55: Malicious Code Infects Chinese Security Site</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34553</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2007-55: Malicious Code Infects Chinese Security Site&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2007-55&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;November 7, 2007&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Planting of Malware&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Defacement are a dime a dozen this days, and are not normally reported by WHID. Even invisible defacements in which sites are changed in order to infect their clients with malicious code are becoming too common. But this time it is the site of a security organization, and not just any one, but China's internet security organization. So in the light of the hot debate about china as the source of all hacking, we think that this story has a value.&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.pcworld.com/article/id,138006-c,hackers/article.html&quot;&gt;Malicious Code Infects Chinese Security Site&lt;/a&gt; [PC World, Oct 3 2007]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Media&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;China</description>      <pubDate>Wed, 16 Jun 2010 15:50:56 -0400</pubDate>      <ddb:attackedentityfield>Media</ddb:attackedentityfield>      <ddb:attackedentitygeography>China</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>November 7, 2007</ddb:dateoccured>      <ddb:entrytitle>WHID 2007-55: Malicious Code Infects Chinese Security Site</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Defacement are a dime a dozen this days, and are not normally reported by WHID. Even invisible defacements in which sites are changed in order to infect their clients with malicious code are becoming too common. But this time it is the site of a security organization, and not just any one, but China's internet security organization. So in the light of the hot debate about china as the source of all hacking, we think that this story has a value.&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.pcworld.com/article/id,138006-c,hackers/article.html&quot;&gt;Malicious Code Infects Chinese Security Site&lt;/a&gt; [PC World, Oct 3 2007]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Planting of Malware</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2007-55</ddb:whidid>    </item>    <item>      <title>WHID 2007-87: 7-Eleven Hack From Russia Led to ATM Looting in New York</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=42604</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2007-87: 7-Eleven Hack From Russia Led to ATM Looting in New York&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2007-87&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;September 2007&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Monetary Loss&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;In his most-recent plea agreement, filed in court Monday, confessed hacker Albert Gonzalez admitted conspiring in the 7-Eleven breach and fingered two Russian associates as the direct culprits. The Russians are identified as “Hacker 1″ and “Hacker 2″ in Gonzalez’s plea agreement, and as “Grigg” and “Annex” in an earlier document inadvertently made public by his attorney.&lt;br&gt;The Russians, evidently using an SQL injection vulnerability,  “gained unauthorized access to 7-Eleven, Inc.’s servers through 7-Eleven’s public-facing internet site, and then leveraged that access into servers supporting ATM terminals located in 7-Eleven stores,” the plea agreement reads. “This access caused 7-Eleven, Inc., on or about November 9, 2007, to disable its public-facing internet site to disable the unauthorized access.”&lt;br&gt;Read More http://www.wired.com/threatlevel/2009/12/seven-eleven/#ixzz0iehheEY7&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;Russia&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Retail&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA&lt;br&gt;&lt;b&gt;Cost: &lt;/b&gt;$2,000,000.00&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://www.wired.com/threatlevel/2009/12/seven-eleven/&quot;&gt;http://www.wired.com/threatlevel/2009/12/seven-eleven/&lt;/a></description>      <pubDate>Wed, 16 Jun 2010 15:18:59 -0400</pubDate>      <ddb:attackedentityfield>Retail</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography>Russia</ddb:attacksourcegeography>      <ddb:cost>$2,000,000.00</ddb:cost>      <ddb:dateoccured>September 2007</ddb:dateoccured>      <ddb:entrytitle>WHID 2007-87: 7-Eleven Hack From Russia Led to ATM Looting in New York</ddb:entrytitle>      <ddb:incidentdescription>In his most-recent plea agreement, filed in court Monday, confessed hacker Albert Gonzalez admitted conspiring in the 7-Eleven breach and fingered two Russian associates as the direct culprits. The Russians are identified as “Hacker 1″ and “Hacker 2″ in Gonzalez’s plea agreement, and as “Grigg” and “Annex” in an earlier document inadvertently made public by his attorney.&#13;&#10;&#13;&#10;The Russians, evidently using an SQL injection vulnerability,  “gained unauthorized access to 7-Eleven, Inc.’s servers through 7-Eleven’s public-facing internet site, and then leveraged that access into servers supporting ATM terminals located in 7-Eleven stores,” the plea agreement reads. “This access caused 7-Eleven, Inc., on or about November 9, 2007, to disable its public-facing internet site to disable the unauthorized access.”&#13;&#10;&#13;&#10;Read More http://www.wired.com/threatlevel/2009/12/seven-eleven/#ixzz0iehheEY7</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Monetary Loss</ddb:outcome>      <ddb:reference>http://www.wired.com/threatlevel/2009/12/seven-eleven/</ddb:reference>      <ddb:whidid>2007-87</ddb:whidid>    </item>    <item>      <title>WHID 2007-56: TJMaxx XSS Vulnerability</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34558</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2007-56: TJMaxx XSS Vulnerability&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2007-56&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;November 7, 2007&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;A small XSS vulnerably caught RSnake eyes. What makes it different, after all xssed.com lists thousands and thousands of those? What caught RSnames eyes was the vulnerable site. TJMaxx earned the reputation as the company that suffered the biggest security breach ever. You would expect them to be more careful.&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://ha.ckers.org/blog/20070923/tjmaxx-xss-vulnerability/&quot;&gt;TJMaxx XSS Vulnerability&lt;/a&gt; [RObert Hansen (Rsnake), Sep 23 2007]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Retail&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA</description>      <pubDate>Wed, 16 Jun 2010 15:50:56 -0400</pubDate>      <ddb:attackedentityfield>Retail</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>November 7, 2007</ddb:dateoccured>      <ddb:entrytitle>WHID 2007-56: TJMaxx XSS Vulnerability</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;A small XSS vulnerably caught RSnake eyes. What makes it different, after all xssed.com lists thousands and thousands of those? What caught RSnames eyes was the vulnerable site. TJMaxx earned the reputation as the company that suffered the biggest security breach ever. You would expect them to be more careful.&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://ha.ckers.org/blog/20070923/tjmaxx-xss-vulnerability/&quot;&gt;TJMaxx XSS Vulnerability&lt;/a&gt; [RObert Hansen (Rsnake), Sep 23 2007]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2007-56</ddb:whidid>    </item>    <item>      <title>WHID 2006-37: MySpace Hack Spreading</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34216</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2006-37: MySpace Hack Spreading&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2006-37&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;July 24, 2006&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Worm&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;MySpace seems to be a heaven for XSS worms. This one seems to be even more interesting as it uses JavaScript embedded in a flash file. It is also interesting as it seems to combine the popular political defacement trend with high level application layer exploit.&lt;/p&gt;&lt;br&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://chaseandsam.com/2006/07/myspace-hack-spreading-like-wildfire.html&quot;&gt; Myspace Hack spreading like wildfire: SPAIRLKAIFS&lt;/a&gt; [Chase and Sam page, Jul 16 2006]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://kinematictheory.phpnet.us/&quot;&gt;How the myspace SWF hack worked&lt;/a&gt; [Unknown, Jul 16 2006]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.scmagazine.com/uk/news/article/569987/political+hacking+hits+myspace/&quot;&gt;Political hacking hits MySpace&lt;/a&gt; [SC Magazine, Jul 17 2006]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Web 2.0</description>      <pubDate>Wed, 16 Jun 2010 18:20:34 -0400</pubDate>      <ddb:attackedentityfield>Web 2.0</ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>July 24, 2006</ddb:dateoccured>      <ddb:entrytitle>WHID 2006-37: MySpace Hack Spreading</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;MySpace seems to be a heaven for XSS worms. This one seems to be even more interesting as it uses JavaScript embedded in a flash file. It is also interesting as it seems to combine the popular political defacement trend with high level application layer exploit.&lt;/p&gt;&#13;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://chaseandsam.com/2006/07/myspace-hack-spreading-like-wildfire.html&quot;&gt; Myspace Hack spreading like wildfire: SPAIRLKAIFS&lt;/a&gt; [Chase and Sam page, Jul 16 2006]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://kinematictheory.phpnet.us/&quot;&gt;How the myspace SWF hack worked&lt;/a&gt; [Unknown, Jul 16 2006]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.scmagazine.com/uk/news/article/569987/political+hacking+hits+myspace/&quot;&gt;Political hacking hits MySpace&lt;/a&gt; [SC Magazine, Jul 17 2006]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Worm</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2006-37</ddb:whidid>    </item>    <item>      <title>WHID 2006-35: Yahoo mail XSS in CSS expression keyword</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34211</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2006-35: Yahoo mail XSS in CSS expression keyword&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2006-35&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;May 9, 2006&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Yahoo mail does not filter properly the CSS &quot;expression&quot; keyword when it includes a comment that is encoded.&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://applesoup.googlepages.com/yahoo_mail_xss.txt&quot;&gt;Yahoo! Mail XSS Vulnerability&lt;/a&gt; [Cheng Peng Su, Apr 21 2006]&lt;/li&gt;&lt;br&gt;&lt;/ul></description>      <pubDate>Wed, 16 Jun 2010 18:22:23 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>May 9, 2006</ddb:dateoccured>      <ddb:entrytitle>WHID 2006-35: Yahoo mail XSS in CSS expression keyword</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Yahoo mail does not filter properly the CSS &quot;expression&quot; keyword when it includes a comment that is encoded.&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://applesoup.googlepages.com/yahoo_mail_xss.txt&quot;&gt;Yahoo! Mail XSS Vulnerability&lt;/a&gt; [Cheng Peng Su, Apr 21 2006]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2006-35</ddb:whidid>    </item>    <item>      <title>WHID 2006-36: PayPal Flaw Gets Accidental Two-Year Reprieve?</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34206</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2006-36: PayPal Flaw Gets Accidental Two-Year Reprieve?&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2006-36&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;July 24, 2006&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Phishing&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;While XSS vulnerabilities in public web sites are found daily, this one is of special interest. It was found in one of the sites most targeted by Phishers, it is exploitable for Phishing and was exploited. On top of that, it seems to have been discovered and reported to PayPal already two years ago but ignored due to a communication failure.&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://news.netcraft.com/archives/2006/06/16/paypal_security_flaw_allows_identity_theft.html&quot;&gt;PayPal Security Flaw allows Identity Theft&lt;/a&gt; [Netcraft, Jun 16 2006]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://news.netcraft.com/archives/2006/07/20/paypal_xss_exploit_available_for_two_years.html&quot;&gt;PayPal XSS Exploit available for two years?&lt;/a&gt; [Netcraft, Jul 20 2006]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://news.com.com/PayPal+fixes+phishing+hole/2100-7349_3-6084974.html&quot;&gt;PayPal fixes phishing hole&lt;/a&gt; [News.com, Jun 16 2006]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://computerworld.com/blogs/node/3028&quot;&gt; Responsible Disclosure? - Paypal vulnerable for two years&lt;/a&gt; [Computer World, Jul 20 2006]&lt;/li&gt;&lt;br&gt;&lt;/ul></description>      <pubDate>Wed, 16 Jun 2010 18:21:33 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>July 24, 2006</ddb:dateoccured>      <ddb:entrytitle>WHID 2006-36: PayPal Flaw Gets Accidental Two-Year Reprieve?</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;While XSS vulnerabilities in public web sites are found daily, this one is of special interest. It was found in one of the sites most targeted by Phishers, it is exploitable for Phishing and was exploited. On top of that, it seems to have been discovered and reported to PayPal already two years ago but ignored due to a communication failure.&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://news.netcraft.com/archives/2006/06/16/paypal_security_flaw_allows_identity_theft.html&quot;&gt;PayPal Security Flaw allows Identity Theft&lt;/a&gt; [Netcraft, Jun 16 2006]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://news.netcraft.com/archives/2006/07/20/paypal_xss_exploit_available_for_two_years.html&quot;&gt;PayPal XSS Exploit available for two years?&lt;/a&gt; [Netcraft, Jul 20 2006]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://news.com.com/PayPal+fixes+phishing+hole/2100-7349_3-6084974.html&quot;&gt;PayPal fixes phishing hole&lt;/a&gt; [News.com, Jun 16 2006]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://computerworld.com/blogs/node/3028&quot;&gt; Responsible Disclosure? - Paypal vulnerable for two years&lt;/a&gt; [Computer World, Jul 20 2006]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Phishing</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2006-36</ddb:whidid>    </item>    <item>      <title>WHID 2007-57: New Zealand&amp;#039;s Government Web Sites Attacked And Information Stolen</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34563</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2007-57: New Zealand&amp;#039;s Government Web Sites Attacked And Information Stolen&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2007-57&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;November 7, 2007&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;An attack on New Zealand government web sites required New Zealand Prime Minister, Helen Clark to comment and ensure the public that no confidential information was stolen. However official sources in New Zealand confirm attacks were carried out by unnamed, but known, foreign governments on New Zealand government web site that resulted in stealing of information.&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.nzherald.co.nz/section/story.cfm?c_id=5&amp;amp;objectid=10462899&quot;&gt;No classified data lost in cyber attacks - Clark&lt;/a&gt; [The New Zealand Herald, Sep 11 2007]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Government&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;New Zealand</description>      <pubDate>Wed, 16 Jun 2010 15:50:56 -0400</pubDate>      <ddb:attackedentityfield>Government</ddb:attackedentityfield>      <ddb:attackedentitygeography>New Zealand</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>November 7, 2007</ddb:dateoccured>      <ddb:entrytitle>WHID 2007-57: New Zealand&amp;#039;s Government Web Sites Attacked And Information Stolen</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;An attack on New Zealand government web sites required New Zealand Prime Minister, Helen Clark to comment and ensure the public that no confidential information was stolen. However official sources in New Zealand confirm attacks were carried out by unnamed, but known, foreign governments on New Zealand government web site that resulted in stealing of information.&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.nzherald.co.nz/section/story.cfm?c_id=5&amp;amp;objectid=10462899&quot;&gt;No classified data lost in cyber attacks - Clark&lt;/a&gt; [The New Zealand Herald, Sep 11 2007]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2007-57</ddb:whidid>    </item>    <item>      <title>WHID 2006-34: XSS Exploit at sms.ac</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34201</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2006-34: XSS Exploit at sms.ac&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2006-34&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;May 9, 2006&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;This community site allows including scripts in multiple locations including ones personal profile thus enabling XSS.&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://addict3d.org/index.php?page=viewarticle&amp;amp;type=security&amp;amp;ID=5754&amp;amp;title=XSS%20Exploit%20at%20sms.ac&quot;&gt; XSS Exploit at sms.ac&lt;/a&gt; [Addict3D, Jan 3 2006]&lt;/li&gt;&lt;br&gt;&lt;/ul></description>      <pubDate>Wed, 16 Jun 2010 18:22:53 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>May 9, 2006</ddb:dateoccured>      <ddb:entrytitle>WHID 2006-34: XSS Exploit at sms.ac</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;This community site allows including scripts in multiple locations including ones personal profile thus enabling XSS.&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://addict3d.org/index.php?page=viewarticle&amp;amp;type=security&amp;amp;ID=5754&amp;amp;title=XSS%20Exploit%20at%20sms.ac&quot;&gt; XSS Exploit at sms.ac&lt;/a&gt; [Addict3D, Jan 3 2006]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2006-34</ddb:whidid>    </item>    <item>      <title>WHID 2006-33: Alexadex.com players.py XSS Exploit</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34196</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2006-33: Alexadex.com players.py XSS Exploit&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2006-33&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;May 9, 2006&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Disclosure Only&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Alexadex is an online investment game. There is an XSS vulnerability in the group adding functionality.&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://seclists.org/lists/bugtraq/2006/May/0113.html&quot;&gt;Alexadex.com players.py XSS Exploit&lt;/a&gt; [Bugtraq, May 5 2006]&lt;/li&gt;&lt;br&gt;&lt;/ul></description>      <pubDate>Wed, 16 Jun 2010 18:23:48 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>May 9, 2006</ddb:dateoccured>      <ddb:entrytitle>WHID 2006-33: Alexadex.com players.py XSS Exploit</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Alexadex is an online investment game. There is an XSS vulnerability in the group adding functionality.&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://seclists.org/lists/bugtraq/2006/May/0113.html&quot;&gt;Alexadex.com players.py XSS Exploit&lt;/a&gt; [Bugtraq, May 5 2006]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Disclosure Only</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2006-33</ddb:whidid>    </item>    <item>      <title>WHID 2007-58: Internet Retailer Publisher Victim of Customer File Hack</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34569</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2007-58: Internet Retailer Publisher Victim of Customer File Hack&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2007-58&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;November 7, 2007&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Vertical Web Media, publisher of Internet Retailer magazine, suffered a security &lt;a href=&quot;http://www.theregister.co.uk/2007/08/17/gentoo_disconnects_vulnerable_server/breach&quot; title=&quot;http://www.theregister.co.uk/2007/08/17/gentoo_disconnects_vulnerable_server/breach&quot;&gt;http://www.theregister.co.uk/2007/08/17/gentoo_disconnects_vulnerable_se...&lt;/a&gt; and credit card information of readers had been stolen. The Irony is that Internet Retailed magazine is covering the risks of e-commerce.&lt;/p&gt;&lt;br&gt;&lt;p&gt;While the actual technique used is not known, signs are that it was a web hack as it was done by a distributed network of bots all over the world and since the information stolen belonged to customers who paid online.&lt;/p&gt;&lt;br&gt;&lt;p&gt;The information stolen includes names, addresses, e-mail addresses, phone numbers, credit card account numbers and card expiration dates. The Number_of_Records stolen is unknown.&lt;/p&gt;&lt;br&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://publications.mediapost.com/index.cfm?fuseaction=Articles.showArticleHomePage&amp;amp;art_aid=67559&quot;&gt;Internet Retailer Publisher Victim Of Customer File Hack&lt;/a&gt; [NBC.com, Sep 18 2007]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Media&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA</description>      <pubDate>Wed, 16 Jun 2010 15:50:56 -0400</pubDate>      <ddb:attackedentityfield>Media</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>November 7, 2007</ddb:dateoccured>      <ddb:entrytitle>WHID 2007-58: Internet Retailer Publisher Victim of Customer File Hack</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Vertical Web Media, publisher of Internet Retailer magazine, suffered a security &lt;a href=&quot;http://www.theregister.co.uk/2007/08/17/gentoo_disconnects_vulnerable_server/breach&quot; title=&quot;http://www.theregister.co.uk/2007/08/17/gentoo_disconnects_vulnerable_server/breach&quot;&gt;http://www.theregister.co.uk/2007/08/17/gentoo_disconnects_vulnerable_se...&lt;/a&gt; and credit card information of readers had been stolen. The Irony is that Internet Retailed magazine is covering the risks of e-commerce.&lt;/p&gt;&#13;&lt;p&gt;While the actual technique used is not known, signs are that it was a web hack as it was done by a distributed network of bots all over the world and since the information stolen belonged to customers who paid online.&lt;/p&gt;&#13;&lt;p&gt;The information stolen includes names, addresses, e-mail addresses, phone numbers, credit card account numbers and card expiration dates. The Number_of_Records stolen is unknown.&lt;/p&gt;&#13;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://publications.mediapost.com/index.cfm?fuseaction=Articles.showArticleHomePage&amp;amp;art_aid=67559&quot;&gt;Internet Retailer Publisher Victim Of Customer File Hack&lt;/a&gt; [NBC.com, Sep 18 2007]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2007-58</ddb:whidid>    </item>    <item>      <title>WHID 2008-50: The Indian government acknowledges hacking incidents</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=35035</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2008-50: The Indian government acknowledges hacking incidents&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2008-50&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;February 29, 2008&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;An official Indian government &lt;a href=&quot;http://pib.nic.in/release/release.asp?relid=36142&quot;&gt;response &lt;/a&gt;to a question in the Indian parliament, the Minister of State for Communications and Information Technology discusses hacking incidents which occurred between 2005 and 2008 in a large number of Indian government agencies. The interesting information is the list of agencies affected:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;Ministry of Railways, &lt;/li&gt;&lt;br&gt;&lt;li&gt;Air Cargo Customs (Mumbai), &lt;/li&gt;&lt;br&gt;&lt;li&gt;Forward markets Commission, &lt;/li&gt;&lt;br&gt;&lt;li&gt;National Institute of Health and Family Welfare, &lt;/li&gt;&lt;br&gt;&lt;li&gt;National Institute of Social Defence, &lt;/li&gt;&lt;br&gt;&lt;li&gt;Department of Administrative Reforms and Public Grievances, &lt;/li&gt;&lt;br&gt;&lt;li&gt;Wireless Planning &amp;amp; Coordination Wing, &lt;/li&gt;&lt;br&gt;&lt;li&gt;Bharat Sanchar Nigam Limited, &lt;/li&gt;&lt;br&gt;&lt;li&gt;Telecom Regulatory Authority of India, &lt;/li&gt;&lt;br&gt;&lt;li&gt;Department of Information Technology and &lt;/li&gt;&lt;br&gt;&lt;li&gt;Anthropological Survey of India. &lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Government&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;India</description>      <pubDate>Wed, 16 Jun 2010 14:39:29 -0400</pubDate>      <ddb:attackedentityfield>Government</ddb:attackedentityfield>      <ddb:attackedentitygeography>India</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>February 29, 2008</ddb:dateoccured>      <ddb:entrytitle>WHID 2008-50: The Indian government acknowledges hacking incidents</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;An official Indian government &lt;a href=&quot;http://pib.nic.in/release/release.asp?relid=36142&quot;&gt;response &lt;/a&gt;to a question in the Indian parliament, the Minister of State for Communications and Information Technology discusses hacking incidents which occurred between 2005 and 2008 in a large number of Indian government agencies. The interesting information is the list of agencies affected:&lt;/p&gt;&#13;&#10;&lt;ul&gt;&#13;&#10;&lt;li&gt;Ministry of Railways, &lt;/li&gt;&#13;&#10;&lt;li&gt;Air Cargo Customs (Mumbai), &lt;/li&gt;&#13;&#10;&lt;li&gt;Forward markets Commission, &lt;/li&gt;&#13;&#10;&lt;li&gt;National Institute of Health and Family Welfare, &lt;/li&gt;&#13;&#10;&lt;li&gt;National Institute of Social Defence, &lt;/li&gt;&#13;&#10;&lt;li&gt;Department of Administrative Reforms and Public Grievances, &lt;/li&gt;&#13;&#10;&lt;li&gt;Wireless Planning &amp;amp; Coordination Wing, &lt;/li&gt;&#13;&#10;&lt;li&gt;Bharat Sanchar Nigam Limited, &lt;/li&gt;&#13;&#10;&lt;li&gt;Telecom Regulatory Authority of India, &lt;/li&gt;&#13;&#10;&lt;li&gt;Department of Information Technology and &lt;/li&gt;&#13;&#10;&lt;li&gt;Anthropological Survey of India. &lt;/li&gt;&#13;&#10;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2008-50</ddb:whidid>    </item>    <item>      <title>WHID 2006-32: libero.it XSS vulnerability - HTML injection</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34191</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2006-32: libero.it XSS vulnerability - HTML injection&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2006-32&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;May 9, 2006&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Disclosure Only&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Libero.it is a Web portal of big Italian ISP offering dial-up, Broadband and talk services. A script on it's customer service pages which enabled a connection speed test is vulnerable to XSS.&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://seclists.org/lists/bugtraq/2006/May/0079.html&quot;&gt;libero.it XSS vulnerability - HTML injection&lt;/a&gt; [Bugtraq (Posted by Davide Denicolo), May 2 2006]&lt;/li&gt;&lt;br&gt;&lt;/ul></description>      <pubDate>Wed, 16 Jun 2010 18:24:39 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>May 9, 2006</ddb:dateoccured>      <ddb:entrytitle>WHID 2006-32: libero.it XSS vulnerability - HTML injection</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Libero.it is a Web portal of big Italian ISP offering dial-up, Broadband and talk services. A script on it's customer service pages which enabled a connection speed test is vulnerable to XSS.&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://seclists.org/lists/bugtraq/2006/May/0079.html&quot;&gt;libero.it XSS vulnerability - HTML injection&lt;/a&gt; [Bugtraq (Posted by Davide Denicolo), May 2 2006]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Disclosure Only</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2006-32</ddb:whidid>    </item>    <item>      <title>WHID 2007-59: Hackers jack Monster.com, infect job hunters</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34579</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2007-59: Hackers jack Monster.com, infect job hunters&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2007-59&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;November 21, 2007&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Planting of Malware&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;A Crimeware iframe tag on a site is not news anymore. On Monster.com it is.&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;articleId=9048019&quot;&gt;Hackers jack Monster.com, infect job hunters&lt;/a&gt; [Computer World, Nov 20 2007]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Internet&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA</description>      <pubDate>Wed, 16 Jun 2010 15:50:56 -0400</pubDate>      <ddb:attackedentityfield>Internet</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>November 21, 2007</ddb:dateoccured>      <ddb:entrytitle>WHID 2007-59: Hackers jack Monster.com, infect job hunters</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;A Crimeware iframe tag on a site is not news anymore. On Monster.com it is.&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;articleId=9048019&quot;&gt;Hackers jack Monster.com, infect job hunters&lt;/a&gt; [Computer World, Nov 20 2007]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Planting of Malware</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2007-59</ddb:whidid>    </item>    <item>      <title>WHID 2007-60: The blog of a Cambridge University security team hacked</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34584</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2007-60: The blog of a Cambridge University security team hacked&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2007-60&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;December 19, 2007&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Downtime&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;This story probably represents hundreds of similar stories. Many of us have come to rely on open source software, which is useful, feature reach and free. It enables us access to tools available to a few only a couple of years ago. The downside is that this easy availability means that many use the tools without having the time, resources and expertise to protect them. Systems such as &lt;a href=&quot;http://www.phpbb.com&quot;&gt;phpBB&lt;/a&gt; and &lt;a href=&quot;http://www.wordpress.org&quot;&gt;WordPress&lt;/a&gt; are good&lt;br /&gt;examples of very popular open source systems that require constant&lt;br /&gt;attention in order to maintain secure.&lt;/p&gt;&lt;br&gt;&lt;p&gt;I am sure that the guys at Light Blue Touchpaper have the expertise to protect their WordPress installation, but they dont have the time. They made the compromise between ease of management of their web site and its security. Actually my &lt;a href=&quot;http://blog.shezaf.com&quot;&gt;personal blog&lt;/a&gt; might be just as vulnerable, since as I write this I am very much not paying attention to its security.&lt;/p&gt;&lt;br&gt;&lt;p&gt;Apart from, or actually because of  the fact that the victims are security experts, this story is noteworthy due to two additional twists in the plot:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;Zero day exploit in the wild - the attacker penetrated twice, once using a known SQL injection vulnerability, but the second time using a yet unknown vulnerability in WordPress, which was reverse engineered and published for the first time by the people at Light Blue Touchpaper.&lt;/li&gt;&lt;br&gt;&lt;p&gt;&lt;/p&gt;&lt;br&gt;&lt;li&gt;The researchers found that they can use Google to retrieve the hashed password of the hacker. Google has become so big that it actually allows efficient encrypted passwords lookup.&lt;/li&gt;&lt;br&gt;&lt;p&gt;&lt;br&gt;&lt;/p&gt;&lt;/ul&gt;&lt;br&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.lightbluetouchpaper.org/2007/10/27/upgrade-and-new-theme/&quot;&gt;Upgrade and new theme&lt;/a&gt; [Light Blue Touchpaper Blog, Oct 27 2007]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.lightbluetouchpaper.org/2007/11/16/google-as-a-password-cracker/&quot;&gt;Google as a password cracker&lt;/a&gt; [Light Blue Touchpaper Blog, Nov 16 2007]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://blogs.guardian.co.uk/technology/2007/11/23/forgotten_your_password_google_can_find_it_for_you_unfortunately.html&quot;&gt;Forgotten your password? Google can find it for you. Unfortunately&lt;/a&gt; [Technology Guardian, Nov 23 2007]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.lightbluetouchpaper.org/2007/11/20/wordpress-cookie-authentication-vulnerability/&quot;&gt;Wordpress cookie authentication vulnerability&lt;/a&gt; [Light Blue Touchpaper Blog, Nov 20 2007]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Education&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;UK&lt;br&gt;&lt;b&gt;Attacked System Technology: &lt;/b&gt;WordPress</description>      <pubDate>Wed, 16 Jun 2010 15:50:56 -0400</pubDate>      <ddb:attackedentityfield>Education</ddb:attackedentityfield>      <ddb:attackedentitygeography>UK</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology>WordPress</ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>December 19, 2007</ddb:dateoccured>      <ddb:entrytitle>WHID 2007-60: The blog of a Cambridge University security team hacked</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;This story probably represents hundreds of similar stories. Many of us have come to rely on open source software, which is useful, feature reach and free. It enables us access to tools available to a few only a couple of years ago. The downside is that this easy availability means that many use the tools without having the time, resources and expertise to protect them. Systems such as &lt;a href=&quot;http://www.phpbb.com&quot;&gt;phpBB&lt;/a&gt; and &lt;a href=&quot;http://www.wordpress.org&quot;&gt;WordPress&lt;/a&gt; are good&lt;br /&gt;examples of very popular open source systems that require constant&lt;br /&gt;attention in order to maintain secure.&lt;/p&gt;&#13;&lt;p&gt;I am sure that the guys at Light Blue Touchpaper have the expertise to protect their WordPress installation, but they dont have the time. They made the compromise between ease of management of their web site and its security. Actually my &lt;a href=&quot;http://blog.shezaf.com&quot;&gt;personal blog&lt;/a&gt; might be just as vulnerable, since as I write this I am very much not paying attention to its security.&lt;/p&gt;&#13;&lt;p&gt;Apart from, or actually because of  the fact that the victims are security experts, this story is noteworthy due to two additional twists in the plot:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;Zero day exploit in the wild - the attacker penetrated twice, once using a known SQL injection vulnerability, but the second time using a yet unknown vulnerability in WordPress, which was reverse engineered and published for the first time by the people at Light Blue Touchpaper.&lt;/li&gt;&#13;&lt;p&gt;&lt;/p&gt;&#13;&lt;li&gt;The researchers found that they can use Google to retrieve the hashed password of the hacker. Google has become so big that it actually allows efficient encrypted passwords lookup.&lt;/li&gt;&#13;&lt;p&gt;&#13;&lt;/p&gt;&lt;/ul&gt;&#13;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.lightbluetouchpaper.org/2007/10/27/upgrade-and-new-theme/&quot;&gt;Upgrade and new theme&lt;/a&gt; [Light Blue Touchpaper Blog, Oct 27 2007]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.lightbluetouchpaper.org/2007/11/16/google-as-a-password-cracker/&quot;&gt;Google as a password cracker&lt;/a&gt; [Light Blue Touchpaper Blog, Nov 16 2007]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://blogs.guardian.co.uk/technology/2007/11/23/forgotten_your_password_google_can_find_it_for_you_unfortunately.html&quot;&gt;Forgotten your password? Google can find it for you. Unfortunately&lt;/a&gt; [Technology Guardian, Nov 23 2007]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.lightbluetouchpaper.org/2007/11/20/wordpress-cookie-authentication-vulnerability/&quot;&gt;Wordpress cookie authentication vulnerability&lt;/a&gt; [Light Blue Touchpaper Blog, Nov 20 2007]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Downtime</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2007-60</ddb:whidid>    </item>    <item>      <title>WHID 2007-61: Another inconvenient truth: Al Gore&amp;#039;s Web site hacked</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34591</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2007-61: Another inconvenient truth: Al Gore&amp;#039;s Web site hacked&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2007-61&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;December 19, 2007&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Link Spam&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Whether comment spam by itself is an application failure or a necessary evil for site allowing rich comments is an open question. However it is reported that in this case vulnerability in WordPress allowed the spammers to actually penetrate the site and modify pages and not just abuse comments.&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.pcworld.com/article/id,139945-pg,1/article.html&quot;&gt;Another inconvenient truth: Al Gore's Web site hacked&lt;/a&gt; [PC World, Nov 26 2007]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://blog.wired.com/business/2007/11/blog-link-spam.html&quot;&gt;Blog Link Spam Claims Another Victim: Al Gore&lt;/a&gt; [Wired, Nov 27 2007]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Politics&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA&lt;br&gt;&lt;b&gt;Attacked System Technology: &lt;/b&gt;WordPress</description>      <pubDate>Wed, 16 Jun 2010 15:50:56 -0400</pubDate>      <ddb:attackedentityfield>Politics</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology>WordPress</ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>December 19, 2007</ddb:dateoccured>      <ddb:entrytitle>WHID 2007-61: Another inconvenient truth: Al Gore&amp;#039;s Web site hacked</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Whether comment spam by itself is an application failure or a necessary evil for site allowing rich comments is an open question. However it is reported that in this case vulnerability in WordPress allowed the spammers to actually penetrate the site and modify pages and not just abuse comments.&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.pcworld.com/article/id,139945-pg,1/article.html&quot;&gt;Another inconvenient truth: Al Gore's Web site hacked&lt;/a&gt; [PC World, Nov 26 2007]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://blog.wired.com/business/2007/11/blog-link-spam.html&quot;&gt;Blog Link Spam Claims Another Victim: Al Gore&lt;/a&gt; [Wired, Nov 27 2007]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Link Spam</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2007-61</ddb:whidid>    </item>    <item>      <title>WHID 2007-62: A security flaw in Passport Canada&amp;#039;s website</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34596</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2007-62: A security flaw in Passport Canada&amp;#039;s website&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2007-62&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;December 19, 2007&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Monetary Loss&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;The Web site of the Canadian passports authority enables users to access others' record by modifying a value of a parameter in the URI.&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.theglobeandmail.com/servlet/Page/document/v5/content/subscribe?user_URL=http://www.theglobeandmail.com%2Fservlet%2Fstory%2FRTGAM.20071204.wpassport1204%2FBNStory%2FNational%2Fhome&amp;amp;ord=258556&amp;amp;brand=theglobeandmail&amp;amp;force_login=true&quot;&gt;Passport applicant finds massive privacy breach&lt;/a&gt; [The Globe and Mail, Dec 4 2007]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.cbc.ca/canada/ottawa/story/2007/12/04/passport-security.html&quot;&gt;Passport Canada strengthens online security following breach&lt;/a&gt; [CBC, Dec 4 2007]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Government&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;Canada</description>      <pubDate>Wed, 16 Jun 2010 15:50:56 -0400</pubDate>      <ddb:attackedentityfield>Government</ddb:attackedentityfield>      <ddb:attackedentitygeography>Canada</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>December 19, 2007</ddb:dateoccured>      <ddb:entrytitle>WHID 2007-62: A security flaw in Passport Canada&amp;#039;s website</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;The Web site of the Canadian passports authority enables users to access others' record by modifying a value of a parameter in the URI.&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.theglobeandmail.com/servlet/Page/document/v5/content/subscribe?user_URL=http://www.theglobeandmail.com%2Fservlet%2Fstory%2FRTGAM.20071204.wpassport1204%2FBNStory%2FNational%2Fhome&amp;amp;ord=258556&amp;amp;brand=theglobeandmail&amp;amp;force_login=true&quot;&gt;Passport applicant finds massive privacy breach&lt;/a&gt; [The Globe and Mail, Dec 4 2007]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.cbc.ca/canada/ottawa/story/2007/12/04/passport-security.html&quot;&gt;Passport Canada strengthens online security following breach&lt;/a&gt; [CBC, Dec 4 2007]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Monetary Loss</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2007-62</ddb:whidid>    </item>    <item>      <title>WHID 2007-63: Credit card data theft at Kartenhaus, a Ticketmaster German subsidiary</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34601</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2007-63: Credit card data theft at Kartenhaus, a Ticketmaster German subsidiary&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2007-63&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;December 19, 2007&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Credit Card Leakage&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;An unidentified group had stolen credit card numbers and billing addresses of the Hamburg, Germany ticket sales office Kartenhaus, a subsidiary of Ticketmaster. Some 66,000 customers who purchased tickets with a credit card from the Kartenhaus.de web site between October 24, 2006 and September 30, 2007 were affected.&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.heise.de/english/newsticker/news/96992&quot;&gt;Theft of credit card data affects tens of thousands of Kartenhaus customers&lt;/a&gt; [Heise, Oct 5 2007]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Retail&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;Germany</description>      <pubDate>Thu, 17 Jun 2010 18:22:28 -0400</pubDate>      <ddb:attackedentityfield>Retail</ddb:attackedentityfield>      <ddb:attackedentitygeography>Germany</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>December 19, 2007</ddb:dateoccured>      <ddb:entrytitle>WHID 2007-63: Credit card data theft at Kartenhaus, a Ticketmaster German subsidiary</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;An unidentified group had stolen credit card numbers and billing addresses of the Hamburg, Germany ticket sales office Kartenhaus, a subsidiary of Ticketmaster. Some 66,000 customers who purchased tickets with a credit card from the Kartenhaus.de web site between October 24, 2006 and September 30, 2007 were affected.&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.heise.de/english/newsticker/news/96992&quot;&gt;Theft of credit card data affects tens of thousands of Kartenhaus customers&lt;/a&gt; [Heise, Oct 5 2007]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Credit Card Leakage</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2007-63</ddb:whidid>    </item>    <item>      <title>WHID 2006-31: URL Bug On 1ASPHost and DomainDLX Hosting Services</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34186</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2006-31: URL Bug On 1ASPHost and DomainDLX Hosting Services&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2006-31&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;May 9, 2006&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Disclosure Only&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;A researcher found that the login error page on this sites can be injected.&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://seclists.org/lists/bugtraq/2006/May/0121.html&quot;&gt;URL Bug On 1ASPHost and DomainDLX Hosting Services&lt;/a&gt; [Bugtraq, Jun 6 2006]&lt;/li&gt;&lt;br&gt;&lt;/ul></description>      <pubDate>Wed, 16 Jun 2010 18:25:05 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>May 9, 2006</ddb:dateoccured>      <ddb:entrytitle>WHID 2006-31: URL Bug On 1ASPHost and DomainDLX Hosting Services</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;A researcher found that the login error page on this sites can be injected.&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://seclists.org/lists/bugtraq/2006/May/0121.html&quot;&gt;URL Bug On 1ASPHost and DomainDLX Hosting Services&lt;/a&gt; [Bugtraq, Jun 6 2006]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Disclosure Only</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2006-31</ddb:whidid>    </item>    <item>      <title>WHID 2006-30: National Secret Agency of Slovak Republic Hacked</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34181</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2006-30: National Secret Agency of Slovak Republic Hacked&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2006-30&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;April 30, 2006&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;A hacker successfully abuse a vulnerability in Horde to penetrate a site owned by the National Security Agency of the Slovak Republic&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://blackhole.sk/node/442&quot;&gt;Narodny Bezpecnostny Urad pwn3d (Slovak with Code Snippets&lt;/a&gt; [Blackhole.sk, Apr 25 2006]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.securityfocus.com/archive/75/432202&quot;&gt;National Secret Agency of Slovak Republic&lt;/a&gt; [Incidents Mailing List, Apr 26 2006]&lt;/li&gt;&lt;br&gt;&lt;/ul></description>      <pubDate>Wed, 16 Jun 2010 18:26:51 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>April 30, 2006</ddb:dateoccured>      <ddb:entrytitle>WHID 2006-30: National Secret Agency of Slovak Republic Hacked</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;A hacker successfully abuse a vulnerability in Horde to penetrate a site owned by the National Security Agency of the Slovak Republic&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://blackhole.sk/node/442&quot;&gt;Narodny Bezpecnostny Urad pwn3d (Slovak with Code Snippets&lt;/a&gt; [Blackhole.sk, Apr 25 2006]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.securityfocus.com/archive/75/432202&quot;&gt;National Secret Agency of Slovak Republic&lt;/a&gt; [Incidents Mailing List, Apr 26 2006]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2006-30</ddb:whidid>    </item>    <item>      <title>WHID 2006-28: Tlen.PL e-mail XSS vulnerability</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34176</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2006-28: Tlen.PL e-mail XSS vulnerability&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2006-28&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;April 20, 2006&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Disclosure Only&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Tlen.PL is a popular Polish IM system provided by o2.pl, which includes e-mail accounts. The e-mail client is web based with a browser embedded in the communicator software. Certain webmail servers do not validate e-mail subject for HTML tags, allowing attacker to inject script code.&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://security.pass.pl/adv/160406_XSS_tlen_pl.txt&quot;&gt;Tlen.PL e-mail XSS vulnerability&lt;/a&gt; [&lt;a href=&quot;http://security.pass.pl/&quot;&gt;Tomasz Koperski&lt;/a&gt;, ]&lt;/li&gt;&lt;br&gt;&lt;/ul></description>      <pubDate>Wed, 16 Jun 2010 18:28:05 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>April 20, 2006</ddb:dateoccured>      <ddb:entrytitle>WHID 2006-28: Tlen.PL e-mail XSS vulnerability</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Tlen.PL is a popular Polish IM system provided by o2.pl, which includes e-mail accounts. The e-mail client is web based with a browser embedded in the communicator software. Certain webmail servers do not validate e-mail subject for HTML tags, allowing attacker to inject script code.&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://security.pass.pl/adv/160406_XSS_tlen_pl.txt&quot;&gt;Tlen.PL e-mail XSS vulnerability&lt;/a&gt; [&lt;a href=&quot;http://security.pass.pl/&quot;&gt;Tomasz Koperski&lt;/a&gt;, ]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Disclosure Only</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2006-28</ddb:whidid>    </item>    <item>      <title>WHID 2007-64: Information about Duke&amp;#039;s Students and Applicants Stolen</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34606</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2007-64: Information about Duke&amp;#039;s Students and Applicants Stolen&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2007-64&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;December 19, 2007&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;The personal data of nearly 1,400 prospective Duke Law School students may have been stolen by a hacker from two separate databases, one including the prospective students' data and another filled with requests for information about the school.&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.upi.com/NewsTrack/Top_News/2007/12/05/hacker_may_have_stolen_duke_students_data/2789/&quot;&gt;Hacker may have stolen Duke students' data&lt;/a&gt; [UPI, Dec 5 2007]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Education&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA</description>      <pubDate>Wed, 16 Jun 2010 15:50:56 -0400</pubDate>      <ddb:attackedentityfield>Education</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>December 19, 2007</ddb:dateoccured>      <ddb:entrytitle>WHID 2007-64: Information about Duke&amp;#039;s Students and Applicants Stolen</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;The personal data of nearly 1,400 prospective Duke Law School students may have been stolen by a hacker from two separate databases, one including the prospective students' data and another filled with requests for information about the school.&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.upi.com/NewsTrack/Top_News/2007/12/05/hacker_may_have_stolen_duke_students_data/2789/&quot;&gt;Hacker may have stolen Duke students' data&lt;/a&gt; [UPI, Dec 5 2007]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2007-64</ddb:whidid>    </item>    <item>      <title>WHID 2009-7: China&amp;#039;s Yeepay.com Suffers Internet Payment Hacker Attack</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=35051</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2009-7: China&amp;#039;s Yeepay.com Suffers Internet Payment Hacker Attack&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2009-7&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;January 19, 2009&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Downtime&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;China retail news &lt;a href=&quot;http://www.chinaretailnews.com/2009/01/19/2134-chinas-yeepaycom-suffers-internet-payment-hacker-attack/&quot;&gt;reports &lt;/a&gt;that Yeepay, a Chinese online payments provider suffered a major denial of service attack. The story seems to be &lt;a href=&quot;http://64.233.183.101/translate_c?hl=en&amp;amp;u=http://www.yeepay.com/html/gg/index.shtml&amp;amp;usg=ALkJrhgN9F-Iyzd_zXN5TPFdGiHzFO1eww&quot;&gt;big in China&lt;/a&gt;, but hardly made it to the west.&lt;/p&gt;&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Finance&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;China</description>      <pubDate>Wed, 16 Jun 2010 14:23:05 -0400</pubDate>      <ddb:attackedentityfield>Finance</ddb:attackedentityfield>      <ddb:attackedentitygeography>China</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>January 19, 2009</ddb:dateoccured>      <ddb:entrytitle>WHID 2009-7: China&amp;#039;s Yeepay.com Suffers Internet Payment Hacker Attack</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;China retail news &lt;a href=&quot;http://www.chinaretailnews.com/2009/01/19/2134-chinas-yeepaycom-suffers-internet-payment-hacker-attack/&quot;&gt;reports &lt;/a&gt;that Yeepay, a Chinese online payments provider suffered a major denial of service attack. The story seems to be &lt;a href=&quot;http://64.233.183.101/translate_c?hl=en&amp;amp;u=http://www.yeepay.com/html/gg/index.shtml&amp;amp;usg=ALkJrhgN9F-Iyzd_zXN5TPFdGiHzFO1eww&quot;&gt;big in China&lt;/a&gt;, but hardly made it to the west.&lt;/p></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Downtime</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2009-7</ddb:whidid>    </item>    <item>      <title>WHID 2007-65: Facebook suing a porn site over automated access</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34611</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2007-65: Facebook suing a porn site over automated access&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2007-65&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;December 19, 2007&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Use of robots and automated software against a web site, as long as it is not done in order to break into the site, falls into a grey area. While hard to classify as an unlawful act, it is usually harmful to the site owner and possibly to the site users. Apart from using valuable resources, such an automated access may breach the site's usage license of public information and might also indicate unlawful activity such as using a botnet. Many times it is hard to know if such a blast of requests is a denial of service attack, brute force password cracking or just a search engine crawler.&lt;/p&gt;&lt;br&gt;&lt;p&gt;Going forward we are going to add such incidents to WHID if there is a reason to believe that they are not friendly, even if the actual goal of the attack cannot be easily classified. The Facebook case at hand is a perfect example: while the details are not clear, the fact that Facebook filed a law suit implies that there is fire behind the smoke.&lt;/p&gt;&lt;br&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://docs.justia.com/cases/federal/district-courts/california/candce/5:2007cv03404/193531/17/0.pdf&quot;&gt;Facebook vs. John Doe&lt;/a&gt; [US District Court, San Jose, CA, Oct 23 2007]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.theregister.co.uk/2007/12/17/facebook_hack_attack_lawsuit/&quot;&gt;Facebook sues Canadian smut firm over hacking&lt;/a&gt; [The Register, Dec 17 2007]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.thestar.com/article/286091&quot;&gt;Facebook suing Ontario porn firm&lt;/a&gt; [The Star, Dec 16 2007]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Internet</description>      <pubDate>Wed, 16 Jun 2010 15:37:13 -0400</pubDate>      <ddb:attackedentityfield>Internet</ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>December 19, 2007</ddb:dateoccured>      <ddb:entrytitle>WHID 2007-65: Facebook suing a porn site over automated access</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Use of robots and automated software against a web site, as long as it is not done in order to break into the site, falls into a grey area. While hard to classify as an unlawful act, it is usually harmful to the site owner and possibly to the site users. Apart from using valuable resources, such an automated access may breach the site's usage license of public information and might also indicate unlawful activity such as using a botnet. Many times it is hard to know if such a blast of requests is a denial of service attack, brute force password cracking or just a search engine crawler.&lt;/p&gt;&#13;&lt;p&gt;Going forward we are going to add such incidents to WHID if there is a reason to believe that they are not friendly, even if the actual goal of the attack cannot be easily classified. The Facebook case at hand is a perfect example: while the details are not clear, the fact that Facebook filed a law suit implies that there is fire behind the smoke.&lt;/p&gt;&#13;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://docs.justia.com/cases/federal/district-courts/california/candce/5:2007cv03404/193531/17/0.pdf&quot;&gt;Facebook vs. John Doe&lt;/a&gt; [US District Court, San Jose, CA, Oct 23 2007]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.theregister.co.uk/2007/12/17/facebook_hack_attack_lawsuit/&quot;&gt;Facebook sues Canadian smut firm over hacking&lt;/a&gt; [The Register, Dec 17 2007]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.thestar.com/article/286091&quot;&gt;Facebook suing Ontario porn firm&lt;/a&gt; [The Star, Dec 16 2007]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2007-65</ddb:whidid>    </item>    <item>      <title>WHID 2006-27: SQL Injection in incredibleindia.org</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34165</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2006-27: SQL Injection in incredibleindia.org&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2006-27&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;April 20, 2006&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Disclosure Only&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;&lt;a href=&quot;http://www.incredibleindia.org&quot; title=&quot;www.incredibleindia.org&quot;&gt;www.incredibleindia.org&lt;/a&gt; is official Indian government tourism website.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;The researcher has found that the parameter PageID in the page ms_Page.asp is vulnerable to SQL injection.  He further tested that SQL error messages enable standard probing methods for finding out the number of columns and their type work.&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://seclists.org/lists/bugtraq/2006/Apr/0408.html&quot;&gt;SQL Injection in incredibleindia.org&lt;/a&gt; [Susam Pal, Apr 16 2006]&lt;/li&gt;&lt;br&gt;&lt;/ul></description>      <pubDate>Wed, 16 Jun 2010 18:28:32 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>April 20, 2006</ddb:dateoccured>      <ddb:entrytitle>WHID 2006-27: SQL Injection in incredibleindia.org</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;&lt;a href=&quot;http://www.incredibleindia.org&quot; title=&quot;www.incredibleindia.org&quot;&gt;www.incredibleindia.org&lt;/a&gt; is official Indian government tourism website.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;The researcher has found that the parameter PageID in the page ms_Page.asp is vulnerable to SQL injection.  He further tested that SQL error messages enable standard probing methods for finding out the number of columns and their type work.&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://seclists.org/lists/bugtraq/2006/Apr/0408.html&quot;&gt;SQL Injection in incredibleindia.org&lt;/a&gt; [Susam Pal, Apr 16 2006]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Disclosure Only</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2006-27</ddb:whidid>    </item>    <item>      <title>WHID 2009-45: Vaserv Hacked and Owner Commits Suicide Over Data Loss</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=35315</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2009-45: Vaserv Hacked and Owner Commits Suicide Over Data Loss&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2009-45&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;June 10, 2009&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Data Loss&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;This must be the worse incident reported by the Web Hacking Incident Database.&lt;/p&gt;&lt;br&gt;&lt;p&gt;We all know that web security is highly important but neglected. We tell frightening stories but listners think they are only &quot;FUD&quot;: fear, uncertainty and doubt, used to sell products and services. I hope that the VAServ incident will serve to warn that those are not fairytale stories. Even so, I wish this one would not have happened.&lt;/p&gt;&lt;br&gt;&lt;p&gt;In this story, like most calamities, it seems that the laymen suffer: small entrepreneurs &amp;amp; upstart companies who lost everything in a hacking incident. One of them even lost his life.&lt;/p&gt;&lt;br&gt;&lt;table style=&quot;height: 141px; width: 50%;&quot; border=&quot;1&quot; align=&quot;right&quot;&gt;&lt;br&gt;&lt;tbody&gt;&lt;br&gt;&lt;tr&gt;&lt;br&gt;&lt;td style=&quot;background-color: #faebd7;&quot;&gt;&lt;strong&gt;&lt;span style=&quot;font-size: small;&quot;&gt;Vaserv web site reporting recovery status, June 10&lt;sup&gt;th&lt;/sup&gt;:&lt;/span&gt;&lt;/strong&gt;&lt;br /&gt; &lt;span style=&quot;font-size: xx-small;&quot;&gt;22:19 vz47uk restored&lt;br /&gt; 22:21 vz46uk data loss&lt;br /&gt; 22:42 Please allow upto 2 hours for a ticket response as currently we have 200+ active tickets&lt;br /&gt; 23:02 vz67uk data loss&lt;br /&gt; 23:20 vz50uk data restored&lt;br /&gt; 23:23 vz51uk data loss&lt;br /&gt;00:03 FsckVPS server26 and server27 are still being worked on, but data *appears* to be intact&lt;/span&gt;&lt;/td&gt;&lt;br&gt;&lt;/tr&gt;&lt;br&gt;&lt;/tbody&gt;&lt;br&gt;&lt;/table&gt;&lt;br&gt;&lt;p&gt;It all started on Sunday, June 7&lt;sup&gt;th&lt;/sup&gt;: someone broke into the web servers of VAServ, a tiny UK based hosting company. The hackers ruined many of VAServ virtual servers. Some of them lost were for ever as the snippet from VAServ home page, serving as an emergency bulletin board, shows.&lt;/p&gt;&lt;br&gt;&lt;p&gt;As tiny as VAServ is, probably no more than 3 people, in today's virtual and flat world they could serve tens of thousands of low cost web sites, many of them now lost for ever. Behind each one of these web sites there is a story of someone who worked hard, whether on a hobby or a small business and is now left with nothing. A comment made on one of the blog entries about the incident reads:&lt;/p&gt;&lt;br&gt;&lt;p style=&quot;padding-left: 30px;&quot;&gt;&lt;em&gt;&quot;yeah thanks for ruining my life for the last 2 years i had built up my site spending alot of money and giving up my job for nothing.........what am i going to tell the wife?&quot;&lt;/em&gt;&lt;/p&gt;&lt;br&gt;&lt;p&gt;Just think about tens of thousand of such stories. Daniel Voyce, a web developer using VAServ for all of his clients, told the &lt;a href=&quot;http://www.theregister.co.uk/2009/06/08/webhost_attack/&quot;&gt;Register: &lt;/a&gt;&lt;/p&gt;&lt;br&gt;&lt;p style=&quot;padding-left: 30px;&quot;&gt;&lt;em&gt;&quot;Since last night, I've had probably 40 phone calls from clients saying 'Why is my website down, It's making me look bad.&quot;&lt;/em&gt;&lt;/p&gt;&lt;br&gt;&lt;p&gt;But this domino effect ruining so many small businesses had another even more devastating angle. Just days before the hack, someone &lt;a href=&quot;http://www.milw0rm.com/exploits/8880&quot;&gt;posted on milw0rm&lt;/a&gt; a long list of yet unpatched vulnerabilities in Kloxo, a virtual machine management software. The list certainly looks comprehensive enough to enable anyone to penetrate a site using Kloxo, which VAServ where, leading VAServ and others to believe that LxLabs, the Bangalorian software company behind Kloxo is the culprit. Somebody claiming to be the hacker &lt;a href=&quot;http://www.inquisitr.com/25617/update-new-information-on-the-vaserv-hack-that-wiped-100k-sites/&quot;&gt;commented to the inquistir blog&lt;/a&gt;, claiming that weak password at VAServ where to blame for the hack, which &lt;a href=&quot;http://www.theregister.co.uk/2009/06/10/vaserv_follow_up/&quot;&gt;Rus Foster from VAServ denied&lt;/a&gt;.&lt;/p&gt;&lt;br&gt;&lt;p&gt;We may never know who is right and who is wrong. LxLabs, just like Vaserv, is a tiny company using the Internet to look big. However one area that suffers a lot in small companies, is their security. It is never important enough to invest resource in security in such a lean and mean operations.&lt;/p&gt;&lt;br&gt;&lt;p&gt;&lt;img src=&quot;http://www.xiom.com/sites/default/files/ligesh.jpg&quot; width=&quot;179&quot; height=&quot;206&quot; style=&quot;float: right;&quot; /&gt;But tiny giants have another weakness: it all falls on the shoulders of too few people. In the case of LxLabs, on &lt;a href=&quot;http://timesofindia.indiatimes.com/Bangalore/Techie-hangs-himself-in-HSR-Layout-/articleshow/4633101.cms&quot;&gt;KT Ligesh the CEO&lt;/a&gt;. Ligesh&lt;a href=&quot;http://timesofindia.indiatimes.com/Bangalore/Techie-hangs-himself-in-HSR-Layout-/articleshow/4633101.cms&quot;&gt; committed suicide&lt;/a&gt; just a day after the hack for which his company was blamed. While already a troubled person, one cannot escape the thought that the hacking incident was the last straw.&lt;/p&gt;&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Service Providers&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://www.inquisitr.com/25617/update-new-information-on-the-vaserv-hack-that-wiped-100k-sites/&quot;&gt;http://www.inquisitr.com/25617/update-new-information-on-the-vaserv-hack-that-wiped-100k-sites/&lt;/a></description>      <pubDate>Wed, 16 Jun 2010 14:13:35 -0400</pubDate>      <ddb:attackedentityfield>Service Providers</ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>June 10, 2009</ddb:dateoccured>      <ddb:entrytitle>WHID 2009-45: Vaserv Hacked and Owner Commits Suicide Over Data Loss</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;This must be the worse incident reported by the Web Hacking Incident Database.&lt;/p&gt;&#13;&#10;&lt;p&gt;We all know that web security is highly important but neglected. We tell frightening stories but listners think they are only &quot;FUD&quot;: fear, uncertainty and doubt, used to sell products and services. I hope that the VAServ incident will serve to warn that those are not fairytale stories. Even so, I wish this one would not have happened.&lt;/p&gt;&#13;&#10;&lt;p&gt;In this story, like most calamities, it seems that the laymen suffer: small entrepreneurs &amp;amp; upstart companies who lost everything in a hacking incident. One of them even lost his life.&lt;/p&gt;&#13;&#10;&lt;table style=&quot;height: 141px; width: 50%;&quot; border=&quot;1&quot; align=&quot;right&quot;&gt;&#13;&#10;&lt;tbody&gt;&#13;&#10;&lt;tr&gt;&#13;&#10;&lt;td style=&quot;background-color: #faebd7;&quot;&gt;&lt;strong&gt;&lt;span style=&quot;font-size: small;&quot;&gt;Vaserv web site reporting recovery status, June 10&lt;sup&gt;th&lt;/sup&gt;:&lt;/span&gt;&lt;/strong&gt;&lt;br /&gt; &lt;span style=&quot;font-size: xx-small;&quot;&gt;22:19 vz47uk restored&lt;br /&gt; 22:21 vz46uk data loss&lt;br /&gt; 22:42 Please allow upto 2 hours for a ticket response as currently we have 200+ active tickets&lt;br /&gt; 23:02 vz67uk data loss&lt;br /&gt; 23:20 vz50uk data restored&lt;br /&gt; 23:23 vz51uk data loss&lt;br /&gt;00:03 FsckVPS server26 and server27 are still being worked on, but data *appears* to be intact&lt;/span&gt;&lt;/td&gt;&#13;&#10;&lt;/tr&gt;&#13;&#10;&lt;/tbody&gt;&#13;&#10;&lt;/table&gt;&#13;&#10;&lt;p&gt;It all started on Sunday, June 7&lt;sup&gt;th&lt;/sup&gt;: someone broke into the web servers of VAServ, a tiny UK based hosting company. The hackers ruined many of VAServ virtual servers. Some of them lost were for ever as the snippet from VAServ home page, serving as an emergency bulletin board, shows.&lt;/p&gt;&#13;&#10;&lt;p&gt;As tiny as VAServ is, probably no more than 3 people, in today's virtual and flat world they could serve tens of thousands of low cost web sites, many of them now lost for ever. Behind each one of these web sites there is a story of someone who worked hard, whether on a hobby or a small business and is now left with nothing. A comment made on one of the blog entries about the incident reads:&lt;/p&gt;&#13;&#10;&lt;p style=&quot;padding-left: 30px;&quot;&gt;&lt;em&gt;&quot;yeah thanks for ruining my life for the last 2 years i had built up my site spending alot of money and giving up my job for nothing.........what am i going to tell the wife?&quot;&lt;/em&gt;&lt;/p&gt;&#13;&#10;&lt;p&gt;Just think about tens of thousand of such stories. Daniel Voyce, a web developer using VAServ for all of his clients, told the &lt;a href=&quot;http://www.theregister.co.uk/2009/06/08/webhost_attack/&quot;&gt;Register: &lt;/a&gt;&lt;/p&gt;&#13;&#10;&lt;p style=&quot;padding-left: 30px;&quot;&gt;&lt;em&gt;&quot;Since last night, I've had probably 40 phone calls from clients saying 'Why is my website down, It's making me look bad.&quot;&lt;/em&gt;&lt;/p&gt;&#13;&#10;&lt;p&gt;But this domino effect ruining so many small businesses had another even more devastating angle. Just days before the hack, someone &lt;a href=&quot;http://www.milw0rm.com/exploits/8880&quot;&gt;posted on milw0rm&lt;/a&gt; a long list of yet unpatched vulnerabilities in Kloxo, a virtual machine management software. The list certainly looks comprehensive enough to enable anyone to penetrate a site using Kloxo, which VAServ where, leading VAServ and others to believe that LxLabs, the Bangalorian software company behind Kloxo is the culprit. Somebody claiming to be the hacker &lt;a href=&quot;http://www.inquisitr.com/25617/update-new-information-on-the-vaserv-hack-that-wiped-100k-sites/&quot;&gt;commented to the inquistir blog&lt;/a&gt;, claiming that weak password at VAServ where to blame for the hack, which &lt;a href=&quot;http://www.theregister.co.uk/2009/06/10/vaserv_follow_up/&quot;&gt;Rus Foster from VAServ denied&lt;/a&gt;.&lt;/p&gt;&#13;&#10;&lt;p&gt;We may never know who is right and who is wrong. LxLabs, just like Vaserv, is a tiny company using the Internet to look big. However one area that suffers a lot in small companies, is their security. It is never important enough to invest resource in security in such a lean and mean operations.&lt;/p&gt;&#13;&#10;&lt;p&gt;&lt;img src=&quot;http://www.xiom.com/sites/default/files/ligesh.jpg&quot; width=&quot;179&quot; height=&quot;206&quot; style=&quot;float: right;&quot; /&gt;But tiny giants have another weakness: it all falls on the shoulders of too few people. In the case of LxLabs, on &lt;a href=&quot;http://timesofindia.indiatimes.com/Bangalore/Techie-hangs-himself-in-HSR-Layout-/articleshow/4633101.cms&quot;&gt;KT Ligesh the CEO&lt;/a&gt;. Ligesh&lt;a href=&quot;http://timesofindia.indiatimes.com/Bangalore/Techie-hangs-himself-in-HSR-Layout-/articleshow/4633101.cms&quot;&gt; committed suicide&lt;/a&gt; just a day after the hack for which his company was blamed. While already a troubled person, one cannot escape the thought that the hacking incident was the last straw.&lt;/p></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Data Loss</ddb:outcome>      <ddb:reference>http://www.inquisitr.com/25617/update-new-information-on-the-vaserv-hack-that-wiped-100k-sites/</ddb:reference>      <ddb:whidid>2009-45</ddb:whidid>    </item>    <item>      <title>WHID 2006-26: Yahoo XSS used for phishing</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34160</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2006-26: Yahoo XSS used for phishing&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2006-26&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;April 18, 2006&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Phishing&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;An XSS vulnerability in Yahoo Mail is actively exploited for targeted phishing.&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.webappsec.org/lists/websecurity/archive/2006-04/msg00049.html&quot;&gt;Alert - Yahoo! Webmail XSS&lt;/a&gt; [Cesar Cerrudo, &lt;a href=&quot;http://www.argeniss.com&quot;&gt;Argeniss&lt;/a&gt;, Apr 17 2006]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://seclists.org/lists/fulldisclosure/2006/Apr/0823.html&quot;&gt;Alert - Yahoo! Mail XSS vulnerability&lt;/a&gt; [Cesar Cerrudo, &lt;a href=&quot;http://www.argeniss.com&quot;&gt;Argeniss&lt;/a&gt;, Apr 28 2006]&lt;/li&gt;&lt;br&gt;&lt;/ul></description>      <pubDate>Wed, 16 Jun 2010 18:28:56 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>April 18, 2006</ddb:dateoccured>      <ddb:entrytitle>WHID 2006-26: Yahoo XSS used for phishing</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;An XSS vulnerability in Yahoo Mail is actively exploited for targeted phishing.&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.webappsec.org/lists/websecurity/archive/2006-04/msg00049.html&quot;&gt;Alert - Yahoo! Webmail XSS&lt;/a&gt; [Cesar Cerrudo, &lt;a href=&quot;http://www.argeniss.com&quot;&gt;Argeniss&lt;/a&gt;, Apr 17 2006]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://seclists.org/lists/fulldisclosure/2006/Apr/0823.html&quot;&gt;Alert - Yahoo! Mail XSS vulnerability&lt;/a&gt; [Cesar Cerrudo, &lt;a href=&quot;http://www.argeniss.com&quot;&gt;Argeniss&lt;/a&gt;, Apr 28 2006]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Phishing</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2006-26</ddb:whidid>    </item>    <item>      <title>WHID 2007-66: Hacker Conquer French Embassy In Libya Web Site</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34617</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2007-66: Hacker Conquer French Embassy In Libya Web Site&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2007-66&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;December 19, 2007&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Planting of Malware&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;To iframe or not to iframe, this is the question. As malware becomes more popular, the number of incidents, mostly insignificant, in which malware was planted on a hacked site is rising and WHID is not the right place to list all of them. We currently report such incidents if the hacked site is of interest or if the Attack_Method is known.&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://news.portalit.net/fullnews_hacker-conquer-french-embassy-in-libya-webiste_712.html&quot;&gt;Hacker Conquer French Embassy In Libya Webiste&lt;/a&gt; [Portalit, Dec 14 2007]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Government</description>      <pubDate>Wed, 16 Jun 2010 15:32:45 -0400</pubDate>      <ddb:attackedentityfield>Government</ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>December 19, 2007</ddb:dateoccured>      <ddb:entrytitle>WHID 2007-66: Hacker Conquer French Embassy In Libya Web Site</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;To iframe or not to iframe, this is the question. As malware becomes more popular, the number of incidents, mostly insignificant, in which malware was planted on a hacked site is rising and WHID is not the right place to list all of them. We currently report such incidents if the hacked site is of interest or if the Attack_Method is known.&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://news.portalit.net/fullnews_hacker-conquer-french-embassy-in-libya-webiste_712.html&quot;&gt;Hacker Conquer French Embassy In Libya Webiste&lt;/a&gt; [Portalit, Dec 14 2007]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Planting of Malware</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2007-66</ddb:whidid>    </item>    <item>      <title>WHID 2007-67: The Day My Web Site Was Hacked</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34623</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2007-67: The Day My Web Site Was Hacked&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2007-67&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;December 19, 2007&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Link Spam&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;In an incident very similar to the &lt;a href=&quot;byid.php?id=2007-61&quot;&gt;Al Gore Hack&lt;/a&gt;, the personal blog of IT journalist Tim Anderson was also hacked. Unlike Mr. Gore, Tim discusses the breach and its origins.&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.itweek.co.uk/itweek/comment/2205891/day-web-site-hacked-3714596&quot;&gt;The day my web site was hacked&lt;/a&gt; [IT Week, Dec 17 2007]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Media&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;UK&lt;br&gt;&lt;b&gt;Attacked System Technology: &lt;/b&gt;WordPress</description>      <pubDate>Wed, 16 Jun 2010 15:31:00 -0400</pubDate>      <ddb:attackedentityfield>Media</ddb:attackedentityfield>      <ddb:attackedentitygeography>UK</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology>WordPress</ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>December 19, 2007</ddb:dateoccured>      <ddb:entrytitle>WHID 2007-67: The Day My Web Site Was Hacked</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;In an incident very similar to the &lt;a href=&quot;byid.php?id=2007-61&quot;&gt;Al Gore Hack&lt;/a&gt;, the personal blog of IT journalist Tim Anderson was also hacked. Unlike Mr. Gore, Tim discusses the breach and its origins.&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.itweek.co.uk/itweek/comment/2205891/day-web-site-hacked-3714596&quot;&gt;The day my web site was hacked&lt;/a&gt; [IT Week, Dec 17 2007]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Link Spam</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2007-67</ddb:whidid>    </item>    <item>      <title>WHID 2009-43: Web Mail Company to Pay Prize After CEO Hacked</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=35310</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2009-43: Web Mail Company to Pay Prize After CEO Hacked&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2009-43&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;June 10, 2009&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Monetary Loss&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;What does a challenge to break an web mail system and get $10,000, broken within minutes prove? Is it a lesson in vanity? Or about the state of web security? Or about security in general. Probably all.&lt;br&gt;The most obvious observatoins is that offering $10,000 for anyone who can break your site and being broken within an hour shows that you don't know what you taking about. Maybe it would be a lesson to all security vendors to not believe their own marketing verbiage. A quick browse of the bugtraq vulnerability archives will show how insecure and easy to evade security products can be.&lt;br&gt;However, judging from the number and seriousness of the incidents reported on the web hacking incidents database, StrongWebmail is not alone and far stronger companies suffers severe incidents, making web applications the weakest link in an organizations information security.&lt;br&gt;Lastly, we should always remember that there is never perfect security. By making systems more secure we are just raising the price required to attack them and lowering the damage of such an attack, but never. As the old joke goes: the only secure system is one without users.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Internet&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://www.strongwebmail.com/secure/email/contests/hack/tc&quot;&gt;http://www.strongwebmail.com/secure/email/contests/hack/tc&lt;/a></description>      <pubDate>Wed, 16 Jun 2010 14:13:43 -0400</pubDate>      <ddb:attackedentityfield>Internet</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>June 10, 2009</ddb:dateoccured>      <ddb:entrytitle>WHID 2009-43: Web Mail Company to Pay Prize After CEO Hacked</ddb:entrytitle>      <ddb:incidentdescription>What does a challenge to break an web mail system and get $10,000, broken within minutes prove? Is it a lesson in vanity? Or about the state of web security? Or about security in general. Probably all.&#13;&#10;&#13;&#10;The most obvious observatoins is that offering $10,000 for anyone who can break your site and being broken within an hour shows that you don't know what you taking about. Maybe it would be a lesson to all security vendors to not believe their own marketing verbiage. A quick browse of the bugtraq vulnerability archives will show how insecure and easy to evade security products can be.&#13;&#10;&#13;&#10;However, judging from the number and seriousness of the incidents reported on the web hacking incidents database, StrongWebmail is not alone and far stronger companies suffers severe incidents, making web applications the weakest link in an organizations information security.&#13;&#10;&#13;&#10;Lastly, we should always remember that there is never perfect security. By making systems more secure we are just raising the price required to attack them and lowering the damage of such an attack, but never. As the old joke goes: the only secure system is one without users.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Monetary Loss</ddb:outcome>      <ddb:reference>http://www.strongwebmail.com/secure/email/contests/hack/tc</ddb:reference>      <ddb:whidid>2009-43</ddb:whidid>    </item>    <item>      <title>WHID 2007-69: The Orkut XSS Worm</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34628</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2007-69: The Orkut XSS Worm&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2007-69&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;December 19, 2007&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Worm&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;A vulnerability in the social networking site Orkut that allowed users to inject HTML and JavaScript into their profiles set the stage for a persistent XSS worm that appears to have affected more than  650,000 Orkut users.&lt;/p&gt;&lt;br&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.gnucitizen.org/blog/the-orkut-xss-worm&quot;&gt;The Orkut XSS Worm&lt;/a&gt; [GNU Citizen, Dec 19 2007]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://antrix.net/journal/techtalk/orkut_xss.html&quot;&gt;Orkut XSS&lt;/a&gt; [Sounds From The Dungeon, Dec 19 2007]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.cgisecurity.com/2007/12/17&quot;&gt;Orkut XSS worm in the wild&lt;/a&gt; [CGI Security, Dec 19 2007]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.marrowbones.com/commons/technosocial/2007/12/orkut_worm_code_and_why_was_go.html#more&quot;&gt;Orkut Worm Code (and why was Google so slow to respond?)&lt;/a&gt; [TechnoSocial, Dec 19 2007]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Web 2.0&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA</description>      <pubDate>Wed, 16 Jun 2010 15:30:35 -0400</pubDate>      <ddb:attackedentityfield>Web 2.0</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>December 19, 2007</ddb:dateoccured>      <ddb:entrytitle>WHID 2007-69: The Orkut XSS Worm</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;A vulnerability in the social networking site Orkut that allowed users to inject HTML and JavaScript into their profiles set the stage for a persistent XSS worm that appears to have affected more than  650,000 Orkut users.&lt;/p&gt;&#13;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.gnucitizen.org/blog/the-orkut-xss-worm&quot;&gt;The Orkut XSS Worm&lt;/a&gt; [GNU Citizen, Dec 19 2007]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://antrix.net/journal/techtalk/orkut_xss.html&quot;&gt;Orkut XSS&lt;/a&gt; [Sounds From The Dungeon, Dec 19 2007]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.cgisecurity.com/2007/12/17&quot;&gt;Orkut XSS worm in the wild&lt;/a&gt; [CGI Security, Dec 19 2007]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.marrowbones.com/commons/technosocial/2007/12/orkut_worm_code_and_why_was_go.html#more&quot;&gt;Orkut Worm Code (and why was Google so slow to respond?)&lt;/a&gt; [TechnoSocial, Dec 19 2007]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Worm</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2007-69</ddb:whidid>    </item>    <item>      <title>WHID 2007-70: Tucson, Arizona police web site defaced using SQL injection</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34634</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2007-70: Tucson, Arizona police web site defaced using SQL injection&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2007-70&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;December 20, 2007&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Defacement&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Just like &lt;a href=&quot;byid.php?id=2007-60&quot;&gt;WHID 2007-60&lt;/a&gt;, this hack is probably a representative of many other incidents. The Indonesian hacker Hmei7 has left the message &quot;Hmei7 has touched your soul&quot; on the Web site of the police department in Tucson, Arizona. Only unlike regular defacement, this time it is not the front page but rather the news section that was modified.&lt;/p&gt;&lt;br&gt;&lt;p&gt;As many you know, the news section is one of the few database driven parts in many mostly static sites, as it allows the site owner to add news without requiring  a web designer. Therefore it came as no surprise that the attack was identified by a public source as an SQL injection attack.&lt;/p&gt;&lt;br&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.theregister.co.uk/2007/12/20/tuscon_police_website_defacement/&quot;&gt;Indonesian hacker touches souls by bringing down police web site&lt;/a&gt; [The Register, Dec 20 2007]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;Indonesia&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Security &amp;amp; Law Enforcement&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA</description>      <pubDate>Wed, 16 Jun 2010 15:30:25 -0400</pubDate>      <ddb:attackedentityfield>Security &amp;amp; Law Enforcement</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography>Indonesia</ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>December 20, 2007</ddb:dateoccured>      <ddb:entrytitle>WHID 2007-70: Tucson, Arizona police web site defaced using SQL injection</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Just like &lt;a href=&quot;byid.php?id=2007-60&quot;&gt;WHID 2007-60&lt;/a&gt;, this hack is probably a representative of many other incidents. The Indonesian hacker Hmei7 has left the message &quot;Hmei7 has touched your soul&quot; on the Web site of the police department in Tucson, Arizona. Only unlike regular defacement, this time it is not the front page but rather the news section that was modified.&lt;/p&gt;&#13;&lt;p&gt;As many you know, the news section is one of the few database driven parts in many mostly static sites, as it allows the site owner to add news without requiring  a web designer. Therefore it came as no surprise that the attack was identified by a public source as an SQL injection attack.&lt;/p&gt;&#13;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.theregister.co.uk/2007/12/20/tuscon_police_website_defacement/&quot;&gt;Indonesian hacker touches souls by bringing down police web site&lt;/a&gt; [The Register, Dec 20 2007]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Defacement</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2007-70</ddb:whidid>    </item>    <item>      <title>WHID 2007-71: Hacker uses Social Security numbers from Ohio court site</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34639</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2007-71: Hacker uses Social Security numbers from Ohio court site&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2007-71&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;December 22, 2007&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;The Secret Service has arrested at least 6 people in an investigation that involves information theft at an Ohio court web site, which is actively used for identity theft. At least one known identity theft case resulted in $40,000 loss to the victim.&lt;/p&gt;&lt;br&gt;&lt;p&gt;The sensitive information was stolen by manipulating predictable identifier parameters. The stolen information belong to at least 270 people and includes the name, address, age and other information could be used to obtain credit cards and open bank accounts. &lt;/p&gt;&lt;br&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.ohio.com/news/12763097.html&quot;&gt;Hacker uses Social Security numbers from Ohio court site&lt;/a&gt; [Ohio.com/AP, Dec 22 2007]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.dispatch.com/live/content/local_news/stories/2007/12/20/clerkh.html&quot;&gt;Feds take over municipal court Web hacking probe&lt;/a&gt; [Columbus Dispatch, Dec 20 2007]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Security &amp;amp; Law Enforcement&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA</description>      <pubDate>Thu, 17 Jun 2010 18:25:45 -0400</pubDate>      <ddb:attackedentityfield>Security &amp;amp; Law Enforcement</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>December 22, 2007</ddb:dateoccured>      <ddb:entrytitle>WHID 2007-71: Hacker uses Social Security numbers from Ohio court site</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;The Secret Service has arrested at least 6 people in an investigation that involves information theft at an Ohio court web site, which is actively used for identity theft. At least one known identity theft case resulted in $40,000 loss to the victim.&lt;/p&gt;&#13;&lt;p&gt;The sensitive information was stolen by manipulating predictable identifier parameters. The stolen information belong to at least 270 people and includes the name, address, age and other information could be used to obtain credit cards and open bank accounts. &lt;/p&gt;&#13;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.ohio.com/news/12763097.html&quot;&gt;Hacker uses Social Security numbers from Ohio court site&lt;/a&gt; [Ohio.com/AP, Dec 22 2007]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.dispatch.com/live/content/local_news/stories/2007/12/20/clerkh.html&quot;&gt;Feds take over municipal court Web hacking probe&lt;/a&gt; [Columbus Dispatch, Dec 20 2007]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2007-71</ddb:whidid>    </item>    <item>      <title>WHID 2008-53: 'SQL by Design' leaks Thousands of SSNs at an Oklahoma Gov site</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=35056</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2008-53: 'SQL by Design' leaks Thousands of SSNs at an Oklahoma Gov site&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2008-53&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;April 14, 2008&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Alex Papadimoulis hits &lt;a href=&quot;http://thedailywtf.com/Articles/Oklahoma-Leaks-Tens-of-Thousands-of-Social-Security-Numbers,-Other-Sensitive-Data.aspx&quot;&gt;again &lt;/a&gt;with a report on leakage of information on Oklahoma's Department of Corrections web site. The detailed report is very interesting and highlights one of the worse types of SQL injection out there: remote SQL by design.&lt;/p&gt;&lt;br&gt;&lt;p&gt;A unique form of SQL injection, or even just a close sibling, remote SQL by design is a vulnerability in which the web application accepts SQL statements from the client in the normal course of operation. The SQL statement might be used in a hidden field, or generated on the fly by a client side script. In any case, it is extremely difficult to prevent alteration of the SQL statement by a user in such applications, making the applications highly vulnerable.&lt;/p&gt;&lt;br&gt;&lt;p&gt;To find for yourself how common is this vulnerability, just Google for SELECT, FROM and WHERE in the URL. Amazing.&lt;/p&gt;&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Government&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA</description>      <pubDate>Wed, 16 Jun 2010 14:37:07 -0400</pubDate>      <ddb:attackedentityfield>Government</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>April 14, 2008</ddb:dateoccured>      <ddb:entrytitle>WHID 2008-53: 'SQL by Design' leaks Thousands of SSNs at an Oklahoma Gov site</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Alex Papadimoulis hits &lt;a href=&quot;http://thedailywtf.com/Articles/Oklahoma-Leaks-Tens-of-Thousands-of-Social-Security-Numbers,-Other-Sensitive-Data.aspx&quot;&gt;again &lt;/a&gt;with a report on leakage of information on Oklahoma's Department of Corrections web site. The detailed report is very interesting and highlights one of the worse types of SQL injection out there: remote SQL by design.&lt;/p&gt;&#13;&#10;&lt;p&gt;A unique form of SQL injection, or even just a close sibling, remote SQL by design is a vulnerability in which the web application accepts SQL statements from the client in the normal course of operation. The SQL statement might be used in a hidden field, or generated on the fly by a client side script. In any case, it is extremely difficult to prevent alteration of the SQL statement by a user in such applications, making the applications highly vulnerable.&lt;/p&gt;&#13;&#10;&lt;p&gt;To find for yourself how common is this vulnerability, just Google for SELECT, FROM and WHERE in the URL. Amazing.&lt;/p></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2008-53</ddb:whidid>    </item>    <item>      <title>WHID 2008-32: Yahoo HotJobs XSS</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=33492</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2008-32: Yahoo HotJobs XSS&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2008-32&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;October 26, 2008&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Session Hijacking&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;&lt;a href=&quot;http://news.netcraft.com/archives/2008/10/26/ongoing_phishing_attack_exposes_yahoo_accounts.html&quot;&gt;Netcraft&lt;/a&gt; reported an ongoing exploit of XSS vulnerability in Yahoo HotJobs site. The attackers have been using an obfuscated JavaScript to steal session cookies of victims, which were in turn sent to a server in the US.&lt;br /&gt;&lt;br&gt;The stolen cookie was a yahoo-wide cookie and therefore by stealing it the hackers could gain control of every service accessible to the victim within Yahoo, including Yahoo! Mail.&lt;br /&gt;&lt;br&gt;Netcraft identified the issue by observing irregular activity by its toolbar users and Yahoo! fixed the vulnerability short after, on Oct 28th.&lt;/p&gt;&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;USA&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Internet&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://news.netcraft.com/archives/2008/10/26/ongoing_phishing_attack_exposes_yahoo_accounts.html&quot;&gt;http://news.netcraft.com/archives/2008/10/26/ongoing_phishing_attack_exposes_yahoo_accounts.html&lt;/a></description>      <pubDate>Wed, 16 Jun 2010 15:02:19 -0400</pubDate>      <ddb:attackedentityfield>Internet</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography>USA</ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>October 26, 2008</ddb:dateoccured>      <ddb:entrytitle>WHID 2008-32: Yahoo HotJobs XSS</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;&lt;a href=&quot;http://news.netcraft.com/archives/2008/10/26/ongoing_phishing_attack_exposes_yahoo_accounts.html&quot;&gt;Netcraft&lt;/a&gt; reported an ongoing exploit of XSS vulnerability in Yahoo HotJobs site. The attackers have been using an obfuscated JavaScript to steal session cookies of victims, which were in turn sent to a server in the US.&lt;br /&gt;&#13;The stolen cookie was a yahoo-wide cookie and therefore by stealing it the hackers could gain control of every service accessible to the victim within Yahoo, including Yahoo! Mail.&lt;br /&gt;&#13;Netcraft identified the issue by observing irregular activity by its toolbar users and Yahoo! fixed the vulnerability short after, on Oct 28th.&lt;/p></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Session Hijacking</ddb:outcome>      <ddb:reference>http://news.netcraft.com/archives/2008/10/26/ongoing_phishing_attack_exposes_yahoo_accounts.html</ddb:reference>      <ddb:whidid>2008-32</ddb:whidid>    </item>    <item>      <title>WHID 2007-72: David Airey domains hijacked</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34646</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2007-72: David Airey domains hijacked&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2007-72&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;December 30, 2007&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Fraud&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;&lt;em&gt;&lt;span style=&quot;text-decoration: underline;&quot;&gt;Update (Dec 30th 2008)&lt;/span&gt;&lt;/em&gt;&lt;/p&gt;&lt;br&gt;&lt;p&gt;It seems that the original report was not accurate and it was not a CSRF vulnerablity that was exploited. The mistake is reported by the victim in an imaginary &lt;a href=&quot;http://www.davidairey.com/google-site-links-gmail-hack-search-penalty/&quot;&gt;discussion with Google&lt;/a&gt; blog post (Search the page for XSRF) and by &lt;a href=&quot;http://googleonlinesecurity.blogspot.com/2008/11/gmail-security-and-recent-phishing.html&quot;&gt;Google&lt;/a&gt;. Google hints that it was a phishing attack, but David Airey is &lt;a href=&quot;http://www.davidairey.com/google-gmail-phishing-scam/&quot;&gt;not convinced&lt;/a&gt;.&lt;/p&gt;&lt;br&gt;&lt;hr /&gt;&lt;br&gt;&lt;p&gt;Many times we dismiss seemingly minor vulnerabilities in major web sites. Most notably, &quot;yet another&quot; XSS or CSRF vulnerability in a well known service is not considered news anymore. However the following story proves that no matter what, such vulnerabilities cannot be ignored.&lt;/p&gt;&lt;br&gt;&lt;p&gt;The attack is simple, the result pretty frightening. An attacker, presumably Iranian, stole the domain name of David Airey, a graphic artist and a known blogger. The attack was very well timed with David's leaving to a long vacation. The goal was to extort money in order to return the domain. In David's case there is a happy end, as the attention he got helped him receive his blog back, with some loss in traffic, search engine ranking and time. But other victims of the attacker who steal domains for living may not be as fortunate.&lt;/p&gt;&lt;br&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://blogs.securiteam.com/index.php/archives/1054&quot;&gt;When fixing is not enough&lt;/a&gt; [Securiteam, Dec 28 2007]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.davidairey.co.uk/google-gmail-security-hijack/&quot;&gt;WARNING: Google's Gmail security failure leaves my business sabotaged&lt;/a&gt; [David Airey, Dec 24 2007]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.gnucitizen.org/blog/google-gmail-e-mail-hijack-technique/&quot;&gt;Google GMail E-mail Hijack Technique&lt;/a&gt; [GNUcitizen, Sep 25 2007]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.davidairey.com/david-airey-dot-com-restored/&quot;&gt;Collective effort restores David Airey.com&lt;/a&gt; [David Airey, Dec 27 2007]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;Iran&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Media&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;UK</description>      <pubDate>Wed, 16 Jun 2010 15:29:02 -0400</pubDate>      <ddb:attackedentityfield>Media</ddb:attackedentityfield>      <ddb:attackedentitygeography>UK</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography>Iran</ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>December 30, 2007</ddb:dateoccured>      <ddb:entrytitle>WHID 2007-72: David Airey domains hijacked</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;&lt;em&gt;&lt;span style=&quot;text-decoration: underline;&quot;&gt;Update (Dec 30th 2008)&lt;/span&gt;&lt;/em&gt;&lt;/p&gt;&#13;&lt;p&gt;It seems that the original report was not accurate and it was not a CSRF vulnerablity that was exploited. The mistake is reported by the victim in an imaginary &lt;a href=&quot;http://www.davidairey.com/google-site-links-gmail-hack-search-penalty/&quot;&gt;discussion with Google&lt;/a&gt; blog post (Search the page for XSRF) and by &lt;a href=&quot;http://googleonlinesecurity.blogspot.com/2008/11/gmail-security-and-recent-phishing.html&quot;&gt;Google&lt;/a&gt;. Google hints that it was a phishing attack, but David Airey is &lt;a href=&quot;http://www.davidairey.com/google-gmail-phishing-scam/&quot;&gt;not convinced&lt;/a&gt;.&lt;/p&gt;&#13;&lt;hr /&gt;&#13;&lt;p&gt;Many times we dismiss seemingly minor vulnerabilities in major web sites. Most notably, &quot;yet another&quot; XSS or CSRF vulnerability in a well known service is not considered news anymore. However the following story proves that no matter what, such vulnerabilities cannot be ignored.&lt;/p&gt;&#13;&lt;p&gt;The attack is simple, the result pretty frightening. An attacker, presumably Iranian, stole the domain name of David Airey, a graphic artist and a known blogger. The attack was very well timed with David's leaving to a long vacation. The goal was to extort money in order to return the domain. In David's case there is a happy end, as the attention he got helped him receive his blog back, with some loss in traffic, search engine ranking and time. But other victims of the attacker who steal domains for living may not be as fortunate.&lt;/p&gt;&#13;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://blogs.securiteam.com/index.php/archives/1054&quot;&gt;When fixing is not enough&lt;/a&gt; [Securiteam, Dec 28 2007]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.davidairey.co.uk/google-gmail-security-hijack/&quot;&gt;WARNING: Google's Gmail security failure leaves my business sabotaged&lt;/a&gt; [David Airey, Dec 24 2007]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.gnucitizen.org/blog/google-gmail-e-mail-hijack-technique/&quot;&gt;Google GMail E-mail Hijack Technique&lt;/a&gt; [GNUcitizen, Sep 25 2007]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.davidairey.com/david-airey-dot-com-restored/&quot;&gt;Collective effort restores David Airey.com&lt;/a&gt; [David Airey, Dec 27 2007]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Fraud</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2007-72</ddb:whidid>    </item>    <item>      <title>WHID 2008-33: Chinese hacker jailed for false quake alarm</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=33497</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2008-33: Chinese hacker jailed for false quake alarm&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2008-33&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;May 29, 2008&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Disinformation&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;A Chinese student penetrated the Shaanxi Provincial Seismic Bureau's web site and planted a false warning on an earth quake expected the following night reports &lt;a href=&quot;http://www.theaustralian.news.com.au/story/0,25197,24275633-12377,00.html&quot;&gt;The Australian&lt;/a&gt;.&lt;br /&gt;&lt;br&gt;The false warning created panic, especially since it was made shortly after the devastating earth quake hitting China just a few weeks earlier. The faked warning drew 767 page views within 10 minutes, the bureaus phones became immediately very busy.&lt;br /&gt;&lt;br&gt;As expected in China, authorities were far from forgiving, and the student was jailed for 18 months.&lt;/p&gt;&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;China&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Government&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;China</description>      <pubDate>Wed, 16 Jun 2010 15:02:19 -0400</pubDate>      <ddb:attackedentityfield>Government</ddb:attackedentityfield>      <ddb:attackedentitygeography>China</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography>China</ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>May 29, 2008</ddb:dateoccured>      <ddb:entrytitle>WHID 2008-33: Chinese hacker jailed for false quake alarm</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;A Chinese student penetrated the Shaanxi Provincial Seismic Bureau's web site and planted a false warning on an earth quake expected the following night reports &lt;a href=&quot;http://www.theaustralian.news.com.au/story/0,25197,24275633-12377,00.html&quot;&gt;The Australian&lt;/a&gt;.&lt;br /&gt;&#13;The false warning created panic, especially since it was made shortly after the devastating earth quake hitting China just a few weeks earlier. The faked warning drew 767 page views within 10 minutes, the bureaus phones became immediately very busy.&lt;br /&gt;&#13;As expected in China, authorities were far from forgiving, and the student was jailed for 18 months.&lt;/p></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Disinformation</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2008-33</ddb:whidid>    </item>    <item>      <title>WHID 2009-42: Puerto Rico sites redirected in a DNS attack</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=35303</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2009-42: Puerto Rico sites redirected in a DNS attack&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2009-42&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;April 27, 2009&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Defacement&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;Attacking web sites by going to the source, targeting DNS servers rather than the web sites themselves shows both the boldness of hackers as well as the fragility of the Internet.&lt;br&gt;While not new, DNS hijacking attacks took an important turn this year showing how much we rely on the web and now little we care for its protection. In the past DNS hijacking required complete control over the DNS server. In recent years most applications are controlled through a web interface, including DNS servers. Earlier this year attackers found an XSS vulnerability in a common DNS platform to hijack unused DNS entries for phishing&lt;br&gt;But this was only a small prelude to the real thing. CNet reports that this time hackers took over an entire TLD (Top Level Domain, or country) DNS server using SQL injection, virtually defacing the Puerto Rican site of companies such as Google and Microsoft.&lt;br&gt;The amazing story unfolds in the comments to CNet story, which outlines a mischievous professor and slow authorities who let him privatize and monetize on domain registration in Puerto Rico without any control.&lt;br&gt;The question we are left with is whether other countries and geographies different? Or even other industries for that matter?&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Internet&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;US&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://news.cnet.com/8301-1009_3-10228436-83.html&quot;&gt;http://news.cnet.com/8301-1009_3-10228436-83.html&lt;/a></description>      <pubDate>Wed, 16 Jun 2010 14:13:43 -0400</pubDate>      <ddb:attackedentityfield>Internet</ddb:attackedentityfield>      <ddb:attackedentitygeography>US</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>April 27, 2009</ddb:dateoccured>      <ddb:entrytitle>WHID 2009-42: Puerto Rico sites redirected in a DNS attack</ddb:entrytitle>      <ddb:incidentdescription>Attacking web sites by going to the source, targeting DNS servers rather than the web sites themselves shows both the boldness of hackers as well as the fragility of the Internet.&#13;&#10;&#13;&#10;While not new, DNS hijacking attacks took an important turn this year showing how much we rely on the web and now little we care for its protection. In the past DNS hijacking required complete control over the DNS server. In recent years most applications are controlled through a web interface, including DNS servers. Earlier this year attackers found an XSS vulnerability in a common DNS platform to hijack unused DNS entries for phishing&#13;&#10;&#13;&#10;But this was only a small prelude to the real thing. CNet reports that this time hackers took over an entire TLD (Top Level Domain, or country) DNS server using SQL injection, virtually defacing the Puerto Rican site of companies such as Google and Microsoft.&#13;&#10;&#13;&#10;The amazing story unfolds in the comments to CNet story, which outlines a mischievous professor and slow authorities who let him privatize and monetize on domain registration in Puerto Rico without any control.&#13;&#10;&#13;&#10;The question we are left with is whether other countries and geographies different? Or even other industries for that matter?</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Defacement</ddb:outcome>      <ddb:reference>http://news.cnet.com/8301-1009_3-10228436-83.html</ddb:reference>      <ddb:whidid>2009-42</ddb:whidid>    </item>    <item>      <title>WHID 2008-34: Adobe hit by malware</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=33502</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2008-34: Adobe hit by malware&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2008-34&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;October 17, 2008&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Planting of Malware&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Adobe joins the long list of sites hit by Asprox, a botnet using SQL injection attacks to plant malware. &lt;a href=&quot;http://www.internetnews.com/security/article.php/3779021/Adobe+Sites+Hit+by+Malware.htm&quot;&gt;Internet News&lt;/a&gt; reports that Sophos has discovered malwares on Adobe &lt;a href=&quot;http://www.sophos.com/pressoffice/news/articles/2008/10/adobe-infection.html&quot;&gt;Vlog it&lt;/a&gt; and &lt;a href=&quot;http://www.sophos.com/security/blog/2008/10/1863.html&quot;&gt;Serious Magic&lt;/a&gt; sites.&lt;/p&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Technology&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA</description>      <pubDate>Wed, 16 Jun 2010 15:02:19 -0400</pubDate>      <ddb:attackedentityfield>Technology</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>October 17, 2008</ddb:dateoccured>      <ddb:entrytitle>WHID 2008-34: Adobe hit by malware</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Adobe joins the long list of sites hit by Asprox, a botnet using SQL injection attacks to plant malware. &lt;a href=&quot;http://www.internetnews.com/security/article.php/3779021/Adobe+Sites+Hit+by+Malware.htm&quot;&gt;Internet News&lt;/a&gt; reports that Sophos has discovered malwares on Adobe &lt;a href=&quot;http://www.sophos.com/pressoffice/news/articles/2008/10/adobe-infection.html&quot;&gt;Vlog it&lt;/a&gt; and &lt;a href=&quot;http://www.sophos.com/security/blog/2008/10/1863.html&quot;&gt;Serious Magic&lt;/a&gt; sites.&lt;/p></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Planting of Malware</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2008-34</ddb:whidid>    </item>    <item>      <title>WHID 2007-74: Web host breach may have exposed passwords for 6,000 clients</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34652</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2007-74: Web host breach may have exposed passwords for 6,000 clients&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2007-74&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;January 1, 2008&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;A known vulnerability in the helpdesk software used by hosting provider Layered Technologies resulted in leakage of information, including names, addresses, phone numbers and email addresses of up to 6,000 of the company's clients.&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.theregister.co.uk/2007/09/19/layered_technologies_breach_disclosure/&quot;&gt;Web host breach may have exposed passwords for 6,000 clients&lt;/a&gt; [The Register, Sep 19 2007]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Service Providers&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA&lt;br&gt;&lt;b&gt;Attacked System Technology: &lt;/b&gt;Cerberus Helpdesk</description>      <pubDate>Wed, 16 Jun 2010 15:28:05 -0400</pubDate>      <ddb:attackedentityfield>Service Providers</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology>Cerberus Helpdesk</ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>January 1, 2008</ddb:dateoccured>      <ddb:entrytitle>WHID 2007-74: Web host breach may have exposed passwords for 6,000 clients</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;A known vulnerability in the helpdesk software used by hosting provider Layered Technologies resulted in leakage of information, including names, addresses, phone numbers and email addresses of up to 6,000 of the company's clients.&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.theregister.co.uk/2007/09/19/layered_technologies_breach_disclosure/&quot;&gt;Web host breach may have exposed passwords for 6,000 clients&lt;/a&gt; [The Register, Sep 19 2007]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2007-74</ddb:whidid>    </item>    <item>      <title>WHID 2006-25: Everyone.net XSS</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34150</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2006-25: Everyone.net XSS&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2006-25&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;April 12, 2006&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Disclosure Only&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Everyone.net login script (loginuser.pl) is prone to a cross site scripting attack in the variable loginName.&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.morx.org/everyoneXSS.txt&quot;&gt;Everyone.net XSS&lt;/a&gt; [Simo Ben Youssef, Feb 12 2006]&lt;/li&gt;&lt;br&gt;&lt;/ul></description>      <pubDate>Wed, 16 Jun 2010 18:29:25 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>April 12, 2006</ddb:dateoccured>      <ddb:entrytitle>WHID 2006-25: Everyone.net XSS</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Everyone.net login script (loginuser.pl) is prone to a cross site scripting attack in the variable loginName.&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.morx.org/everyoneXSS.txt&quot;&gt;Everyone.net XSS&lt;/a&gt; [Simo Ben Youssef, Feb 12 2006]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Disclosure Only</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2006-25</ddb:whidid>    </item>    <item>      <title>WHID 2008-35: Business Week site hit by malware</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=33507</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2008-35: Business Week site hit by malware&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2008-35&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;September 15, 2008&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Planting of Malware&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Business Week is the latest victim of Asprox, a botnet using SQL injection attacks to plant malware. &lt;a href=&quot;http://www.internetnews.com/security/article.php/3779021/Adobe+Sites+Hit+by+Malware.htm&quot;&gt;Internet News&lt;/a&gt; reports that Sophos has &lt;a href=&quot;http://www.sophos.com/blogs/gc/g/2008/09/15/hackers-infect-businessweek-website-via-sql-injection-attack/&quot;&gt;discovered&lt;/a&gt; malwares on a large number of pages on the magazines web site. A Google safe browsing report, which checks how many pages on a web site, if any, are infected with malware picked at 214 out of 2,157 pages on the site, just shy of 10%.&lt;/p&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Information Services&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA</description>      <pubDate>Wed, 16 Jun 2010 15:02:19 -0400</pubDate>      <ddb:attackedentityfield>Information Services</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>September 15, 2008</ddb:dateoccured>      <ddb:entrytitle>WHID 2008-35: Business Week site hit by malware</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Business Week is the latest victim of Asprox, a botnet using SQL injection attacks to plant malware. &lt;a href=&quot;http://www.internetnews.com/security/article.php/3779021/Adobe+Sites+Hit+by+Malware.htm&quot;&gt;Internet News&lt;/a&gt; reports that Sophos has &lt;a href=&quot;http://www.sophos.com/blogs/gc/g/2008/09/15/hackers-infect-businessweek-website-via-sql-injection-attack/&quot;&gt;discovered&lt;/a&gt; malwares on a large number of pages on the magazines web site. A Google safe browsing report, which checks how many pages on a web site, if any, are infected with malware picked at 214 out of 2,157 pages on the site, just shy of 10%.&lt;/p></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Planting of Malware</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2008-35</ddb:whidid>    </item>    <item>      <title>WHID 2009-41: Malware in Advertizing at Digital Spy</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=35298</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2009-41: Malware in Advertizing at Digital Spy&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2009-41&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;June 2, 2009&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Planting of Malware&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;The register reports that Digital Spy, a high profile UK gossip site carried banner inflicting ads. Digital Spy has acknowledged the issue and said it promptly addressed it, however details on the source of the malicious banners is still not availalbe.&lt;br&gt;Malware distribution through ad programs is a borderline phenomenon. While there is no question that malware distribucion is malicious, and in most geographies illegal, in many cases the site owners are not technically responsible for the content of the ads they serve  as the ad content comes directly from a 3rd party. The question whether they are legally responsible is open.&lt;br&gt;Another issue is defining a malware. Many times ads are used to entice users to download and install programs that are questionable. a rootkit installed through a known browser vulnerability is a malware, however the distinction between adware and malware is many time blurred and depends on:&lt;br&gt;The ratio between benefit to the user and benefit to the software distributor, &lt;br&gt;The clarity in which the benefit to the software distributor is explained to the user, and lastly: &lt;br&gt;The legality of this benefit &lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Media&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;UK&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://www.theregister.co.uk/2009/06/02/digital_spy_malware/&quot;&gt;http://www.theregister.co.uk/2009/06/02/digital_spy_malware/&lt;/a></description>      <pubDate>Wed, 16 Jun 2010 14:13:59 -0400</pubDate>      <ddb:attackedentityfield>Media</ddb:attackedentityfield>      <ddb:attackedentitygeography>UK</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>June 2, 2009</ddb:dateoccured>      <ddb:entrytitle>WHID 2009-41: Malware in Advertizing at Digital Spy</ddb:entrytitle>      <ddb:incidentdescription>The register reports that Digital Spy, a high profile UK gossip site carried banner inflicting ads. Digital Spy has acknowledged the issue and said it promptly addressed it, however details on the source of the malicious banners is still not availalbe.&#13;&#10;&#13;&#10;Malware distribution through ad programs is a borderline phenomenon. While there is no question that malware distribucion is malicious, and in most geographies illegal, in many cases the site owners are not technically responsible for the content of the ads they serve  as the ad content comes directly from a 3rd party. The question whether they are legally responsible is open.&#13;&#10;&#13;&#10;Another issue is defining a malware. Many times ads are used to entice users to download and install programs that are questionable. a rootkit installed through a known browser vulnerability is a malware, however the distinction between adware and malware is many time blurred and depends on:&#13;&#10;&#13;&#10;The ratio between benefit to the user and benefit to the software distributor, &#13;&#10;The clarity in which the benefit to the software distributor is explained to the user, and lastly: &#13;&#10;The legality of this benefit </ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Planting of Malware</ddb:outcome>      <ddb:reference>http://www.theregister.co.uk/2009/06/02/digital_spy_malware/</ddb:reference>      <ddb:whidid>2009-41</ddb:whidid>    </item>    <item>      <title>WHID 2007-75: PlusNet blames itself for webmail spamfest</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34657</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2007-75: PlusNet blames itself for webmail spamfest&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2007-75&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;January 1, 2008&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Misconfiguration of a webmail system at a British hosting provider led to leakage of the entire user's database including all e-mails. The e-mail addresses where actively used for sending spam. Additionally the exploit was used to plant malware on some of the customers' web sites.&lt;/p&gt;&lt;br&gt;&lt;p&gt;This incident is unique since PlusNet has published a very interesting and revealing report about the incident that shed a lot of light on real world state of life application security. A must read.&lt;/p&gt;&lt;br&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.theregister.co.uk/2007/05/24/plusnet_takes_blame/&quot;&gt;PlusNet blames itself for webmail spamfest&lt;/a&gt; [News Story, May 24 2007]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://community.plus.net/comms/2007/05/23/webmail-incident-report/&quot;&gt;Web mail Incident Report&lt;/a&gt; [PlusNet, May 23 2008]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Service Providers&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;UK</description>      <pubDate>Wed, 16 Jun 2010 15:27:43 -0400</pubDate>      <ddb:attackedentityfield>Service Providers</ddb:attackedentityfield>      <ddb:attackedentitygeography>UK</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>January 1, 2008</ddb:dateoccured>      <ddb:entrytitle>WHID 2007-75: PlusNet blames itself for webmail spamfest</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Misconfiguration of a webmail system at a British hosting provider led to leakage of the entire user's database including all e-mails. The e-mail addresses where actively used for sending spam. Additionally the exploit was used to plant malware on some of the customers' web sites.&lt;/p&gt;&#13;&lt;p&gt;This incident is unique since PlusNet has published a very interesting and revealing report about the incident that shed a lot of light on real world state of life application security. A must read.&lt;/p&gt;&#13;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.theregister.co.uk/2007/05/24/plusnet_takes_blame/&quot;&gt;PlusNet blames itself for webmail spamfest&lt;/a&gt; [News Story, May 24 2007]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://community.plus.net/comms/2007/05/23/webmail-incident-report/&quot;&gt;Web mail Incident Report&lt;/a&gt; [PlusNet, May 23 2008]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2007-75</ddb:whidid>    </item>    <item>      <title>WHID 2009-6: InfoGov switch hosting due to lack of security</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=35029</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2009-6: InfoGov switch hosting due to lack of security&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2009-6&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;January 16, 2009&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Planting of Malware&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;This gem is taken out of a &lt;a href=&quot;http://www.hostsearch.com/news/supported247_news_8191.asp&quot;&gt;press release&lt;/a&gt; issued by a hosting provider. According to the press release, InfoGov, a UK provider of risk management solutions, switched hosting its sites to a new provider because the previous one did not provide adequate solution to an SQL injection attack that penetrated the site and inflicted Malware on InfoGov customers.&lt;/p&gt;&lt;br&gt;&lt;p&gt;Probably yet another fallout from the on going Asprox attack, this incident is interesting as it emphasises the responsibility that customers expect service providers to take in protecting from web based attacks.&lt;/p&gt;&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Government&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;UK</description>      <pubDate>Wed, 16 Jun 2010 14:23:05 -0400</pubDate>      <ddb:attackedentityfield>Government</ddb:attackedentityfield>      <ddb:attackedentitygeography>UK</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>January 16, 2009</ddb:dateoccured>      <ddb:entrytitle>WHID 2009-6: InfoGov switch hosting due to lack of security</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;This gem is taken out of a &lt;a href=&quot;http://www.hostsearch.com/news/supported247_news_8191.asp&quot;&gt;press release&lt;/a&gt; issued by a hosting provider. According to the press release, InfoGov, a UK provider of risk management solutions, switched hosting its sites to a new provider because the previous one did not provide adequate solution to an SQL injection attack that penetrated the site and inflicted Malware on InfoGov customers.&lt;/p&gt;&#13;&#10;&lt;p&gt;Probably yet another fallout from the on going Asprox attack, this incident is interesting as it emphasises the responsibility that customers expect service providers to take in protecting from web based attacks.&lt;/p></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Planting of Malware</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2009-6</ddb:whidid>    </item>    <item>      <title>WHID 2007-76: A large web hosting firm inflicted by mass malware installation</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34663</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2007-76: A large web hosting firm inflicted by mass malware installation&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2007-76&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;January 1, 2008&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Planting of Malware&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;The Washington Post ran a story about a large scale infiltration to IPower, a major hosting provider. According to the story and the following comments, it seems that the problem is plunging IPower for a long time without being resolved. Put in perspective the &lt;a href=&quot;byid_id_2007-75.shtml&quot;&gt;PlusNet incident&lt;/a&gt; which was serious but swiftly handled and publicly acknowledged by the company.&lt;/p&gt;&lt;br&gt;&lt;p&gt;Actually the problem is so dominant that a recent &lt;a href=&quot;http://stopbadware.org&quot;&gt;StopBadware&lt;/a&gt; report lists Ipower as by far the most Malware infected hosting company. Reports mention that the problem started as early as mid 2006.&lt;br&gt;&lt;/p&gt;&lt;p&gt;The root cause of the breach here is mentioned as being a vulnerability in either Apache, PHP or cPanel. I have selected the third as being more probably until further evidence materialize.&lt;/p&gt;&lt;br&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://blog.washingtonpost.com/securityfix/2007/05/cyber_crooks_hijack_activities_1.html&quot;&gt;Cyber Crooks Hijack Activities of Large Web-Hosting Firm&lt;/a&gt; [Washington Post, May 23 2007]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://stopbadware.org/home/pr_050307&quot;&gt;StopBadware.org Identifies Companies Hosting Large Numbers of Websites That Can Infect Internet Users With Badware&lt;/a&gt; [StopBadware, May 4 2007]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Service Providers&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA&lt;br&gt;&lt;b&gt;Attacked System Technology: &lt;/b&gt;cPanel</description>      <pubDate>Wed, 16 Jun 2010 15:27:00 -0400</pubDate>      <ddb:attackedentityfield>Service Providers</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology>cPanel</ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>January 1, 2008</ddb:dateoccured>      <ddb:entrytitle>WHID 2007-76: A large web hosting firm inflicted by mass malware installation</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;The Washington Post ran a story about a large scale infiltration to IPower, a major hosting provider. According to the story and the following comments, it seems that the problem is plunging IPower for a long time without being resolved. Put in perspective the &lt;a href=&quot;byid_id_2007-75.shtml&quot;&gt;PlusNet incident&lt;/a&gt; which was serious but swiftly handled and publicly acknowledged by the company.&lt;/p&gt;&#13;&lt;p&gt;Actually the problem is so dominant that a recent &lt;a href=&quot;http://stopbadware.org&quot;&gt;StopBadware&lt;/a&gt; report lists Ipower as by far the most Malware infected hosting company. Reports mention that the problem started as early as mid 2006.&#13;&lt;/p&gt;&lt;p&gt;The root cause of the breach here is mentioned as being a vulnerability in either Apache, PHP or cPanel. I have selected the third as being more probably until further evidence materialize.&lt;/p&gt;&#13;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://blog.washingtonpost.com/securityfix/2007/05/cyber_crooks_hijack_activities_1.html&quot;&gt;Cyber Crooks Hijack Activities of Large Web-Hosting Firm&lt;/a&gt; [Washington Post, May 23 2007]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://stopbadware.org/home/pr_050307&quot;&gt;StopBadware.org Identifies Companies Hosting Large Numbers of Websites That Can Infect Internet Users With Badware&lt;/a&gt; [StopBadware, May 4 2007]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Planting of Malware</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2007-76</ddb:whidid>    </item>    <item>      <title>WHID 2009-5: School data hacked, grades altered</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=35024</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2009-5: School data hacked, grades altered&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2009-5&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;January 15, 2009&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Disinformation&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;This &lt;a href=&quot;http://www.tmcnet.com/usubmit/2009/01/15/3916297.htm&quot;&gt;story &lt;/a&gt;about student hacking a Pottsville, PA school online system and changing grades demonstrated again that password stealing is by far the most common method in which web sites are hacked.&lt;/p&gt;&lt;br&gt;&lt;p&gt;While it is usually not considered a vulnerability in the application itself, I think that application that expose administrative or high privileges interface to the web should include authentication beyond a simple password. A school grading system is one example. The Twitter administrative interface &lt;a href=&quot;/whid-2009-2&quot;&gt;hacked last week&lt;/a&gt; is another example.&lt;/p&gt;&lt;br&gt;&lt;p&gt; &lt;/p&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Education&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA</description>      <pubDate>Wed, 16 Jun 2010 14:23:05 -0400</pubDate>      <ddb:attackedentityfield>Education</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>January 15, 2009</ddb:dateoccured>      <ddb:entrytitle>WHID 2009-5: School data hacked, grades altered</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;This &lt;a href=&quot;http://www.tmcnet.com/usubmit/2009/01/15/3916297.htm&quot;&gt;story &lt;/a&gt;about student hacking a Pottsville, PA school online system and changing grades demonstrated again that password stealing is by far the most common method in which web sites are hacked.&lt;/p&gt;&#13;&lt;p&gt;While it is usually not considered a vulnerability in the application itself, I think that application that expose administrative or high privileges interface to the web should include authentication beyond a simple password. A school grading system is one example. The Twitter administrative interface &lt;a href=&quot;/whid-2009-2&quot;&gt;hacked last week&lt;/a&gt; is another example.&lt;/p&gt;&#13;&lt;p&gt; &lt;/p></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Disinformation</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2009-5</ddb:whidid>    </item>    <item>      <title>WHID 2007-77: HostGator: cPanel Security Hole Exploited in Mass Hack</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34668</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2007-77: HostGator: cPanel Security Hole Exploited in Mass Hack&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2007-77&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;January 1, 2008&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Planting of Malware&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Hackers exploited an unknown cPanel vulnerability to break into HostGator servers and plant malware on hosted sites.&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://news.netcraft.com/archives/2006/09/23/hostgator_cpanel_security_hole_exploited_in_mass_hack.html&quot;&gt;HostGator: cPanel Security Hole Exploited in Mass Hack&lt;/a&gt; [NetCraft, Sep 23 2007]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://news.netcraft.com/archives/2006/09/22/hacked_hostgator_sites_distribute_ie_exploit.html&quot;&gt;Hacked HostGator Sites Distribute IE Exploit&lt;/a&gt; [NetCraft, Sep 22 2008]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Service Providers&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA&lt;br&gt;&lt;b&gt;Attacked System Technology: &lt;/b&gt;cPanel</description>      <pubDate>Wed, 16 Jun 2010 15:26:18 -0400</pubDate>      <ddb:attackedentityfield>Service Providers</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology>cPanel</ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>January 1, 2008</ddb:dateoccured>      <ddb:entrytitle>WHID 2007-77: HostGator: cPanel Security Hole Exploited in Mass Hack</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Hackers exploited an unknown cPanel vulnerability to break into HostGator servers and plant malware on hosted sites.&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://news.netcraft.com/archives/2006/09/23/hostgator_cpanel_security_hole_exploited_in_mass_hack.html&quot;&gt;HostGator: cPanel Security Hole Exploited in Mass Hack&lt;/a&gt; [NetCraft, Sep 23 2007]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://news.netcraft.com/archives/2006/09/22/hacked_hostgator_sites_distribute_ie_exploit.html&quot;&gt;Hacked HostGator Sites Distribute IE Exploit&lt;/a&gt; [NetCraft, Sep 22 2008]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Planting of Malware</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2007-77</ddb:whidid>    </item>    <item>      <title>WHID 2006-24: Hotmail XSS (2)</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34145</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2006-24: Hotmail XSS (2)&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2006-24&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;April 12, 2006&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Disclosure Only&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;The $a variable in Hotmail's inbox is vulnerable to cross site scripting vulnerability. Exploit requires the victim to open the email message.&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.morx.org/HotmailCookieXploit.txt&quot;&gt;Hotmail Cross Site Scripting&lt;/a&gt; [Simo Ben Youssef, Feb 20 2006]&lt;/li&gt;&lt;br&gt;&lt;/ul></description>      <pubDate>Wed, 16 Jun 2010 18:29:47 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>April 12, 2006</ddb:dateoccured>      <ddb:entrytitle>WHID 2006-24: Hotmail XSS (2)</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;The $a variable in Hotmail's inbox is vulnerable to cross site scripting vulnerability. Exploit requires the victim to open the email message.&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.morx.org/HotmailCookieXploit.txt&quot;&gt;Hotmail Cross Site Scripting&lt;/a&gt; [Simo Ben Youssef, Feb 20 2006]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Disclosure Only</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2006-24</ddb:whidid>    </item>    <item>      <title>WHID 2009-40: SQL injection Hits Sensitive US Army servers</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=35293</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2009-40: SQL injection Hits Sensitive US Army servers&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2009-40&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;January 26, 2009&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Defacement&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;Information Week reports that a well known Turkish hacker penetrated two sensitive US army servers, one at McAlester Ammunition Plant in McAlester, Okla., and the other at the U.S. Army Corps of Engineers' Transatlantic Center in Winchester, Va. The hacks are the currently under criminal investigation by Defense Department officials.&lt;br&gt;The breaches where not publicly disclosed and the level of exposure is therefore not known. It is known however that web site visitors where redirected to a site protesting against climate change.&lt;br&gt;The Register speculates that the attack method was SQL injection.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;Turkey&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Government&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://www.informationweek.com/news/government/federal/showArticle.jhtml?articleID=217700619&quot;&gt;http://www.informationweek.com/news/government/federal/showArticle.jhtml?articleID=217700619&lt;/a></description>      <pubDate>Wed, 16 Jun 2010 14:14:05 -0400</pubDate>      <ddb:attackedentityfield>Government</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography>Turkey</ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>January 26, 2009</ddb:dateoccured>      <ddb:entrytitle>WHID 2009-40: SQL injection Hits Sensitive US Army servers</ddb:entrytitle>      <ddb:incidentdescription>Information Week reports that a well known Turkish hacker penetrated two sensitive US army servers, one at McAlester Ammunition Plant in McAlester, Okla., and the other at the U.S. Army Corps of Engineers' Transatlantic Center in Winchester, Va. The hacks are the currently under criminal investigation by Defense Department officials.&#13;&#10;&#13;&#10;The breaches where not publicly disclosed and the level of exposure is therefore not known. It is known however that web site visitors where redirected to a site protesting against climate change.&#13;&#10;&#13;&#10;The Register speculates that the attack method was SQL injection.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Defacement</ddb:outcome>      <ddb:reference>http://www.informationweek.com/news/government/federal/showArticle.jhtml?articleID=217700619</ddb:reference>      <ddb:whidid>2009-40</ddb:whidid>    </item>    <item>      <title>WHID 2007-78: A Brazilian banking site allows users to views receipts intended for others</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34673</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2007-78: A Brazilian banking site allows users to views receipts intended for others&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2007-78&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;January 1, 2008&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;IDG now reports a bug in the internet banking application of Unibanco, a Brazilian Bank. The vulnerability allowed logged users to view transaction receipts of other unrelated users by changing the &quot;receipt ID&quot; on the form or URL.&lt;/p&gt;&lt;br&gt;&lt;p&gt;Reported by Alexandre Sieira&lt;/p&gt;&lt;br&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://translate.google.com/translate?u=http%3A%2F%2Fidgnow.uol.com.br%2Fseguranca%2F2007%2F01%2F29%2Fidgnoticia.2007-01-29.8751247129%2FIDGNoticia_view&amp;amp;langpair=pt|en&amp;amp;hl=en&amp;amp;ie=UTF-8&quot;&gt;Unibanco tem brecha em sistema de comprovantes de transa??es online&lt;/a&gt; [IDG Now (Google Translate), Jan 29 2007]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Finance&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;Brazil</description>      <pubDate>Wed, 16 Jun 2010 15:24:46 -0400</pubDate>      <ddb:attackedentityfield>Finance</ddb:attackedentityfield>      <ddb:attackedentitygeography>Brazil</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>January 1, 2008</ddb:dateoccured>      <ddb:entrytitle>WHID 2007-78: A Brazilian banking site allows users to views receipts intended for others</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;IDG now reports a bug in the internet banking application of Unibanco, a Brazilian Bank. The vulnerability allowed logged users to view transaction receipts of other unrelated users by changing the &quot;receipt ID&quot; on the form or URL.&lt;/p&gt;&#13;&lt;p&gt;Reported by Alexandre Sieira&lt;/p&gt;&#13;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://translate.google.com/translate?u=http%3A%2F%2Fidgnow.uol.com.br%2Fseguranca%2F2007%2F01%2F29%2Fidgnoticia.2007-01-29.8751247129%2FIDGNoticia_view&amp;amp;langpair=pt|en&amp;amp;hl=en&amp;amp;ie=UTF-8&quot;&gt;Unibanco tem brecha em sistema de comprovantes de transa??es online&lt;/a&gt; [IDG Now (Google Translate), Jan 29 2007]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2007-78</ddb:whidid>    </item>    <item>      <title>WHID 2009-4: Twitter  Personal Info CSRF</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=35019</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2009-4: Twitter  Personal Info CSRF&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2009-4&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;January 7, 2009&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Gareth Heyes (and others) reported an interesting vulnerability in Twitter last week. While his &lt;a href=&quot;http://www.thespanner.co.uk/2009/01/07/i-know-what-your-friends-did-last-summer/&quot;&gt;post &lt;/a&gt;included a proof of concept code, it does not qualify as a hack only a vulnerability disclosure and the Web Hacking Incident Database does not list vulnerabilities.&lt;/p&gt;&lt;br&gt;&lt;p&gt;Luckily &lt;img src=&quot;/sites/all/modules/wysiwyg/tinymce/jscripts/tiny_mce/plugins/emotions/img/smiley-cool.gif&quot; alt=&quot;Cool&quot; title=&quot;Cool&quot; /&gt; &lt;a href=&quot;http://maone.net/&quot;&gt;Giorgio Maone&lt;/a&gt; decided to create his own proof of concept, run it himself and &lt;a href=&quot;http://hackademix.net/2009/01/13/twitter-json-hijacking-updates/&quot;&gt;provide us with the result&lt;/a&gt;, enabling me to label this as a hack&lt;/p&gt;&lt;br&gt;&lt;p&gt;By exploiting a CSRF bug in twitter (or maybe a feature?) site owners can get twitter profiles of their visitors. For Twitter this is a second this year and now the comprise 50% of the web incidents for 2009. Is this going to be the year of Web 2.0 security?&lt;/p&gt;&lt;br&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;Italy&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Web 2.0&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA</description>      <pubDate>Wed, 16 Jun 2010 14:23:05 -0400</pubDate>      <ddb:attackedentityfield>Web 2.0</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography>Italy</ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>January 7, 2009</ddb:dateoccured>      <ddb:entrytitle>WHID 2009-4: Twitter  Personal Info CSRF</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Gareth Heyes (and others) reported an interesting vulnerability in Twitter last week. While his &lt;a href=&quot;http://www.thespanner.co.uk/2009/01/07/i-know-what-your-friends-did-last-summer/&quot;&gt;post &lt;/a&gt;included a proof of concept code, it does not qualify as a hack only a vulnerability disclosure and the Web Hacking Incident Database does not list vulnerabilities.&lt;/p&gt;&#13;&#10;&lt;p&gt;Luckily &lt;img src=&quot;/sites/all/modules/wysiwyg/tinymce/jscripts/tiny_mce/plugins/emotions/img/smiley-cool.gif&quot; alt=&quot;Cool&quot; title=&quot;Cool&quot; /&gt; &lt;a href=&quot;http://maone.net/&quot;&gt;Giorgio Maone&lt;/a&gt; decided to create his own proof of concept, run it himself and &lt;a href=&quot;http://hackademix.net/2009/01/13/twitter-json-hijacking-updates/&quot;&gt;provide us with the result&lt;/a&gt;, enabling me to label this as a hack&lt;/p&gt;&#13;&#10;&lt;p&gt;By exploiting a CSRF bug in twitter (or maybe a feature?) site owners can get twitter profiles of their visitors. For Twitter this is a second this year and now the comprise 50% of the web incidents for 2009. Is this going to be the year of Web 2.0 security?&lt;/p&gt;&#13;&#10;&lt;p&gt;&amp;nbsp;&lt;/p></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2009-4</ddb:whidid>    </item>    <item>      <title>WHID 2007-79: Infamous Russian malware gang used SQL injection to penetrate US government sites</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34678</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2007-79: Infamous Russian malware gang used SQL injection to penetrate US government sites&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2007-79&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;January 1, 2008&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;RBN was a big story. It was a hackers group that could work relatively freely in Russia due to rumors connections in high windows. This way it could allow safe hosting for malware. For getting people to the malware they penetrated web sites around the world, and the references article mentioned SQL injection as the method they infiltrated more high profile sites such as US government sites.&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.news.com/Infamous-Russian-malware-gang-vanishes/2100-7355_3-6217852.html?part=rss&amp;amp;tag=2547-1_3-0-5&amp;amp;subj=news&quot;&gt;Infamous Russian malware gang vanishes&lt;/a&gt; [News.com, Nov 9 2008]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.grumpysecurityguy.com/governement-sql-injection/&quot;&gt;US Gov sites Hacked with SQL Injection&lt;/a&gt; [Bill Pennington, Nov 9 2008]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;Russia&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Government</description>      <pubDate>Mon, 24 May 2010 13:54:42 -0400</pubDate>      <ddb:attackedentityfield>Government</ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography>Russia</ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>January 1, 2008</ddb:dateoccured>      <ddb:entrytitle>WHID 2007-79: Infamous Russian malware gang used SQL injection to penetrate US government sites</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;RBN was a big story. It was a hackers group that could work relatively freely in Russia due to rumors connections in high windows. This way it could allow safe hosting for malware. For getting people to the malware they penetrated web sites around the world, and the references article mentioned SQL injection as the method they infiltrated more high profile sites such as US government sites.&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.news.com/Infamous-Russian-malware-gang-vanishes/2100-7355_3-6217852.html?part=rss&amp;amp;tag=2547-1_3-0-5&amp;amp;subj=news&quot;&gt;Infamous Russian malware gang vanishes&lt;/a&gt; [News.com, Nov 9 2008]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.grumpysecurityguy.com/governement-sql-injection/&quot;&gt;US Gov sites Hacked with SQL Injection&lt;/a&gt; [Bill Pennington, Nov 9 2008]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome></ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2007-79</ddb:whidid>    </item>    <item>      <title>WHID 2008-49: ValueClick weak decryption and vulnerability to SQL injection</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=35013</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2008-49: ValueClick weak decryption and vulnerability to SQL injection&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2008-49&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;March 17, 2008&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Monetary Loss&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;As a side story to ValueClick indictment of deceptive marketing by the FTC, the &lt;a href=&quot;http://www.ftc.gov/opa/2008/03/vc.shtm&quot;&gt;FTC investigation&lt;/a&gt; also found SQL injection vulnerabilities and lack of sufficient encryption of sensitive customer information. These findings contributed to the $2.9 million fine the FTC levied on ValueClick as well as to the company &lt;a href=&quot;http://www.theregister.co.uk/2008/03/17/ebay_dumps_valueclick/&quot;&gt;being dumped from managing eBay's affiliate program&lt;/a&gt;.&lt;/p&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Marketing&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA</description>      <pubDate>Wed, 16 Jun 2010 14:40:05 -0400</pubDate>      <ddb:attackedentityfield>Marketing</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>March 17, 2008</ddb:dateoccured>      <ddb:entrytitle>WHID 2008-49: ValueClick weak decryption and vulnerability to SQL injection</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;As a side story to ValueClick indictment of deceptive marketing by the FTC, the &lt;a href=&quot;http://www.ftc.gov/opa/2008/03/vc.shtm&quot;&gt;FTC investigation&lt;/a&gt; also found SQL injection vulnerabilities and lack of sufficient encryption of sensitive customer information. These findings contributed to the $2.9 million fine the FTC levied on ValueClick as well as to the company &lt;a href=&quot;http://www.theregister.co.uk/2008/03/17/ebay_dumps_valueclick/&quot;&gt;being dumped from managing eBay's affiliate program&lt;/a&gt;.&lt;/p></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Monetary Loss</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2008-49</ddb:whidid>    </item>    <item>      <title>WHID 2007-80: Vodafone blocks website after hacking</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34684</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2007-80: Vodafone blocks website after hacking&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2007-80&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;January 1, 2008&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Defacement&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Yet another defacement, but this time at a very major telecommunication provider in India. These are the guys in charge of our network after all!&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://timesofindia.indiatimes.com/Lucknow/Vodafone_blocks_website_after_hacking/articleshow/2523834.cms&quot;&gt;Vodafone blocks website after hacking&lt;/a&gt; [Times of India, Nov 7 2007]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Service Providers&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;India</description>      <pubDate>Wed, 16 Jun 2010 15:21:21 -0400</pubDate>      <ddb:attackedentityfield>Service Providers</ddb:attackedentityfield>      <ddb:attackedentitygeography>India</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>January 1, 2008</ddb:dateoccured>      <ddb:entrytitle>WHID 2007-80: Vodafone blocks website after hacking</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Yet another defacement, but this time at a very major telecommunication provider in India. These are the guys in charge of our network after all!&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://timesofindia.indiatimes.com/Lucknow/Vodafone_blocks_website_after_hacking/articleshow/2523834.cms&quot;&gt;Vodafone blocks website after hacking&lt;/a&gt; [Times of India, Nov 7 2007]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Defacement</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2007-80</ddb:whidid>    </item>    <item>      <title>WHID 2006-23: ICQ search vulnerable to XSS</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34140</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2006-23: ICQ search vulnerable to XSS&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2006-23&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;April 12, 2006&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Disclosure Only&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;ICQ.com search script (search_result.php) is vulnerable to cross-site scripting attacks. This problem is due to a failure&lt;br /&gt;in the application  to properly sanitize user input, the input can be passed to the vulnerable script in 2 variables&lt;br /&gt;(gender and home_country_code).&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.morx.org/ICQ-XSS.txt&quot;&gt;ICQ Cross Site Scripting&lt;/a&gt; [Simo Ben Youssef, Jan 10 2006]&lt;/li&gt;&lt;br&gt;&lt;/ul></description>      <pubDate>Wed, 16 Jun 2010 18:30:18 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>April 12, 2006</ddb:dateoccured>      <ddb:entrytitle>WHID 2006-23: ICQ search vulnerable to XSS</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;ICQ.com search script (search_result.php) is vulnerable to cross-site scripting attacks. This problem is due to a failure&lt;br /&gt;in the application  to properly sanitize user input, the input can be passed to the vulnerable script in 2 variables&lt;br /&gt;(gender and home_country_code).&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.morx.org/ICQ-XSS.txt&quot;&gt;ICQ Cross Site Scripting&lt;/a&gt; [Simo Ben Youssef, Jan 10 2006]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Disclosure Only</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2006-23</ddb:whidid>    </item>    <item>      <title>WHID 2006-22: SQL injection in a banking application</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34135</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2006-22: SQL injection in a banking application&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2006-22&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;April 12, 2006&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Disclosure Only&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;A CIO of a bank in Singapore reports that many application layer vulnerabilities, including SQL injection, where discovered in a banking application they purchased before it was put into production.&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.cio-asia.com/ShowPage.aspx?pagetype=2&amp;amp;articleid=3381&amp;amp;pubid=5&amp;amp;issueid=81&quot;&gt;Pulled in All Directions&lt;/a&gt; [CIO Asia, Jan 1 2006]&lt;/li&gt;&lt;br&gt;&lt;/ul></description>      <pubDate>Wed, 16 Jun 2010 18:30:49 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>April 12, 2006</ddb:dateoccured>      <ddb:entrytitle>WHID 2006-22: SQL injection in a banking application</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;A CIO of a bank in Singapore reports that many application layer vulnerabilities, including SQL injection, where discovered in a banking application they purchased before it was put into production.&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.cio-asia.com/ShowPage.aspx?pagetype=2&amp;amp;articleid=3381&amp;amp;pubid=5&amp;amp;issueid=81&quot;&gt;Pulled in All Directions&lt;/a&gt; [CIO Asia, Jan 1 2006]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Disclosure Only</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2006-22</ddb:whidid>    </item>    <item>      <title>WHID 2007-81: MSNBC Turkish site caught serving malware</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34689</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2007-81: MSNBC Turkish site caught serving malware&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2007-81&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;January 1, 2008&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Planting of Malware&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Another Malware defacement, but this time at a very prominent web site: MSNBC Turkish edition. There are indications that this is an application layer attack.&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://blogs.zdnet.com/security/?p=641&quot;&gt;MSNBC Turkish site caught serving malware&lt;/a&gt; [Zdnet, Nov 7 2007]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.websense.com/securitylabs/alerts/alert.php?AlertID=817&quot;&gt;Malicious Website / Malicious Code:   MSNBC's Turkish site compromise&lt;/a&gt; [WebSense, Nov 7 2007]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://isc.sans.org/diary.html?storyid=3621&quot;&gt;yl18.net mass defacement &lt;/a&gt; [SANS ISC, Nov 6 2007]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Media&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;Turkey</description>      <pubDate>Wed, 16 Jun 2010 15:20:54 -0400</pubDate>      <ddb:attackedentityfield>Media</ddb:attackedentityfield>      <ddb:attackedentitygeography>Turkey</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>January 1, 2008</ddb:dateoccured>      <ddb:entrytitle>WHID 2007-81: MSNBC Turkish site caught serving malware</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Another Malware defacement, but this time at a very prominent web site: MSNBC Turkish edition. There are indications that this is an application layer attack.&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://blogs.zdnet.com/security/?p=641&quot;&gt;MSNBC Turkish site caught serving malware&lt;/a&gt; [Zdnet, Nov 7 2007]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.websense.com/securitylabs/alerts/alert.php?AlertID=817&quot;&gt;Malicious Website / Malicious Code:   MSNBC's Turkish site compromise&lt;/a&gt; [WebSense, Nov 7 2007]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://isc.sans.org/diary.html?storyid=3621&quot;&gt;yl18.net mass defacement &lt;/a&gt; [SANS ISC, Nov 6 2007]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Planting of Malware</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2007-81</ddb:whidid>    </item>    <item>      <title>WHID 2008-48: TicketMaster Fighting Hackers Line Bypassing</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=35008</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2008-48: TicketMaster Fighting Hackers Line Bypassing&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2008-48&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;March 9, 2008&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Extortion&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;&lt;em&gt;&lt;strong&gt;Update (April 19&lt;sup&gt;th&lt;/sup&gt; 2009)&lt;/strong&gt;&lt;/em&gt; - A &lt;a href=&quot;http://www.vancouversun.com/entertainment/Hackers+foil+Ticketmaster+website+security+order+thousands+tickets+high+priced+resale/1387348/story.html&quot;&gt;recent article in the Vancouver Sun&lt;/a&gt; further discuss the issue. While there are no new technical details, the &lt;a href=&quot;http://www.vancouversun.com/entertainment/Hackers+foil+Ticketmaster+website+security+order+thousands+tickets+high+priced+resale/1387348/story.html#Comments&quot;&gt;discussion that follows&lt;/a&gt; the article is illuminating&lt;/p&gt;&lt;br&gt;&lt;hr /&gt;&lt;br&gt;&lt;p&gt;Insufficient anti-automation is fast becoming a major, if not the major threat to web application. The reason is that it can be very profitable for the hacker, and on the other hand it is far from a simple vulnerability just requiring a quick fix.&lt;/p&gt;&lt;br&gt;&lt;p&gt;&lt;a href=&quot;http://www.canada.com/theprovince/news/story.html?id=a091de62-e480-4cd9-bdd3-32e660081d86&amp;amp;k=9897&quot;&gt;TicketMaster on going combat with hackers&lt;/a&gt; line bypassing to buy event tickets to resell them for a high price is a very good example of the issue. In this specific example the hackers demonstrate that &lt;a href=&quot;http://en.wikipedia.org/wiki/Captcha&quot;&gt;Captcha,&lt;/a&gt; a method of blocking automated programs by presenting a challenge supposedly difficult for a computer software&lt;a href=&quot;http://en.wikipedia.org/wiki/Captcha&quot;&gt;, &lt;/a&gt;is not sufficient.&lt;/p&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Retail&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA</description>      <pubDate>Wed, 16 Jun 2010 14:41:14 -0400</pubDate>      <ddb:attackedentityfield>Retail</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>March 9, 2008</ddb:dateoccured>      <ddb:entrytitle>WHID 2008-48: TicketMaster Fighting Hackers Line Bypassing</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;&lt;em&gt;&lt;strong&gt;Update (April 19&lt;sup&gt;th&lt;/sup&gt; 2009)&lt;/strong&gt;&lt;/em&gt; - A &lt;a href=&quot;http://www.vancouversun.com/entertainment/Hackers+foil+Ticketmaster+website+security+order+thousands+tickets+high+priced+resale/1387348/story.html&quot;&gt;recent article in the Vancouver Sun&lt;/a&gt; further discuss the issue. While there are no new technical details, the &lt;a href=&quot;http://www.vancouversun.com/entertainment/Hackers+foil+Ticketmaster+website+security+order+thousands+tickets+high+priced+resale/1387348/story.html#Comments&quot;&gt;discussion that follows&lt;/a&gt; the article is illuminating&lt;/p&gt;&#13;&lt;hr /&gt;&#13;&lt;p&gt;Insufficient anti-automation is fast becoming a major, if not the major threat to web application. The reason is that it can be very profitable for the hacker, and on the other hand it is far from a simple vulnerability just requiring a quick fix.&lt;/p&gt;&#13;&lt;p&gt;&lt;a href=&quot;http://www.canada.com/theprovince/news/story.html?id=a091de62-e480-4cd9-bdd3-32e660081d86&amp;amp;k=9897&quot;&gt;TicketMaster on going combat with hackers&lt;/a&gt; line bypassing to buy event tickets to resell them for a high price is a very good example of the issue. In this specific example the hackers demonstrate that &lt;a href=&quot;http://en.wikipedia.org/wiki/Captcha&quot;&gt;Captcha,&lt;/a&gt; a method of blocking automated programs by presenting a challenge supposedly difficult for a computer software&lt;a href=&quot;http://en.wikipedia.org/wiki/Captcha&quot;&gt;, &lt;/a&gt;is not sufficient.&lt;/p></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Extortion</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2008-48</ddb:whidid>    </item>    <item>      <title>WHID 2008-01: Information stolen from geeks.com (Updated)</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34694</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2008-01: Information stolen from geeks.com (Updated)&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2008-01&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;January 8, 2008&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;&lt;strong&gt;&lt;em&gt;Update (Feb 8&lt;sup&gt;th&lt;/sup&gt; 2009)&lt;/em&gt;&lt;/strong&gt; - The company has reached a &lt;a href=&quot;http://www.ftc.gov/os/caselist/0823113/index.shtm&quot;&gt;settlement &lt;/a&gt;with the FTC. Not a breathtaking achievement in the effort to make business care about web application security, yet a step in this direction. The report also identifies the attack as an SQL injection attack.&lt;/p&gt;&lt;br&gt;&lt;hr /&gt;&lt;br&gt;&amp;lt;!--break--&gt;&lt;br&gt;&lt;p&gt;Very detailed records of geeks.com customers were stolen from the site. The records included name, address, telephone number, e-mail address, credit card number, expiration date, and most notoriously, card verification number (CVV).&lt;/p&gt;&lt;br&gt;&lt;p&gt;The interesting part is that the site had a Hacker Safe seal. The seal was revoked twice last year due to vulnerabilities, but restored after they where patched. It seems that this time the hack preceded the scan or the scan missed the vulnerability. So much for application scanning and vulnerability assessment....&lt;/p&gt;&lt;br&gt;&lt;p&gt;And don't take it lightly as a geeks site. Geeks.com is a $150M/year business.&lt;/p&gt;&lt;br&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;articleId=9056004&amp;amp;intsrc=news_ts_head&quot;&gt;Update: 'Hacker safe' Web site gets hit by hacker&lt;/a&gt; [Copmuter World, Jan 7 2008]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.informationweek.com/news/showArticle.jhtml?articleID=205600099&amp;amp;subSection=All+Stories&quot;&gt;'Hacker Safe' Geeks.com Hacked&lt;/a&gt; [Information Week, Jan 7 2008]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://consumerist.com/341408/geekscom-website-hacked-customer-data-stolen&quot;&gt;Geeks.com Website Hacked, Customer Data Stolen&lt;/a&gt; [Consumerist, ]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Retail&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA</description>      <pubDate>Wed, 16 Jun 2010 15:16:34 -0400</pubDate>      <ddb:attackedentityfield>Retail</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>January 8, 2008</ddb:dateoccured>      <ddb:entrytitle>WHID 2008-01: Information stolen from geeks.com (Updated)</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;&lt;strong&gt;&lt;em&gt;Update (Feb 8&lt;sup&gt;th&lt;/sup&gt; 2009)&lt;/em&gt;&lt;/strong&gt; - The company has reached a &lt;a href=&quot;http://www.ftc.gov/os/caselist/0823113/index.shtm&quot;&gt;settlement &lt;/a&gt;with the FTC. Not a breathtaking achievement in the effort to make business care about web application security, yet a step in this direction. The report also identifies the attack as an SQL injection attack.&lt;/p&gt;&#13;&lt;hr /&gt;&#13;&amp;lt;!--break--&gt;&#13;&lt;p&gt;Very detailed records of geeks.com customers were stolen from the site. The records included name, address, telephone number, e-mail address, credit card number, expiration date, and most notoriously, card verification number (CVV).&lt;/p&gt;&#13;&lt;p&gt;The interesting part is that the site had a Hacker Safe seal. The seal was revoked twice last year due to vulnerabilities, but restored after they where patched. It seems that this time the hack preceded the scan or the scan missed the vulnerability. So much for application scanning and vulnerability assessment....&lt;/p&gt;&#13;&lt;p&gt;And don't take it lightly as a geeks site. Geeks.com is a $150M/year business.&lt;/p&gt;&#13;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;articleId=9056004&amp;amp;intsrc=news_ts_head&quot;&gt;Update: 'Hacker safe' Web site gets hit by hacker&lt;/a&gt; [Copmuter World, Jan 7 2008]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.informationweek.com/news/showArticle.jhtml?articleID=205600099&amp;amp;subSection=All+Stories&quot;&gt;'Hacker Safe' Geeks.com Hacked&lt;/a&gt; [Information Week, Jan 7 2008]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://consumerist.com/341408/geekscom-website-hacked-customer-data-stolen&quot;&gt;Geeks.com Website Hacked, Customer Data Stolen&lt;/a&gt; [Consumerist, ]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2008-01</ddb:whidid>    </item>    <item>      <title>WHID 2009-39: Uno is back: 245,000 records stolen from Orange France using SQL injection</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=35285</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2009-39: Uno is back: 245,000 records stolen from Orange France using SQL injection&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2009-39&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;May 26, 2009&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;After focusing earlier this year on Anti-Virus vendors, Uno, the Romanian Hacker is now back and reports in his blog that an Orange France web site dedicated to photo management is vulnerable to SQL injection and that he was able to access 245,000 records from the web site.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;Romania&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Service Providers&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;France&lt;br&gt;&lt;b&gt;Number of Records: &lt;/b&gt;245,000&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://www.hackersblog.org/2009/05/25/orange-is-so-cool/&quot;&gt;http://www.hackersblog.org/2009/05/25/orange-is-so-cool/&lt;/a></description>      <pubDate>Wed, 16 Jun 2010 14:14:12 -0400</pubDate>      <ddb:attackedentityfield>Service Providers</ddb:attackedentityfield>      <ddb:attackedentitygeography>France</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography>Romania</ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>May 26, 2009</ddb:dateoccured>      <ddb:entrytitle>WHID 2009-39: Uno is back: 245,000 records stolen from Orange France using SQL injection</ddb:entrytitle>      <ddb:incidentdescription>After focusing earlier this year on Anti-Virus vendors, Uno, the Romanian Hacker is now back and reports in his blog that an Orange France web site dedicated to photo management is vulnerable to SQL injection and that he was able to access 245,000 records from the web site.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords>245,000</ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference>http://www.hackersblog.org/2009/05/25/orange-is-so-cool/</ddb:reference>      <ddb:whidid>2009-39</ddb:whidid>    </item>    <item>      <title>WHID 2007-82: An SQL injection Mass Robot</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34699</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2007-82: An SQL injection Mass Robot&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2007-82&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;January 8, 2008&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Planting of Malware&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;An SQL injection robot is running wild and has already hacked hundreds of thousands of web sites. Since the robot plants malicious code in infected sites, its traces can be found by Googling for a name of Chinese sites referred to in malicious code.&lt;/p&gt;&lt;br&gt;&lt;p&gt;As a security practitioner I often see SQL injection bots, and many times when I install ModSecurity, an open source application firewall but this bot is unique in the way it exploits web sites. It is easier to perform a wide scale attack by exploiting the least common denominator, which in the hacking world is the operating system. As a result most SQL bots tend to try to use SQL injection vectors that will enable issuing OS commands. A good example is a &lt;a href=&quot;http://www.securityfocus.com/bid/21799/discuss&quot;&gt;Cacti vulnerability&lt;/a&gt;: since it allows an OS command to be issued I often see bots looking for it in the wild. This attack is the first I have seen in which the actual attack vector is SQL based. The bot is modifying every record it has access to into a malicious code in the hope that it will be fetched and displayed by the application to its users.&lt;/p&gt;&lt;br&gt;&lt;p&gt;A byproduct if this vector is that is that results are catastrophic for the site owners. While in a case of common defacement attacks restoring (or recreating) the homepage is all it required to get back to business, in this case the whole database is ruined. Considering the scope of the attack and that restoring the database, if it was ever backup, requires much more expertise, the overall damage of this attack is very high.&lt;/p&gt;&lt;br&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.informationweek.com/news/showArticle.jhtml?articleID=205600157&amp;amp;pgno=2&amp;amp;queryText&quot;&gt;70,000 Web Pages Hacked By Database Attack&lt;/a&gt; [Information Week, Jan 8 2008]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://isc.sans.org/diary.html?date=2008-01-04&quot;&gt;Realplayer Vulnerability&lt;/a&gt; [SANS Internet Storm Center, Jan 4 2008]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.heise-security.co.uk/news/101488&quot;&gt;Massive embedded exploit web site attack underway&lt;/a&gt; [Heise, Jan 8 2008]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.modsecurity.org/blog/archives/2008/01/sql_injection_a.html&quot;&gt;SQL Injection Attack Infects Thousands of Websites&lt;/a&gt; [Ryan Barnett, Jan 8 2008]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://isc.sans.org/diary.html?storyid=3823&amp;amp;rss&quot;&gt;Mass exploits with SQL Injection&lt;/a&gt; [SANS, Jan 9 2008]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;China</description>      <pubDate>Thu, 17 Jun 2010 18:28:26 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography>China</ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>January 8, 2008</ddb:dateoccured>      <ddb:entrytitle>WHID 2007-82: An SQL injection Mass Robot</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;An SQL injection robot is running wild and has already hacked hundreds of thousands of web sites. Since the robot plants malicious code in infected sites, its traces can be found by Googling for a name of Chinese sites referred to in malicious code.&lt;/p&gt;&#13;&lt;p&gt;As a security practitioner I often see SQL injection bots, and many times when I install ModSecurity, an open source application firewall but this bot is unique in the way it exploits web sites. It is easier to perform a wide scale attack by exploiting the least common denominator, which in the hacking world is the operating system. As a result most SQL bots tend to try to use SQL injection vectors that will enable issuing OS commands. A good example is a &lt;a href=&quot;http://www.securityfocus.com/bid/21799/discuss&quot;&gt;Cacti vulnerability&lt;/a&gt;: since it allows an OS command to be issued I often see bots looking for it in the wild. This attack is the first I have seen in which the actual attack vector is SQL based. The bot is modifying every record it has access to into a malicious code in the hope that it will be fetched and displayed by the application to its users.&lt;/p&gt;&#13;&lt;p&gt;A byproduct if this vector is that is that results are catastrophic for the site owners. While in a case of common defacement attacks restoring (or recreating) the homepage is all it required to get back to business, in this case the whole database is ruined. Considering the scope of the attack and that restoring the database, if it was ever backup, requires much more expertise, the overall damage of this attack is very high.&lt;/p&gt;&#13;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.informationweek.com/news/showArticle.jhtml?articleID=205600157&amp;amp;pgno=2&amp;amp;queryText&quot;&gt;70,000 Web Pages Hacked By Database Attack&lt;/a&gt; [Information Week, Jan 8 2008]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://isc.sans.org/diary.html?date=2008-01-04&quot;&gt;Realplayer Vulnerability&lt;/a&gt; [SANS Internet Storm Center, Jan 4 2008]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.heise-security.co.uk/news/101488&quot;&gt;Massive embedded exploit web site attack underway&lt;/a&gt; [Heise, Jan 8 2008]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.modsecurity.org/blog/archives/2008/01/sql_injection_a.html&quot;&gt;SQL Injection Attack Infects Thousands of Websites&lt;/a&gt; [Ryan Barnett, Jan 8 2008]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://isc.sans.org/diary.html?storyid=3823&amp;amp;rss&quot;&gt;Mass exploits with SQL Injection&lt;/a&gt; [SANS, Jan 9 2008]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Planting of Malware</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2007-82</ddb:whidid>    </item>    <item>      <title>WHID 2008-47: The Federal Suppliers Guide validates login credential in JavaScript</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=35003</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2008-47: The Federal Suppliers Guide validates login credential in JavaScript&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2008-47&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;February 29, 2008&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Monetary Loss&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Alex Papadimoulis &lt;a href=&quot;http://thedailywtf.com/Articles/So-You-Hacked-Our-Site!.aspx&quot;&gt;tells in a brilliantly humoristic way&lt;/a&gt; about the lack of security of the Federal Suppliers Guide's web site. The guide, is presumably limited to federal procurement agents only, but at the time of writing the credential checking was done on the client in JavaScript and for a single global user name and password.&lt;/p&gt;&lt;br&gt;&lt;p&gt;Beyond making a mockery of the claim that the guide was limited to federal agents only, it also seemed to be a marketing method as it limits the potential advertisers from checking who is in the guide. After getting in Alex contacted some of the advertisers to find out that none of them got any value from the guide. Alex did not join, and I wonder how much Alex's report lowered the Federal Suppliers Guide earning.&lt;/p&gt;&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;USA&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Marketing&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA</description>      <pubDate>Wed, 16 Jun 2010 14:44:09 -0400</pubDate>      <ddb:attackedentityfield>Marketing</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography>USA</ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>February 29, 2008</ddb:dateoccured>      <ddb:entrytitle>WHID 2008-47: The Federal Suppliers Guide validates login credential in JavaScript</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Alex Papadimoulis &lt;a href=&quot;http://thedailywtf.com/Articles/So-You-Hacked-Our-Site!.aspx&quot;&gt;tells in a brilliantly humoristic way&lt;/a&gt; about the lack of security of the Federal Suppliers Guide's web site. The guide, is presumably limited to federal procurement agents only, but at the time of writing the credential checking was done on the client in JavaScript and for a single global user name and password.&lt;/p&gt;&#13;&lt;p&gt;Beyond making a mockery of the claim that the guide was limited to federal agents only, it also seemed to be a marketing method as it limits the potential advertisers from checking who is in the guide. After getting in Alex contacted some of the advertisers to find out that none of them got any value from the guide. Alex did not join, and I wonder how much Alex's report lowered the Federal Suppliers Guide earning.&lt;/p></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Monetary Loss</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2008-47</ddb:whidid>    </item>    <item>      <title>WHID 2008-02: Italian Bank&amp;#039;s XSS Opportunity Seized by Fraudsters</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34704</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2008-02: Italian Bank&amp;#039;s XSS Opportunity Seized by Fraudsters&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2008-02&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;January 9, 2008&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Phishing&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;It has been a while since a phishing scam using XSS vulnerability found its way to the Web Hacking Incidents database (&lt;a href=&quot;http://www.webappsec.org/projects/whid/byid_id_2004-11.shtml&quot;&gt;SunTrust, WHID 2004-11&lt;/a&gt;). The current incident is a good example of what does and does not get into our database: XSS vulnerabilities in public web sites are discovered daily and reported in sites such as &lt;a href=&quot;http://www.xssed.org/&quot;&gt;XSSed&lt;/a&gt;, however most of these vulnerabilities are not included in WHID for lack of public interest. The current incident is different since the vulnerability is known to be exploited by attackers, moving it from the realm of technical interest to the realm of a real problem.&lt;/p&gt;&lt;br&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://news.netcraft.com/archives/2008/01/08/italian_banks_xss_opportunity_seized_by_fraudsters.html&quot;&gt;Italian Bank's XSS Opportunity Seized by Fraudsters&lt;/a&gt; [NetCraft, Jan 8 2008]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Finance&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;Italy</description>      <pubDate>Wed, 16 Jun 2010 15:16:03 -0400</pubDate>      <ddb:attackedentityfield>Finance</ddb:attackedentityfield>      <ddb:attackedentitygeography>Italy</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>January 9, 2008</ddb:dateoccured>      <ddb:entrytitle>WHID 2008-02: Italian Bank&amp;#039;s XSS Opportunity Seized by Fraudsters</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;It has been a while since a phishing scam using XSS vulnerability found its way to the Web Hacking Incidents database (&lt;a href=&quot;http://www.webappsec.org/projects/whid/byid_id_2004-11.shtml&quot;&gt;SunTrust, WHID 2004-11&lt;/a&gt;). The current incident is a good example of what does and does not get into our database: XSS vulnerabilities in public web sites are discovered daily and reported in sites such as &lt;a href=&quot;http://www.xssed.org/&quot;&gt;XSSed&lt;/a&gt;, however most of these vulnerabilities are not included in WHID for lack of public interest. The current incident is different since the vulnerability is known to be exploited by attackers, moving it from the realm of technical interest to the realm of a real problem.&lt;/p&gt;&#13;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://news.netcraft.com/archives/2008/01/08/italian_banks_xss_opportunity_seized_by_fraudsters.html&quot;&gt;Italian Bank's XSS Opportunity Seized by Fraudsters&lt;/a&gt; [NetCraft, Jan 8 2008]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Phishing</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2008-02</ddb:whidid>    </item>    <item>      <title>WHID 2006-21: Sourceforge.net XSS (1)</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34130</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2006-21: Sourceforge.net XSS (1)&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2006-21&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;April 12, 2006&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Disclosure Only&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Sourceforge download pages are vulnerable to XSS&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://seclists.org/lists/bugtraq/2006/Feb/0537.html&quot;&gt;Sourceforge XSS&lt;/a&gt; [Bugtraq, Feb 24 2006]&lt;/li&gt;&lt;br&gt;&lt;/ul></description>      <pubDate>Wed, 16 Jun 2010 18:31:10 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>April 12, 2006</ddb:dateoccured>      <ddb:entrytitle>WHID 2006-21: Sourceforge.net XSS (1)</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Sourceforge download pages are vulnerable to XSS&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://seclists.org/lists/bugtraq/2006/Feb/0537.html&quot;&gt;Sourceforge XSS&lt;/a&gt; [Bugtraq, Feb 24 2006]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Disclosure Only</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2006-21</ddb:whidid>    </item>    <item>      <title>WHID 2009-38: Time's Poll For Most Influencial Hacked</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=35277</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2009-38: Time's Poll For Most Influencial Hacked&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2009-38&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;April 15, 2009&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Link Spam&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Polls are easy target for automation abuse. You can usually participate anonymously and the poll operator has an interest in drawing as many participants as possible, but as &lt;a href=&quot;http://www.xiom.com/whid-2009-3&quot;&gt;demonstrated by previous incidents&lt;/a&gt; such loose security enables hackers to distort the results.&lt;/p&gt;&lt;br&gt;&lt;p&gt;This time &lt;a href=&quot;http://www.theregister.co.uk/2009/04/17/time_top_100_hack/&quot;&gt;a &lt;span&gt;hacker&lt;/span&gt; &lt;span&gt;succeeded&lt;/span&gt; in manipulating&lt;/a&gt; &lt;span&gt;Time's&lt;/span&gt; poll for most &lt;span&gt;influential&lt;/span&gt; people in 2009.&lt;/p&gt;&lt;br&gt;&lt;p&gt;&lt;a href=&quot;http://www.time.com/time/specials/packages/article/0,28804,1883644_1886141,00.html&quot;&gt;&lt;img src=&quot;http://www.xiom.com/sites/default/files/images/time_poll_hacked.png&quot; alt=&quot;Top results for the hacked Time poll&quot; width=&quot;480&quot; height=&quot;156&quot; /&gt;&lt;/a&gt;&lt;/p&gt;&lt;br&gt;&lt;p&gt;Such poll are probably always &lt;span&gt;distorted&lt;/span&gt; by automated programs,&amp;nbsp; with every stakeholder running his own robot to promote a cause. The &lt;a href=&quot;http://www.time.com/time/specials/packages/article/0,28804,1883644_1886141,00.html&quot;&gt;current time poll status&lt;/a&gt; &lt;span&gt;Shawn&lt;/span&gt; above includes mostly known people, though the standings do seem skewed. Is it just that our view of the world is different than others, or have &lt;span&gt;Muslims&lt;/span&gt; around the world become avid Time readers? The top rated person, &quot;moot&quot;, which none of you heard about until now, proves that it is all about automation.&lt;/p&gt;&lt;br&gt;&lt;p&gt;This specific poll distortion &lt;a href=&quot;http://musicmachinery.com/2009/04/15/inside-the-precision-hack/&quot;&gt;reported by Paul &lt;span&gt;&lt;span&gt;Lamere&lt;/span&gt;&lt;/span&gt;&lt;/a&gt; is unique since a group of hackers called 4chan, led by &quot;moot&quot;, took the time to fight Time's humble attempts to mitigate automation. Among the measures and countermeasures that 4chan and Time exchanged are:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;4chan distributed the simple get URL required to vote for moot through legitimate web sites and comment spamming. Such a link can easily be executed automatically by a web site user without his awareness using CSRF techniques.&lt;/li&gt;&lt;br&gt;&lt;li&gt;Using a typical CSRF counter measure, Time added a salted and hashed key to ensure that the poll was submitted from its own poll form. However the key was authentication on the client by &lt;span&gt;Time's&lt;/span&gt; poll Flash application &lt;span&gt;enabling&lt;/span&gt; 4&lt;span&gt;&lt;span&gt;chan&lt;/span&gt;&lt;/span&gt; to easily find it out and overcome the issue. &lt;/li&gt;&lt;br&gt;&lt;li&gt;The Time voting mechanism did not even check that the ranking in the vote was legal, so a link to vote down &quot;moot&quot; competitors in the list was also used until Time fixed the issue. Voting down is key to winning such a poll as 4chan competitors are not at rest running their own sophisticated campaigns.&lt;/li&gt;&lt;br&gt;&lt;li&gt;Lastly 4chan developed sophisticated robots to auto-vote. Those robots overcome Time's anti-automation protections: since each user is allowed to vote just once in every 13 seconds, the robots uses open proxies to vote faster. Since time only prevents voting for the same person from the same IP, the robots used the extra 12 seconds available for each source IP to vote down competitors. The system also reports to a central server allowing monitoring of the voting rate!&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;p&gt;&lt;img src=&quot;http://www.xiom.com/sites/default/files/images/4chan_voting_rate.png&quot; alt=&quot;Rate of voting for &amp;quot;rain&amp;quot; as recorded by 4chan monitoring&quot; width=&quot;480&quot; height=&quot;149&quot; /&gt;&lt;/p&gt;&lt;br&gt;&lt;p&gt;However this specific hack is ever more interesting. At one point 4&lt;span&gt;&lt;span&gt;chan&lt;/span&gt;&lt;/span&gt; where bored with just running moot for presidency, so they decided to use their sophisticated machine to do a more elaborate work. They &lt;span&gt;decided to fix all first 21 nominees so that their initials would spell &quot;&lt;span&gt;Marblecake&lt;/span&gt; Also the Game&quot;. And as &lt;/span&gt;&lt;a href=&quot;http://musicmachinery.files.wordpress.com/2009/04/kg9kl.jpg?w=450&amp;amp;h=460&quot;&gt;Paul &lt;span&gt;&lt;span&gt;Lamere&lt;/span&gt;&lt;/span&gt;'s screenshot&lt;/a&gt; proves, they made it.&lt;/p&gt;&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Media&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://www.theregister.co.uk/2009/04/17/time_top_100_hack/&quot;&gt;http://www.theregister.co.uk/2009/04/17/time_top_100_hack/&lt;/a></description>      <pubDate>Wed, 16 Jun 2010 14:14:14 -0400</pubDate>      <ddb:attackedentityfield>Media</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>April 15, 2009</ddb:dateoccured>      <ddb:entrytitle>WHID 2009-38: Time's Poll For Most Influencial Hacked</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Polls are easy target for automation abuse. You can usually participate anonymously and the poll operator has an interest in drawing as many participants as possible, but as &lt;a href=&quot;http://www.xiom.com/whid-2009-3&quot;&gt;demonstrated by previous incidents&lt;/a&gt; such loose security enables hackers to distort the results.&lt;/p&gt;&#13;&#10;&lt;p&gt;This time &lt;a href=&quot;http://www.theregister.co.uk/2009/04/17/time_top_100_hack/&quot;&gt;a &lt;span&gt;hacker&lt;/span&gt; &lt;span&gt;succeeded&lt;/span&gt; in manipulating&lt;/a&gt; &lt;span&gt;Time's&lt;/span&gt; poll for most &lt;span&gt;influential&lt;/span&gt; people in 2009.&lt;/p&gt;&#13;&#10;&lt;p&gt;&lt;a href=&quot;http://www.time.com/time/specials/packages/article/0,28804,1883644_1886141,00.html&quot;&gt;&lt;img src=&quot;http://www.xiom.com/sites/default/files/images/time_poll_hacked.png&quot; alt=&quot;Top results for the hacked Time poll&quot; width=&quot;480&quot; height=&quot;156&quot; /&gt;&lt;/a&gt;&lt;/p&gt;&#13;&#10;&lt;p&gt;Such poll are probably always &lt;span&gt;distorted&lt;/span&gt; by automated programs,&amp;nbsp; with every stakeholder running his own robot to promote a cause. The &lt;a href=&quot;http://www.time.com/time/specials/packages/article/0,28804,1883644_1886141,00.html&quot;&gt;current time poll status&lt;/a&gt; &lt;span&gt;Shawn&lt;/span&gt; above includes mostly known people, though the standings do seem skewed. Is it just that our view of the world is different than others, or have &lt;span&gt;Muslims&lt;/span&gt; around the world become avid Time readers? The top rated person, &quot;moot&quot;, which none of you heard about until now, proves that it is all about automation.&lt;/p&gt;&#13;&#10;&lt;p&gt;This specific poll distortion &lt;a href=&quot;http://musicmachinery.com/2009/04/15/inside-the-precision-hack/&quot;&gt;reported by Paul &lt;span&gt;&lt;span&gt;Lamere&lt;/span&gt;&lt;/span&gt;&lt;/a&gt; is unique since a group of hackers called 4chan, led by &quot;moot&quot;, took the time to fight Time's humble attempts to mitigate automation. Among the measures and countermeasures that 4chan and Time exchanged are:&lt;/p&gt;&#13;&#10;&lt;ul&gt;&#13;&#10;&lt;li&gt;4chan distributed the simple get URL required to vote for moot through legitimate web sites and comment spamming. Such a link can easily be executed automatically by a web site user without his awareness using CSRF techniques.&lt;/li&gt;&#13;&#10;&lt;li&gt;Using a typical CSRF counter measure, Time added a salted and hashed key to ensure that the poll was submitted from its own poll form. However the key was authentication on the client by &lt;span&gt;Time's&lt;/span&gt; poll Flash application &lt;span&gt;enabling&lt;/span&gt; 4&lt;span&gt;&lt;span&gt;chan&lt;/span&gt;&lt;/span&gt; to easily find it out and overcome the issue. &lt;/li&gt;&#13;&#10;&lt;li&gt;The Time voting mechanism did not even check that the ranking in the vote was legal, so a link to vote down &quot;moot&quot; competitors in the list was also used until Time fixed the issue. Voting down is key to winning such a poll as 4chan competitors are not at rest running their own sophisticated campaigns.&lt;/li&gt;&#13;&#10;&lt;li&gt;Lastly 4chan developed sophisticated robots to auto-vote. Those robots overcome Time's anti-automation protections: since each user is allowed to vote just once in every 13 seconds, the robots uses open proxies to vote faster. Since time only prevents voting for the same person from the same IP, the robots used the extra 12 seconds available for each source IP to vote down competitors. The system also reports to a central server allowing monitoring of the voting rate!&lt;/li&gt;&#13;&#10;&lt;/ul&gt;&#13;&#10;&lt;p&gt;&lt;img src=&quot;http://www.xiom.com/sites/default/files/images/4chan_voting_rate.png&quot; alt=&quot;Rate of voting for &amp;quot;rain&amp;quot; as recorded by 4chan monitoring&quot; width=&quot;480&quot; height=&quot;149&quot; /&gt;&lt;/p&gt;&#13;&#10;&lt;p&gt;However this specific hack is ever more interesting. At one point 4&lt;span&gt;&lt;span&gt;chan&lt;/span&gt;&lt;/span&gt; where bored with just running moot for presidency, so they decided to use their sophisticated machine to do a more elaborate work. They &lt;span&gt;decided to fix all first 21 nominees so that their initials would spell &quot;&lt;span&gt;Marblecake&lt;/span&gt; Also the Game&quot;. And as &lt;/span&gt;&lt;a href=&quot;http://musicmachinery.files.wordpress.com/2009/04/kg9kl.jpg?w=450&amp;amp;h=460&quot;&gt;Paul &lt;span&gt;&lt;span&gt;Lamere&lt;/span&gt;&lt;/span&gt;'s screenshot&lt;/a&gt; proves, they made it.&lt;/p></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Link Spam</ddb:outcome>      <ddb:reference>http://www.theregister.co.uk/2009/04/17/time_top_100_hack/</ddb:reference>      <ddb:whidid>2009-38</ddb:whidid>    </item>    <item>      <title>WHID 2006-48: SQL Injection Used to Steal Information from &amp;quot;Life is Good&amp;quot;</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34709</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2006-48: SQL Injection Used to Steal Information from &amp;quot;Life is Good&amp;quot;&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2006-48&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;January 19, 2008&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Credit Card Leakage&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;&lt;em&gt;&lt;strong&gt;Update (Jan 26&lt;sup&gt;th&lt;/sup&gt; 2009) &lt;/strong&gt;&lt;/em&gt;- an &lt;a href=&quot;http://www.scmagazineus.com/Clothing-retailer-settles-with-FTC-over-credit-card-breach/article/109217/&quot;&gt;SC magazine article sheds more light on the incident&lt;/a&gt; revealing that there was actually a breach, apparently using SQL injection, which resulted in leakage of 10,000 credit card numbers&lt;/p&gt;&lt;br&gt;&lt;p&gt;&lt;hr /&gt;&lt;br&gt;An SQL injection vulnerability that could result in a hacker being able to access credit card numbers, expiration dates, and security codes of thousands of consumers was discovered in the web site of retailer &quot;life is good&quot;.&lt;/p&gt;&lt;br&gt;&lt;p&gt;The US Federal Trade Commission charged &quot;life is good&quot; with lack of reasonable and appropriate security for the sensitive consumer information stored on its servers. The company's settlement with the company requires the company to accept a very comprehensive and costly security procedure going forward.&lt;/p&gt;&lt;br&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.informationweek.com/news/showArticle.jhtml?articleID=205901219&quot;&gt;Online Retailer Settles Charges That It Left Consumer Data Open To Hackers&lt;/a&gt; [Information Week, Jan 18 2008]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.storefrontbacktalk.com/story/011808ftc&quot;&gt;FTC Wags Finger At Site For Weak Consumer Data Security&lt;/a&gt; [Storefront Backtack, Jan 18 2008]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.ftc.gov/os/caselist/0723046/index.shtm&quot;&gt;n the Matter of Life is good, Inc., a corporation, and Life is good Retail, Inc., a corporation. FTC Matter No. 072-3046&lt;/a&gt; [Federal Trade Commission, Jan 17 2008]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Retail&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA</description>      <pubDate>Thu, 17 Jun 2010 18:24:19 -0400</pubDate>      <ddb:attackedentityfield>Retail</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>January 19, 2008</ddb:dateoccured>      <ddb:entrytitle>WHID 2006-48: SQL Injection Used to Steal Information from &amp;quot;Life is Good&amp;quot;</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;&lt;em&gt;&lt;strong&gt;Update (Jan 26&lt;sup&gt;th&lt;/sup&gt; 2009) &lt;/strong&gt;&lt;/em&gt;- an &lt;a href=&quot;http://www.scmagazineus.com/Clothing-retailer-settles-with-FTC-over-credit-card-breach/article/109217/&quot;&gt;SC magazine article sheds more light on the incident&lt;/a&gt; revealing that there was actually a breach, apparently using SQL injection, which resulted in leakage of 10,000 credit card numbers&lt;/p&gt;&#13;&lt;p&gt;&lt;hr /&gt;&#13;An SQL injection vulnerability that could result in a hacker being able to access credit card numbers, expiration dates, and security codes of thousands of consumers was discovered in the web site of retailer &quot;life is good&quot;.&lt;/p&gt;&#13;&lt;p&gt;The US Federal Trade Commission charged &quot;life is good&quot; with lack of reasonable and appropriate security for the sensitive consumer information stored on its servers. The company's settlement with the company requires the company to accept a very comprehensive and costly security procedure going forward.&lt;/p&gt;&#13;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.informationweek.com/news/showArticle.jhtml?articleID=205901219&quot;&gt;Online Retailer Settles Charges That It Left Consumer Data Open To Hackers&lt;/a&gt; [Information Week, Jan 18 2008]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.storefrontbacktalk.com/story/011808ftc&quot;&gt;FTC Wags Finger At Site For Weak Consumer Data Security&lt;/a&gt; [Storefront Backtack, Jan 18 2008]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.ftc.gov/os/caselist/0723046/index.shtm&quot;&gt;n the Matter of Life is good, Inc., a corporation, and Life is good Retail, Inc., a corporation. FTC Matter No. 072-3046&lt;/a&gt; [Federal Trade Commission, Jan 17 2008]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Credit Card Leakage</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2006-48</ddb:whidid>    </item>    <item>      <title>WHID 2006-20: Sourceforge.net XSS (2)</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34125</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2006-20: Sourceforge.net XSS (2)&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2006-20&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;April 10, 2006&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Disclosure Only&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Sourceforge forums search is vulnerable to XSS&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://seclists.org/lists/vuln-dev/2006/Apr/0018.html&quot;&gt;Sourceforge.net XSS&lt;/a&gt; [Vulnerability Development, Apr 9 2006]&lt;/li&gt;&lt;br&gt;&lt;/ul></description>      <pubDate>Wed, 16 Jun 2010 18:31:39 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>April 10, 2006</ddb:dateoccured>      <ddb:entrytitle>WHID 2006-20: Sourceforge.net XSS (2)</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Sourceforge forums search is vulnerable to XSS&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://seclists.org/lists/vuln-dev/2006/Apr/0018.html&quot;&gt;Sourceforge.net XSS&lt;/a&gt; [Vulnerability Development, Apr 9 2006]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Disclosure Only</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2006-20</ddb:whidid>    </item>    <item>      <title>WHID 2008-04: RIAA web site cleared</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34714</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2008-04: RIAA web site cleared&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2008-04&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;January 22, 2008&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Defacement&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;The web site of RIAA, the Recording Industry Association of America was attacked twice using SQL injection over the weekend. First a &lt;a href=&quot;http://reddit.com/info/660oo/comments/&quot;&gt;query that takes particularly long time was posted on a social network web site&lt;/a&gt; causing a distributed denial of service attack against the site. Later on hackers found and abused additional SQL injection and XSS vulnerabilities resulting in major defacement of the site.&lt;/p&gt;&lt;br&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.theregister.co.uk/2008/01/21/riaa_hacktivism/&quot;&gt;RIAA wiped off the net&lt;/a&gt; [The Register, Jan 21 2008]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://reddit.com/info/660oo/comments/&quot;&gt;This link runs a slooow SQL query on the RIAA's server. Don't click it; that would be wrong&lt;/a&gt; [Reddit, Jan 20 2008]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://torrentfreak.com/riaa-website-hacked-080120/&quot;&gt;RIAA Website Wiped Clean by &quot;Hackers&quot;&lt;/a&gt; [Torrent Freak, Jan 20 2008]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Entertainment</description>      <pubDate>Wed, 16 Jun 2010 15:15:24 -0400</pubDate>      <ddb:attackedentityfield>Entertainment</ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>January 22, 2008</ddb:dateoccured>      <ddb:entrytitle>WHID 2008-04: RIAA web site cleared</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;The web site of RIAA, the Recording Industry Association of America was attacked twice using SQL injection over the weekend. First a &lt;a href=&quot;http://reddit.com/info/660oo/comments/&quot;&gt;query that takes particularly long time was posted on a social network web site&lt;/a&gt; causing a distributed denial of service attack against the site. Later on hackers found and abused additional SQL injection and XSS vulnerabilities resulting in major defacement of the site.&lt;/p&gt;&#13;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.theregister.co.uk/2008/01/21/riaa_hacktivism/&quot;&gt;RIAA wiped off the net&lt;/a&gt; [The Register, Jan 21 2008]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://reddit.com/info/660oo/comments/&quot;&gt;This link runs a slooow SQL query on the RIAA's server. Don't click it; that would be wrong&lt;/a&gt; [Reddit, Jan 20 2008]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://torrentfreak.com/riaa-website-hacked-080120/&quot;&gt;RIAA Website Wiped Clean by &quot;Hackers&quot;&lt;/a&gt; [Torrent Freak, Jan 20 2008]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Defacement</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2008-04</ddb:whidid>    </item>    <item>      <title>WHID 2006-19: Google XSS</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34120</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2006-19: Google XSS&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2006-19&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;April 10, 2006&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Disclosure Only&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Yet another Google XSS. This time it seems to hit Arabic variant of the main search site. It seems that the actual language selector parameter enables the attack.&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://seclists.org/lists/bugtraq/2006/Apr/0213.html&quot;&gt;Google XSS (1)&lt;/a&gt; [Bugtraq, Apr 10 2006]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://seclists.org/lists/bugtraq/2006/Apr/0222.html&quot;&gt;Google XSS (2)&lt;/a&gt; [Bugrtaq, Apr 10 2006]&lt;/li&gt;&lt;br&gt;&lt;/ul></description>      <pubDate>Wed, 16 Jun 2010 18:32:14 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>April 10, 2006</ddb:dateoccured>      <ddb:entrytitle>WHID 2006-19: Google XSS</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Yet another Google XSS. This time it seems to hit Arabic variant of the main search site. It seems that the actual language selector parameter enables the attack.&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://seclists.org/lists/bugtraq/2006/Apr/0213.html&quot;&gt;Google XSS (1)&lt;/a&gt; [Bugtraq, Apr 10 2006]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://seclists.org/lists/bugtraq/2006/Apr/0222.html&quot;&gt;Google XSS (2)&lt;/a&gt; [Bugrtaq, Apr 10 2006]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Disclosure Only</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2006-19</ddb:whidid>    </item>    <item>      <title>WHID 2009-37: Twitter XSS/CSRF worm series (Updated)</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=35270</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2009-37: Twitter XSS/CSRF worm series (Updated)&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2009-37&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;April 11, 2009&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Worm&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;&lt;em&gt;&lt;strong&gt;Update (Apr 19&lt;sup&gt;th&lt;/sup&gt; 2009)&lt;/strong&gt;&lt;/em&gt; - The initial Mooney Twitter worm has evolved into a series of 5 worms at the time of writing, each exploiting a different vulnerability in Twitter. The latest one specifically focuses on twitter accounts who have a high number of followers thus targeting celebrities such as Ashton Kutcher and Oprah Winfrey &lt;a href=&quot;http://www.sophos.com/blogs/gc/g/2009/04/17/mikeyy-worm-targets-oprah-york-times/&quot;&gt;according to Graham Cluley&lt;/a&gt; from Sophos.&lt;/p&gt;&lt;br&gt;&lt;p&gt;The hack seems to have paid of to Mikeyy Mooney who was &lt;a href=&quot;http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;articleId=9131737&amp;amp;intsrc=news_ts_head&quot;&gt;hired to as security consultant&lt;/a&gt; following the incident.&lt;/p&gt;&lt;br&gt;&lt;hr /&gt;&lt;br&gt;&lt;p&gt;Twitter is in the spotlights again. Mikeyy Mooney, the 17-year-old creator of StalkDaily.com, a Twitter alternative, &lt;a href=&quot;http://www.bnonews.com/news/242.html&quot;&gt;admitted &lt;/a&gt;to hacking his giant competitor by implementing a worm that propagated itself through twitter making every affected user tweet about StalkDaily. Mikeyy certainly got the advertising and page views he was looking for.&lt;/p&gt;&lt;br&gt;&lt;p&gt;&lt;img src=&quot;http://www.xiom.com/sites/default/files/images/Mikeyy_270x246.png&quot; alt=&quot;Mikeyy Mooney, the Twitter worms creator&quot; width=&quot;270&quot; height=&quot;246&quot; style=&quot;float: right;&quot; /&gt;Mikeyy's worm is a good example of how CSRF and XSS can be combined to create a strong blended attack, in this case a propagating worm. A Web 2.0 community generated site such as twitter is often vulnerable to stored XSS . This often implies that a user can update his own profile with malicious code and as a result others who view his content get hit. Without any other vulnerability to complicate things, you are safe as long as your friends are trustworthy.&lt;/p&gt;&lt;br&gt;&lt;p&gt;However, if the site is also vulnerable to CSRF, the XSS exploit can include in addition to the payload also the original XSS inflicting code run under the attacked users credential, modifying his content and therefore hiting his own friends, which hit their own friends and so on.&lt;/p&gt;&lt;br&gt;&lt;p&gt;You can find the technical details of the attack on &lt;a href=&quot;http://dcortesi.com/2009/04/11/twitter-stalkdaily-worm-postmortem/&quot;&gt;Damon Cortesi's blog&lt;/a&gt;. You may also be interested in the &lt;a href=&quot;http://gist.github.com/93782&quot;&gt;full XSS payload&lt;/a&gt;.&lt;/p&gt;&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;USA&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Web 2.0&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://dcortesi.com/2009/04/11/twitter-stalkdaily-worm-postmortem/&quot;&gt;http://dcortesi.com/2009/04/11/twitter-stalkdaily-worm-postmortem/&lt;/a></description>      <pubDate>Wed, 16 Jun 2010 14:14:28 -0400</pubDate>      <ddb:attackedentityfield>Web 2.0</ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography>USA</ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>April 11, 2009</ddb:dateoccured>      <ddb:entrytitle>WHID 2009-37: Twitter XSS/CSRF worm series (Updated)</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;&lt;em&gt;&lt;strong&gt;Update (Apr 19&lt;sup&gt;th&lt;/sup&gt; 2009)&lt;/strong&gt;&lt;/em&gt; - The initial Mooney Twitter worm has evolved into a series of 5 worms at the time of writing, each exploiting a different vulnerability in Twitter. The latest one specifically focuses on twitter accounts who have a high number of followers thus targeting celebrities such as Ashton Kutcher and Oprah Winfrey &lt;a href=&quot;http://www.sophos.com/blogs/gc/g/2009/04/17/mikeyy-worm-targets-oprah-york-times/&quot;&gt;according to Graham Cluley&lt;/a&gt; from Sophos.&lt;/p&gt;&#13;&#10;&lt;p&gt;The hack seems to have paid of to Mikeyy Mooney who was &lt;a href=&quot;http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;articleId=9131737&amp;amp;intsrc=news_ts_head&quot;&gt;hired to as security consultant&lt;/a&gt; following the incident.&lt;/p&gt;&#13;&#10;&lt;hr /&gt;&#13;&#10;&lt;p&gt;Twitter is in the spotlights again. Mikeyy Mooney, the 17-year-old creator of StalkDaily.com, a Twitter alternative, &lt;a href=&quot;http://www.bnonews.com/news/242.html&quot;&gt;admitted &lt;/a&gt;to hacking his giant competitor by implementing a worm that propagated itself through twitter making every affected user tweet about StalkDaily. Mikeyy certainly got the advertising and page views he was looking for.&lt;/p&gt;&#13;&#10;&lt;p&gt;&lt;img src=&quot;http://www.xiom.com/sites/default/files/images/Mikeyy_270x246.png&quot; alt=&quot;Mikeyy Mooney, the Twitter worms creator&quot; width=&quot;270&quot; height=&quot;246&quot; style=&quot;float: right;&quot; /&gt;Mikeyy's worm is a good example of how CSRF and XSS can be combined to create a strong blended attack, in this case a propagating worm. A Web 2.0 community generated site such as twitter is often vulnerable to stored XSS . This often implies that a user can update his own profile with malicious code and as a result others who view his content get hit. Without any other vulnerability to complicate things, you are safe as long as your friends are trustworthy.&lt;/p&gt;&#13;&#10;&lt;p&gt;However, if the site is also vulnerable to CSRF, the XSS exploit can include in addition to the payload also the original XSS inflicting code run under the attacked users credential, modifying his content and therefore hiting his own friends, which hit their own friends and so on.&lt;/p&gt;&#13;&#10;&lt;p&gt;You can find the technical details of the attack on &lt;a href=&quot;http://dcortesi.com/2009/04/11/twitter-stalkdaily-worm-postmortem/&quot;&gt;Damon Cortesi's blog&lt;/a&gt;. You may also be interested in the &lt;a href=&quot;http://gist.github.com/93782&quot;&gt;full XSS payload&lt;/a&gt;.&lt;/p></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Worm</ddb:outcome>      <ddb:reference>http://dcortesi.com/2009/04/11/twitter-stalkdaily-worm-postmortem/</ddb:reference>      <ddb:whidid>2009-37</ddb:whidid>    </item>    <item>      <title>WHID 2009-3: Google Trends Falls Victim to a Stunt</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34998</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2009-3: Google Trends Falls Victim to a Stunt&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2009-3&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;January 6, 2009&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Disinformation&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;&lt;img src=&quot;/sites/default/files/images/trends.gif&quot; align=&quot;right&quot; /&gt;Someone, and not for the 1st time, succeeded in manipulating &lt;a href=&quot;http://www.google.com/trends&quot;&gt;Google Trends&lt;/a&gt;, a Google service listing popular search terms. In this case the New York Time &lt;a href=&quot;http://bits.blogs.nytimes.com/2009/01/07/google-trends-falls-victim-to-disturbing-stunt/?hp&quot;&gt;reports&lt;/a&gt; that a symbol at presumably denoting 9/11 reached number 2 in the list of hot Trends (see picture right).&lt;/p&gt;&lt;br&gt;&lt;p&gt;While this may be nothing more than a joke, the capability to create a trend can have a huge and sometimes devastating effect. After all in recent months the future of big financial institutes was determined by the rumor mill.&lt;/p&gt;&lt;br&gt;&lt;p&gt;On the technical side, insufficient anti-automation controls have been one of the more obscure and hardest to fix vulnerabilities in web applications. Starting with the &lt;a href=&quot;/whid-2005-65&quot;&gt;Lexis-Nexis incident (WHID 2005-65)&lt;/a&gt;, many incidents where waved off as nothing more than an automated client. However, as the incidents pile it becomes clear that it is the responsibility of the site owner to mitigate such harmful automation attacks.&lt;/p&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Internet&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA</description>      <pubDate>Wed, 16 Jun 2010 18:50:03 -0400</pubDate>      <ddb:attackedentityfield>Internet</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>January 6, 2009</ddb:dateoccured>      <ddb:entrytitle>WHID 2009-3: Google Trends Falls Victim to a Stunt</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;&lt;img src=&quot;/sites/default/files/images/trends.gif&quot; align=&quot;right&quot; /&gt;Someone, and not for the 1st time, succeeded in manipulating &lt;a href=&quot;http://www.google.com/trends&quot;&gt;Google Trends&lt;/a&gt;, a Google service listing popular search terms. In this case the New York Time &lt;a href=&quot;http://bits.blogs.nytimes.com/2009/01/07/google-trends-falls-victim-to-disturbing-stunt/?hp&quot;&gt;reports&lt;/a&gt; that a symbol at presumably denoting 9/11 reached number 2 in the list of hot Trends (see picture right).&lt;/p&gt;&#13;&lt;p&gt;While this may be nothing more than a joke, the capability to create a trend can have a huge and sometimes devastating effect. After all in recent months the future of big financial institutes was determined by the rumor mill.&lt;/p&gt;&#13;&lt;p&gt;On the technical side, insufficient anti-automation controls have been one of the more obscure and hardest to fix vulnerabilities in web applications. Starting with the &lt;a href=&quot;/whid-2005-65&quot;&gt;Lexis-Nexis incident (WHID 2005-65)&lt;/a&gt;, many incidents where waved off as nothing more than an automated client. However, as the incidents pile it becomes clear that it is the responsibility of the site owner to mitigate such harmful automation attacks.&lt;/p></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Disinformation</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2009-3</ddb:whidid>    </item>    <item>      <title>WHID 2008-05: Drive-by Pharming in the Wild</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34723</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2008-05: Drive-by Pharming in the Wild&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2008-05&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;January 28, 2008&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Phishing&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Symantec &lt;a href=&quot;http://www.symantec.com/enterprise/security_response/weblog/2008/01/driveby_pharming_in_the_wild.html&quot;&gt;reported&lt;/a&gt; an active exploit of CSRF against residential ADSL routers in Mexico (WHID 2008-05). An e-mail with a malicious IMG tag was sent to victims. By accessing the image in the mail, the user initiated a router command to changethe DNS entry of a leading Mexican bank, making any subsequent access by a user to the bank go through the attacker's server.&lt;/p&gt;&lt;br&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.symantec.com/enterprise/security_response/weblog/2008/01/driveby_pharming_in_the_wild.html&quot;&gt;Drive-by Pharming in the Wild&lt;/a&gt; [Symantec, Jan 22 2008]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.heise-security.co.uk/news/102352&quot;&gt;Symantec reports first active attack on a DSL router&lt;/a&gt; [Heise, Jan 24 2008]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.xiom.com/?p=12&quot;&gt;Client Side Web Server Hacking&lt;/a&gt; [WHID Blog, Jan 28 2008]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Finance&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;Mexico&lt;br&gt;&lt;b&gt;Attacked System Technology: &lt;/b&gt;DSL Router</description>      <pubDate>Wed, 16 Jun 2010 15:14:35 -0400</pubDate>      <ddb:attackedentityfield>Finance</ddb:attackedentityfield>      <ddb:attackedentitygeography>Mexico</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology>DSL Router</ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>January 28, 2008</ddb:dateoccured>      <ddb:entrytitle>WHID 2008-05: Drive-by Pharming in the Wild</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Symantec &lt;a href=&quot;http://www.symantec.com/enterprise/security_response/weblog/2008/01/driveby_pharming_in_the_wild.html&quot;&gt;reported&lt;/a&gt; an active exploit of CSRF against residential ADSL routers in Mexico (WHID 2008-05). An e-mail with a malicious IMG tag was sent to victims. By accessing the image in the mail, the user initiated a router command to changethe DNS entry of a leading Mexican bank, making any subsequent access by a user to the bank go through the attacker's server.&lt;/p&gt;&#13;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.symantec.com/enterprise/security_response/weblog/2008/01/driveby_pharming_in_the_wild.html&quot;&gt;Drive-by Pharming in the Wild&lt;/a&gt; [Symantec, Jan 22 2008]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.heise-security.co.uk/news/102352&quot;&gt;Symantec reports first active attack on a DSL router&lt;/a&gt; [Heise, Jan 24 2008]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.xiom.com/?p=12&quot;&gt;Client Side Web Server Hacking&lt;/a&gt; [WHID Blog, Jan 28 2008]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Phishing</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2008-05</ddb:whidid>    </item>    <item>      <title>WHID 2006-18: Myspace.com - Intricate Script Injection Vulnerability</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34115</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2006-18: Myspace.com - Intricate Script Injection Vulnerability&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2006-18&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;April 10, 2006&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Disclosure Only&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Forget putting &amp;lt;script&amp;gt; tags in input field. This high tech vulnerability exploits the code handling online/offline flags by inserting a malicious online/offline flag. Awesome.&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.silent-products.com/advisory4.5.06.txt&quot;&gt;Myspace.com - Intricate Script Injection Vulnerability&lt;/a&gt; [Justin Lavoie, Apr 5 2006]&lt;/li&gt;&lt;br&gt;&lt;/ul></description>      <pubDate>Wed, 16 Jun 2010 18:33:49 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>April 10, 2006</ddb:dateoccured>      <ddb:entrytitle>WHID 2006-18: Myspace.com - Intricate Script Injection Vulnerability</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Forget putting &amp;lt;script&amp;gt; tags in input field. This high tech vulnerability exploits the code handling online/offline flags by inserting a malicious online/offline flag. Awesome.&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.silent-products.com/advisory4.5.06.txt&quot;&gt;Myspace.com - Intricate Script Injection Vulnerability&lt;/a&gt; [Justin Lavoie, Apr 5 2006]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Disclosure Only</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2006-18</ddb:whidid>    </item>    <item>      <title>WHID 2009-36: Hackers steal Austalian and NZ Shell customer info (Updated)</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=35261</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2009-36: Hackers steal Austalian and NZ Shell customer info (Updated)&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2009-36&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;February 17, 2009&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;&lt;em&gt;&lt;strong&gt;Update (Apr 19&lt;sup&gt;th&lt;/sup&gt; 2009)&lt;/strong&gt;&lt;/em&gt; - (Presumably) the hacker posted a comment to this story with some details. He says that the Number_of_Records leaking was much higher: 17,000 Aussies and 7,000 Kiwis. The rest we did not understand and hope that either he or any of you can clarify.&lt;/p&gt;&lt;br&gt;&lt;p&gt;&lt;a href=&quot;http://www.xiom.com/whid/2009/36/shell_au_hacking&quot;&gt;Read more...&lt;/a&gt;&lt;/p&gt;&lt;br&gt;&lt;p&gt;&lt;hr /&gt;&lt;br&gt;Leakage of information from an energy company is usually associated with gas stations fraud such as installing a stealth credit card reader at the pump. However, a &lt;a href=&quot;http://www.stuff.co.nz/national/2269256/Hackers-steal-Shell-customer-info&quot;&gt;report&lt;/a&gt; suggests that an incident in which information about 4500 Australian and 1400 Kiwis leaked was a result of  a glitch in a web based application for applying for a Shell fuel card. The information obtained included company names, address details, email addresses and some bank account details.&lt;/p&gt;&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Retail&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Number of Records: &lt;/b&gt;5,900&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://www.stuff.co.nz/national/2269256/Hackers-steal-Shell-customer-info&quot;&gt;http://www.stuff.co.nz/national/2269256/Hackers-steal-Shell-customer-info&lt;/a></description>      <pubDate>Wed, 16 Jun 2010 14:14:36 -0400</pubDate>      <ddb:attackedentityfield>Retail</ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>February 17, 2009</ddb:dateoccured>      <ddb:entrytitle>WHID 2009-36: Hackers steal Austalian and NZ Shell customer info (Updated)</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;&lt;em&gt;&lt;strong&gt;Update (Apr 19&lt;sup&gt;th&lt;/sup&gt; 2009)&lt;/strong&gt;&lt;/em&gt; - (Presumably) the hacker posted a comment to this story with some details. He says that the Number_of_Records leaking was much higher: 17,000 Aussies and 7,000 Kiwis. The rest we did not understand and hope that either he or any of you can clarify.&lt;/p&gt;&#13;&#10;&lt;p&gt;&lt;a href=&quot;http://www.xiom.com/whid/2009/36/shell_au_hacking&quot;&gt;Read more...&lt;/a&gt;&lt;/p&gt;&#13;&#10;&lt;p&gt;&lt;hr /&gt;&#13;&#10;Leakage of information from an energy company is usually associated with gas stations fraud such as installing a stealth credit card reader at the pump. However, a &lt;a href=&quot;http://www.stuff.co.nz/national/2269256/Hackers-steal-Shell-customer-info&quot;&gt;report&lt;/a&gt; suggests that an incident in which information about 4500 Australian and 1400 Kiwis leaked was a result of  a glitch in a web based application for applying for a Shell fuel card. The information obtained included company names, address details, email addresses and some bank account details.&lt;/p></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords>5,900</ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference>http://www.stuff.co.nz/national/2269256/Hackers-steal-Shell-customer-info</ddb:reference>      <ddb:whidid>2009-36</ddb:whidid>    </item>    <item>      <title>WHID 2008-06: Hackers Take Down Pennsylvania Government</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34731</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2008-06: Hackers Take Down Pennsylvania Government&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2008-06&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;January 28, 2008&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Defacement&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;&gt;&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.linuxjournal.com/node/1006060&quot;&gt;Hackers Take Down Pennsylvania Government&lt;/a&gt; [Linux Journal, Jan 10 2008]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://ap.google.com/article/ALeqM5iGKgY3SpKw7_p7A8MGHpTfSpN8mAD8TVE5SG0&quot;&gt;Hackers Force Pa. to Shut State Web Site&lt;/a&gt; [AP, Jan 4 2008]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.geeksaresexy.net/2008/01/09/pennsylvania-state-disconnects-from-internet-over-chinese-hacker-phearz/&quot;&gt;Pennsylvania State Disconnects from Internet Over Chinese Hacker Phearz&lt;/a&gt; [Geeks Are Sexy, Jan 9 2008]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.post-gazette.com/pg/08006/847083-85.stm&quot;&gt;Officials say no data was compromised by hackers&lt;/a&gt; [Post Gazette, Jan 6 2008]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Government&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA</description>      <pubDate>Wed, 16 Jun 2010 15:12:52 -0400</pubDate>      <ddb:attackedentityfield>Government</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>January 28, 2008</ddb:dateoccured>      <ddb:entrytitle>WHID 2008-06: Hackers Take Down Pennsylvania Government</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;&gt;&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.linuxjournal.com/node/1006060&quot;&gt;Hackers Take Down Pennsylvania Government&lt;/a&gt; [Linux Journal, Jan 10 2008]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://ap.google.com/article/ALeqM5iGKgY3SpKw7_p7A8MGHpTfSpN8mAD8TVE5SG0&quot;&gt;Hackers Force Pa. to Shut State Web Site&lt;/a&gt; [AP, Jan 4 2008]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.geeksaresexy.net/2008/01/09/pennsylvania-state-disconnects-from-internet-over-chinese-hacker-phearz/&quot;&gt;Pennsylvania State Disconnects from Internet Over Chinese Hacker Phearz&lt;/a&gt; [Geeks Are Sexy, Jan 9 2008]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.post-gazette.com/pg/08006/847083-85.stm&quot;&gt;Officials say no data was compromised by hackers&lt;/a&gt; [Post Gazette, Jan 6 2008]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Defacement</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2008-06</ddb:whidid>    </item>    <item>      <title>WHID 2008-46: CheckFree customers redirected to fraudsters sites</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34991</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2008-46: CheckFree customers redirected to fraudsters sites&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2008-46&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;December 2, 2008&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Phishing&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;In an attack with an alarming similarity to the COX incident (&lt;a href=&quot;/whid-2008-45&quot;&gt;WHID 2008-45&lt;/a&gt;), but with a far greater potential damage, hackers changes the DNS records for CheckFree, the largest bill payment service in the USA. Customers where redirected to servers in the Ukraine, which attempted to install a password login software on their computers.&lt;/p&gt;&lt;br&gt;&lt;p&gt;The change was done using correct credentials to login to the administrative web site of Network Solutions, CheckFree domain registrar. It is yet unknown how the hackers got the credentials. Since &lt;a href=&quot;http://www.icann.org/en/committees/security/sac028.pdf&quot;&gt;Phishing attacks against domain registrars&lt;/a&gt; including Network Solutions have started to surface recently, a good guess is that it was through a Phishing attack.&lt;/p&gt;&lt;br&gt;&lt;p&gt;According to &lt;a href=&quot;http://doj.nh.gov/consumer/pdf/fiserv.pdf&quot;&gt;CheckFree report to the authorities&lt;/a&gt;, it estimates that around 160,000 customers where expoesed to the attack, and informed 5 million potential victims who may have been among this group.&lt;/p&gt;&lt;br&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://voices.washingtonpost.com/securityfix/2008/12/digging_deeper_into_the_checkf.html&quot;&gt;The Washington Post's analysis of the incident&lt;/a&gt;&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;Ukraine&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Finance&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA</description>      <pubDate>Wed, 16 Jun 2010 14:46:00 -0400</pubDate>      <ddb:attackedentityfield>Finance</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography>Ukraine</ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>December 2, 2008</ddb:dateoccured>      <ddb:entrytitle>WHID 2008-46: CheckFree customers redirected to fraudsters sites</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;In an attack with an alarming similarity to the COX incident (&lt;a href=&quot;/whid-2008-45&quot;&gt;WHID 2008-45&lt;/a&gt;), but with a far greater potential damage, hackers changes the DNS records for CheckFree, the largest bill payment service in the USA. Customers where redirected to servers in the Ukraine, which attempted to install a password login software on their computers.&lt;/p&gt;&#13;&lt;p&gt;The change was done using correct credentials to login to the administrative web site of Network Solutions, CheckFree domain registrar. It is yet unknown how the hackers got the credentials. Since &lt;a href=&quot;http://www.icann.org/en/committees/security/sac028.pdf&quot;&gt;Phishing attacks against domain registrars&lt;/a&gt; including Network Solutions have started to surface recently, a good guess is that it was through a Phishing attack.&lt;/p&gt;&#13;&lt;p&gt;According to &lt;a href=&quot;http://doj.nh.gov/consumer/pdf/fiserv.pdf&quot;&gt;CheckFree report to the authorities&lt;/a&gt;, it estimates that around 160,000 customers where expoesed to the attack, and informed 5 million potential victims who may have been among this group.&lt;/p&gt;&#13;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://voices.washingtonpost.com/securityfix/2008/12/digging_deeper_into_the_checkf.html&quot;&gt;The Washington Post's analysis of the incident&lt;/a&gt;&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Phishing</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2008-46</ddb:whidid>    </item>    <item>      <title>WHID 2008-07: Another Free MacWorld Platinum Pass? Yes in 2008!</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34737</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2008-07: Another Free MacWorld Platinum Pass? Yes in 2008!&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2008-07&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;January 28, 2008&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Monetary Loss&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Kurt already got his free MacWorld pass last year (&lt;a href=&quot;http://www.webappsec.org/projects/whid/byid_id_2007-14.shtml&quot;&gt;WHID 2007-14&lt;/a&gt;), but it seems that nothing changes year after year and he was able to pull a similar trick this year. As the codes that allow customers to get the passes where hashed but stored on the client browser, Kurt was able to crack them.&lt;/p&gt;&lt;br&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://grutztopia.jingojango.net/2008/01/another-free-macworld-platinum-pass-yes.html&quot;&gt;Another Free MacWorld Platinum Pass? Yes in 2008!&lt;/a&gt; [Kurt Grutzmacher, Jan 14 2008]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Technology&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA</description>      <pubDate>Wed, 16 Jun 2010 15:12:20 -0400</pubDate>      <ddb:attackedentityfield>Technology</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>January 28, 2008</ddb:dateoccured>      <ddb:entrytitle>WHID 2008-07: Another Free MacWorld Platinum Pass? Yes in 2008!</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Kurt already got his free MacWorld pass last year (&lt;a href=&quot;http://www.webappsec.org/projects/whid/byid_id_2007-14.shtml&quot;&gt;WHID 2007-14&lt;/a&gt;), but it seems that nothing changes year after year and he was able to pull a similar trick this year. As the codes that allow customers to get the passes where hashed but stored on the client browser, Kurt was able to crack them.&lt;/p&gt;&#13;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://grutztopia.jingojango.net/2008/01/another-free-macworld-platinum-pass-yes.html&quot;&gt;Another Free MacWorld Platinum Pass? Yes in 2008!&lt;/a&gt; [Kurt Grutzmacher, Jan 14 2008]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Monetary Loss</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2008-07</ddb:whidid>    </item>    <item>      <title>WHID 2006-17: Mass defacement using XSS at Israblog</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34110</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2006-17: Mass defacement using XSS at Israblog&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2006-17&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;April 10, 2006&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Defacement&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Israblog is a large Israeli blogging site. A hacker used XSS to hijack bloggers sessions and deface them. The defacing was used to inform the world that Israblog lead developer is a bad programmer.&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.nrg.co.il/online/10/ART1/070/252.html&quot;&gt;Large Scale Breakin to Israblog&lt;/a&gt; [NRG (Hebrew), Apr 5 2006]&lt;/li&gt;&lt;br&gt;&lt;/ul></description>      <pubDate>Wed, 16 Jun 2010 18:34:21 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>April 10, 2006</ddb:dateoccured>      <ddb:entrytitle>WHID 2006-17: Mass defacement using XSS at Israblog</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Israblog is a large Israeli blogging site. A hacker used XSS to hijack bloggers sessions and deface them. The defacing was used to inform the world that Israblog lead developer is a bad programmer.&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.nrg.co.il/online/10/ART1/070/252.html&quot;&gt;Large Scale Breakin to Israblog&lt;/a&gt; [NRG (Hebrew), Apr 5 2006]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Defacement</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2006-17</ddb:whidid>    </item>    <item>      <title>WHID 2007-83: More Social Security numbers leaked at Montana State University</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34742</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2007-83: More Social Security numbers leaked at Montana State University&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2007-83&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;January 28, 2008&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Again a Microsoft Excel file was left on a University's web site for anyone to view.&lt;/p&gt;&lt;br&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.montanasnewsstation.com/Global/story.asp?S=7321482&amp;amp;nav=LpDb&quot;&gt;More Social Security numbers leaked at MSU&lt;/a&gt; [Montana's News Station, Nov 7 2007]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Education&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA</description>      <pubDate>Wed, 16 Jun 2010 15:20:46 -0400</pubDate>      <ddb:attackedentityfield>Education</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>January 28, 2008</ddb:dateoccured>      <ddb:entrytitle>WHID 2007-83: More Social Security numbers leaked at Montana State University</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Again a Microsoft Excel file was left on a University's web site for anyone to view.&lt;/p&gt;&#13;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.montanasnewsstation.com/Global/story.asp?S=7321482&amp;amp;nav=LpDb&quot;&gt;More Social Security numbers leaked at MSU&lt;/a&gt; [Montana's News Station, Nov 7 2007]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2007-83</ddb:whidid>    </item>    <item>      <title>WHID 2006-16: AstraTel customer call records leaked</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34105</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2006-16: AstraTel customer call records leaked&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2006-16&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;April 10, 2006&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;A security hole in Sydney internet provider Astratel's LiveBilling online account management system has seriously compromised its customers' privacy.&lt;br&gt;&lt;/p&gt;&lt;p&gt; The service redirected users to a different server and propagated the user information in a hidden field without re-authenticating.&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://australianit.news.com.au/articles/0,7204,18665780%5E15331%5E%5Enbv%5E15306%2D15318,00.html&quot;&gt;Privacy breach at ISP&lt;/a&gt; [Australian IT, Mar 31 2006]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://forums.whirlpool.net.au/forum-replies.cfm?t=498645&quot;&gt;AstraTel customer call records leaked&lt;/a&gt; [Public Forum, Mar 31 2006]&lt;/li&gt;&lt;br&gt;&lt;/ul></description>      <pubDate>Wed, 16 Jun 2010 18:35:22 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>April 10, 2006</ddb:dateoccured>      <ddb:entrytitle>WHID 2006-16: AstraTel customer call records leaked</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;A security hole in Sydney internet provider Astratel's LiveBilling online account management system has seriously compromised its customers' privacy.&#13;&lt;/p&gt;&lt;p&gt; The service redirected users to a different server and propagated the user information in a hidden field without re-authenticating.&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://australianit.news.com.au/articles/0,7204,18665780%5E15331%5E%5Enbv%5E15306%2D15318,00.html&quot;&gt;Privacy breach at ISP&lt;/a&gt; [Australian IT, Mar 31 2006]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://forums.whirlpool.net.au/forum-replies.cfm?t=498645&quot;&gt;AstraTel customer call records leaked&lt;/a&gt; [Public Forum, Mar 31 2006]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2006-16</ddb:whidid>    </item>    <item>      <title>WHID 2009-2: Twitter accounts of the famous hacked (Updated)</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34985</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2009-2: Twitter accounts of the famous hacked (Updated)&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2009-2&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;January 5, 2009&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Defacement&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;&lt;em&gt;&lt;strong&gt;Update (Jan 11&lt;sup&gt;th&lt;/sup&gt; 2009)&lt;/strong&gt;&lt;/em&gt; - The hacker &lt;a href=&quot;http://blog.wired.com/27bstroke6/2009/01/professed-twitt.html&quot;&gt;bragged &lt;/a&gt;about the hack and revealed that it was a brute force dictionary attack against an administrator account. Twitter does not block repetitive login failures therefore enabling brute force attacks. We are still leaving the incident classification &quot;insufficient authentication&quot; in addition to brute force as we feel an administration interface should have additional authentication mechanism and not just a password.&lt;/p&gt;&lt;br&gt;&lt;hr /&gt;&lt;br&gt;&lt;hr /&gt;&lt;br&gt;&lt;p&gt;Twitter &lt;a href=&quot;http://blog.twitter.com/2009/01/monday-morning-madness.html&quot;&gt;announced &lt;/a&gt;that a hacker broke into 33 accounts including Obama's now inactive twitter. The hack is a result of a flaw in a web based support tool used by twitter, which where evidently accessible externally without proper authorization.&lt;/p&gt;&lt;br&gt;&lt;p&gt;It is important to note that this incident is not related to &lt;a href=&quot;http://blog.twitter.com/2009/01/gone-phishing.html&quot;&gt;Twitter phishing attack&lt;/a&gt; which occurred on the previous weekend.&lt;/p&gt;&lt;br&gt;&lt;p&gt;This incident highlights the issue of public facing administration interfaces, which often combine strong functionality with lesser attention to quality and therefore security. As organizations virtualize, those interfaces become available over the Internet, often without sufficient protection.&lt;/p&gt;&lt;br&gt;&lt;p&gt;You can read some of the funny things that the hacker published in different twitters on &lt;a href=&quot;http://www.readwriteweb.com/archives/twitter_security_collapses_oba.php&quot;&gt;Read Write Web&lt;/a&gt;.&lt;/p&gt;&lt;br&gt;&lt;p&gt;Additional information:&lt;a href=&quot;http://news.cnet.com/8301-13577_3-10131251-36.html&quot;&gt; &lt;/a&gt;&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://news.cnet.com/8301-13577_3-10131251-36.html&quot;&gt;CNet&lt;/a&gt;&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.mediabistro.com/webnewser/personalities/rick_sanchez_twitter_hacked_104818.asp&quot;&gt;Media Bistro&lt;/a&gt;&lt;a href=&quot;http://news.cnet.com/8301-13577_3-10131251-36.html&quot;&gt;&lt;br /&gt;&lt;/a&gt;&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;USA&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Web 2.0&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA&lt;br&gt;&lt;b&gt;Attacked System Technology: &lt;/b&gt;Administration Tool&lt;br&gt;&lt;b&gt;Items Leaked: &lt;/b&gt;Password&lt;br&gt;&lt;b&gt;Number of Records: &lt;/b&gt;33</description>      <pubDate>Wed, 16 Jun 2010 14:23:05 -0400</pubDate>      <ddb:attackedentityfield>Web 2.0</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology>Administration Tool</ddb:attackedsystemtechnology>      <ddb:attacksourcegeography>USA</ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>January 5, 2009</ddb:dateoccured>      <ddb:entrytitle>WHID 2009-2: Twitter accounts of the famous hacked (Updated)</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;&lt;em&gt;&lt;strong&gt;Update (Jan 11&lt;sup&gt;th&lt;/sup&gt; 2009)&lt;/strong&gt;&lt;/em&gt; - The hacker &lt;a href=&quot;http://blog.wired.com/27bstroke6/2009/01/professed-twitt.html&quot;&gt;bragged &lt;/a&gt;about the hack and revealed that it was a brute force dictionary attack against an administrator account. Twitter does not block repetitive login failures therefore enabling brute force attacks. We are still leaving the incident classification &quot;insufficient authentication&quot; in addition to brute force as we feel an administration interface should have additional authentication mechanism and not just a password.&lt;/p&gt;&#13;&#10;&lt;hr /&gt;&#13;&#10;&lt;hr /&gt;&#13;&#10;&lt;p&gt;Twitter &lt;a href=&quot;http://blog.twitter.com/2009/01/monday-morning-madness.html&quot;&gt;announced &lt;/a&gt;that a hacker broke into 33 accounts including Obama's now inactive twitter. The hack is a result of a flaw in a web based support tool used by twitter, which where evidently accessible externally without proper authorization.&lt;/p&gt;&#13;&#10;&lt;p&gt;It is important to note that this incident is not related to &lt;a href=&quot;http://blog.twitter.com/2009/01/gone-phishing.html&quot;&gt;Twitter phishing attack&lt;/a&gt; which occurred on the previous weekend.&lt;/p&gt;&#13;&#10;&lt;p&gt;This incident highlights the issue of public facing administration interfaces, which often combine strong functionality with lesser attention to quality and therefore security. As organizations virtualize, those interfaces become available over the Internet, often without sufficient protection.&lt;/p&gt;&#13;&#10;&lt;p&gt;You can read some of the funny things that the hacker published in different twitters on &lt;a href=&quot;http://www.readwriteweb.com/archives/twitter_security_collapses_oba.php&quot;&gt;Read Write Web&lt;/a&gt;.&lt;/p&gt;&#13;&#10;&lt;p&gt;Additional information:&lt;a href=&quot;http://news.cnet.com/8301-13577_3-10131251-36.html&quot;&gt; &lt;/a&gt;&lt;/p&gt;&#13;&#10;&lt;ul&gt;&#13;&#10;&lt;li&gt;&lt;a href=&quot;http://news.cnet.com/8301-13577_3-10131251-36.html&quot;&gt;CNet&lt;/a&gt;&lt;/li&gt;&#13;&#10;&lt;li&gt;&lt;a href=&quot;http://www.mediabistro.com/webnewser/personalities/rick_sanchez_twitter_hacked_104818.asp&quot;&gt;Media Bistro&lt;/a&gt;&lt;a href=&quot;http://news.cnet.com/8301-13577_3-10131251-36.html&quot;&gt;&lt;br /&gt;&lt;/a&gt;&lt;/li&gt;&#13;&#10;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked>Password</ddb:itemsleaked>      <ddb:numberofrecords>33</ddb:numberofrecords>      <ddb:outcome>Defacement</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2009-2</ddb:whidid>    </item>    <item>      <title>WHID 2008-08: Hacker steals Davidson Cos. clients&amp;#039; data</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34747</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2008-08: Hacker steals Davidson Cos. clients&amp;#039; data&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2008-08&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;February 4, 2008&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;A computer hacker broke into the database of D.A. Davidson, a local Montana financial services firm and stole their entire customers' database: 226,000 records including names and social security numbers. Attack_Method is not known, but it seems very much like a web hack.&lt;/p&gt;&lt;br&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.greatfallstribune.com/apps/pbcs.dll/article?AID=/20080130/NEWS01/801300301&quot;&gt;Hacker steals Davidson Cos. clients' data&lt;/a&gt; [Great Falls Tribune, Feb 4 2008]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.davidsoncompanies.com/dc/pressreleases/pressreleasesdetail.cfm?newsid=1777378305&quot;&gt;Davidson Companies Informs Clients of Network Intrusion Resulting in Illegal Access to Personal Data&lt;/a&gt; [Davidson Companies, Jan 30 2008]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.greatfallstribune.com/apps/pbcs.dll/article?AID=/20080210/NEWS01/802100303&quot;&gt;Davidson Co.'s security breach reminds that personal data isn't as safe as we'd like&lt;/a&gt; [Great Falls Tribune, Feb 11 2008]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Finance&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA</description>      <pubDate>Wed, 16 Jun 2010 15:11:45 -0400</pubDate>      <ddb:attackedentityfield>Finance</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>February 4, 2008</ddb:dateoccured>      <ddb:entrytitle>WHID 2008-08: Hacker steals Davidson Cos. clients&amp;#039; data</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;A computer hacker broke into the database of D.A. Davidson, a local Montana financial services firm and stole their entire customers' database: 226,000 records including names and social security numbers. Attack_Method is not known, but it seems very much like a web hack.&lt;/p&gt;&#13;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.greatfallstribune.com/apps/pbcs.dll/article?AID=/20080130/NEWS01/801300301&quot;&gt;Hacker steals Davidson Cos. clients' data&lt;/a&gt; [Great Falls Tribune, Feb 4 2008]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.davidsoncompanies.com/dc/pressreleases/pressreleasesdetail.cfm?newsid=1777378305&quot;&gt;Davidson Companies Informs Clients of Network Intrusion Resulting in Illegal Access to Personal Data&lt;/a&gt; [Davidson Companies, Jan 30 2008]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.greatfallstribune.com/apps/pbcs.dll/article?AID=/20080210/NEWS01/802100303&quot;&gt;Davidson Co.'s security breach reminds that personal data isn't as safe as we'd like&lt;/a&gt; [Great Falls Tribune, Feb 11 2008]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2008-08</ddb:whidid>    </item>    <item>      <title>WHID 2009-35: Former US Senator Donors Information Leaks</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=35252</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2009-35: Former US Senator Donors Information Leaks&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2009-35&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;March 11, 2009&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Norm Coleman, a former senator from Minnesota, is going through a legal battle to try to win back his seat in the senate. If the way he manages his web site security and the crises it created are an indicator, I am not sure that he has a place there.&lt;/p&gt;&lt;br&gt;&lt;p&gt;The Coleman team &lt;a href=&quot;http://www.startribune.com/politics/state/41127537.html?elr=KArks8c7PaP3E77K_3c::D3aDhUec7PaP3E77K_0c::D3aDhUiD3aPc:_Yyc:aULPQL7PQLanchO7DiUr&quot;&gt;called in the US Secret Service&lt;/a&gt; to investigate the leak in which sensitive information about more than 4700 donors was published on Wikileaks, a web site devoted to such exposures. Coleman himself called the incident &quot;an obviously an attack on my campaign&quot;.&lt;/p&gt;&lt;br&gt;&lt;p&gt;However the Minnesota Independent &lt;a href=&quot;http://minnesotaindependent.com/28711/breaking-colemans-unsecured-donorbase-to-be-revealed-on-wikileaks&quot;&gt;reveals &lt;/a&gt;that the information was exposed for anyone to view on the senator's web site since at least January 28&lt;sup&gt;th&lt;/sup&gt;. Hardly an attack. At the time the site was suffering performance issues and in a debate about the cause somebody &lt;a href=&quot;http://minnesotaindependent.com/24761/disenfranchised-voters-crash-colemans-site-unlikely-says-blogger#comment-24131&quot;&gt;commented &lt;/a&gt;to an Independent about the an exposed database, which the Independent was fast to &lt;a href=&quot;http://minnesotaindependent.com/24817/crashgate-reveals-unprotected-database-on-colemans-site&quot;&gt;report &lt;/a&gt;on. Moreover, Wikileaks took the trouble to inform the people in the list that their information leaked, while it took the Senator team over a month to react.&lt;/p&gt;&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Politics&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA&lt;br&gt;&lt;b&gt;Number of Records: &lt;/b&gt;4,700&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://minnesotaindependent.com/28711/breaking-colemans-unsecured-donorbase-to-be-revealed-on-wikileaks&quot;&gt;http://minnesotaindependent.com/28711/breaking-colemans-unsecured-donorbase-to-be-revealed-on-wikileaks&lt;/a></description>      <pubDate>Wed, 16 Jun 2010 14:14:37 -0400</pubDate>      <ddb:attackedentityfield>Politics</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>March 11, 2009</ddb:dateoccured>      <ddb:entrytitle>WHID 2009-35: Former US Senator Donors Information Leaks</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Norm Coleman, a former senator from Minnesota, is going through a legal battle to try to win back his seat in the senate. If the way he manages his web site security and the crises it created are an indicator, I am not sure that he has a place there.&lt;/p&gt;&#13;&#10;&lt;p&gt;The Coleman team &lt;a href=&quot;http://www.startribune.com/politics/state/41127537.html?elr=KArks8c7PaP3E77K_3c::D3aDhUec7PaP3E77K_0c::D3aDhUiD3aPc:_Yyc:aULPQL7PQLanchO7DiUr&quot;&gt;called in the US Secret Service&lt;/a&gt; to investigate the leak in which sensitive information about more than 4700 donors was published on Wikileaks, a web site devoted to such exposures. Coleman himself called the incident &quot;an obviously an attack on my campaign&quot;.&lt;/p&gt;&#13;&#10;&lt;p&gt;However the Minnesota Independent &lt;a href=&quot;http://minnesotaindependent.com/28711/breaking-colemans-unsecured-donorbase-to-be-revealed-on-wikileaks&quot;&gt;reveals &lt;/a&gt;that the information was exposed for anyone to view on the senator's web site since at least January 28&lt;sup&gt;th&lt;/sup&gt;. Hardly an attack. At the time the site was suffering performance issues and in a debate about the cause somebody &lt;a href=&quot;http://minnesotaindependent.com/24761/disenfranchised-voters-crash-colemans-site-unlikely-says-blogger#comment-24131&quot;&gt;commented &lt;/a&gt;to an Independent about the an exposed database, which the Independent was fast to &lt;a href=&quot;http://minnesotaindependent.com/24817/crashgate-reveals-unprotected-database-on-colemans-site&quot;&gt;report &lt;/a&gt;on. Moreover, Wikileaks took the trouble to inform the people in the list that their information leaked, while it took the Senator team over a month to react.&lt;/p></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords>4,700</ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference>http://minnesotaindependent.com/28711/breaking-colemans-unsecured-donorbase-to-be-revealed-on-wikileaks</ddb:reference>      <ddb:whidid>2009-35</ddb:whidid>    </item>    <item>      <title>WHID 2008-09: Hacking Stage 6</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34752</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2008-09: Hacking Stage 6&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2008-09&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;February 10, 2008&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Sensitive information about people who created an account on the site leaked and was published through IRC.&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://en.wikipedia.org/wiki/Stage6#Hacking&quot;&gt;Stage 6 - Hacking&lt;/a&gt; [Wikipedia, Feb 9 2008]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Entertainment&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA</description>      <pubDate>Wed, 16 Jun 2010 15:11:17 -0400</pubDate>      <ddb:attackedentityfield>Entertainment</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>February 10, 2008</ddb:dateoccured>      <ddb:entrytitle>WHID 2008-09: Hacking Stage 6</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Sensitive information about people who created an account on the site leaked and was published through IRC.&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://en.wikipedia.org/wiki/Stage6#Hacking&quot;&gt;Stage 6 - Hacking&lt;/a&gt; [Wikipedia, Feb 9 2008]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2008-09</ddb:whidid>    </item>    <item>      <title>WHID 2009-34: Romanian Hacker Moves On To The Telegraph</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=35247</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2009-34: Romanian Hacker Moves On To The Telegraph&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2009-34&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;March 6, 2009&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Another week, another hack by the &lt;a href=&quot;http://www.hackersblog.org&quot;&gt;HackerBlog&lt;/a&gt;, and when it targets an important web site and the impact is severe it is worthy of WHID. This time the Romanian hacker &lt;a href=&quot;http://www.hackersblog.org/2009/03/06/telegraphcouk-hacked-sql-injection/&quot;&gt;used blind SQL injection to penetrate to the web site of the Telegraph&lt;/a&gt;, a leading English daily paper.&lt;/p&gt;&lt;br&gt;&lt;p&gt;Among his findings is a table including 700,000 e-mails, which would be a gold mine for spammers.&lt;/p&gt;&lt;br&gt;&lt;p&gt;The Telegraph &lt;a href=&quot;http://blogs.telegraph.co.uk/shane_richmond/blog/2009/03/09/hackersblog_and_telegraphcouk&quot;&gt;response&lt;/a&gt; was published on their official blog.&lt;/p&gt;&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;Romania&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Media&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;UK&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://www.hackersblog.org/2009/03/06/telegraphcouk-hacked-sql-injection/&quot;&gt;http://www.hackersblog.org/2009/03/06/telegraphcouk-hacked-sql-injection/&lt;/a></description>      <pubDate>Wed, 16 Jun 2010 14:14:40 -0400</pubDate>      <ddb:attackedentityfield>Media</ddb:attackedentityfield>      <ddb:attackedentitygeography>UK</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography>Romania</ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>March 6, 2009</ddb:dateoccured>      <ddb:entrytitle>WHID 2009-34: Romanian Hacker Moves On To The Telegraph</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Another week, another hack by the &lt;a href=&quot;http://www.hackersblog.org&quot;&gt;HackerBlog&lt;/a&gt;, and when it targets an important web site and the impact is severe it is worthy of WHID. This time the Romanian hacker &lt;a href=&quot;http://www.hackersblog.org/2009/03/06/telegraphcouk-hacked-sql-injection/&quot;&gt;used blind SQL injection to penetrate to the web site of the Telegraph&lt;/a&gt;, a leading English daily paper.&lt;/p&gt;&#13;&#10;&lt;p&gt;Among his findings is a table including 700,000 e-mails, which would be a gold mine for spammers.&lt;/p&gt;&#13;&#10;&lt;p&gt;The Telegraph &lt;a href=&quot;http://blogs.telegraph.co.uk/shane_richmond/blog/2009/03/09/hackersblog_and_telegraphcouk&quot;&gt;response&lt;/a&gt; was published on their official blog.&lt;/p></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference>http://www.hackersblog.org/2009/03/06/telegraphcouk-hacked-sql-injection/</ddb:reference>      <ddb:whidid>2009-34</ddb:whidid>    </item>    <item>      <title>WHID 2006-15: eBay contains a cross-site scripting vulnerability</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34095</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2006-15: eBay contains a cross-site scripting vulnerability&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2006-15&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;April 4, 2006&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Disclosure Only&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;eBay contains a cross-site scripting vulnerability. When an eBay user posts an auction, eBay allows SCRIPT tags to be included in the auction description which creates a cross-site scripting vulnerability in the eBay website&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://addict3d.org/index.php?page=viewarticle&amp;amp;type=security&amp;amp;ID=5986&amp;amp;title=eBay%20contains%20a%20cross-site%20scripting%20vulnerability&quot;&gt; eBay contains a cross-site scripting vulnerability&lt;/a&gt; [Addict3D, Apr 4 2006]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://news.com.com/Phishers+set+hidden+traps+on+eBay/2100-7349_3-6056687.html&quot;&gt;Phishers set hidden traps on eBay&lt;/a&gt; [CNet, Mar 31 2006]&lt;/li&gt;&lt;br&gt;&lt;/ul></description>      <pubDate>Wed, 16 Jun 2010 18:35:49 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>April 4, 2006</ddb:dateoccured>      <ddb:entrytitle>WHID 2006-15: eBay contains a cross-site scripting vulnerability</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;eBay contains a cross-site scripting vulnerability. When an eBay user posts an auction, eBay allows SCRIPT tags to be included in the auction description which creates a cross-site scripting vulnerability in the eBay website&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://addict3d.org/index.php?page=viewarticle&amp;amp;type=security&amp;amp;ID=5986&amp;amp;title=eBay%20contains%20a%20cross-site%20scripting%20vulnerability&quot;&gt; eBay contains a cross-site scripting vulnerability&lt;/a&gt; [Addict3D, Apr 4 2006]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://news.com.com/Phishers+set+hidden+traps+on+eBay/2100-7349_3-6056687.html&quot;&gt;Phishers set hidden traps on eBay&lt;/a&gt; [CNet, Mar 31 2006]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Disclosure Only</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2006-15</ddb:whidid>    </item>    <item>      <title>WHID 2007-84: Soccer league&amp;#039;s online shoppers get kicked by security breach</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34757</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2007-84: Soccer league&amp;#039;s online shoppers get kicked by security breach&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2007-84&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;February 10, 2008&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;It is already February, and we still add 2007 incidents. If&lt;br /&gt;you wonder why, it is because organizations such as MLS only now find&lt;br /&gt;out that they were hacked last year! Sometime between January and&lt;br /&gt;August of 2007, names, addresses, credit and debit card data, and&lt;br /&gt;passwords of an unknown number of people, including 169 New Hampshire&lt;br /&gt;residents were stolen from the site.&lt;/p&gt;&lt;br&gt;&lt;p&gt;Why New Hampshire? Because the company has to report to the&lt;br /&gt;authorities there about the incidents, but only specify the number of&lt;br /&gt;individuals from this state affected. Why only New Hampshire? Since&lt;br /&gt;regulations and bills requiring disclosures exist in many states, one&lt;br /&gt;would expect that the company would have to provide such a testimonial&lt;br /&gt;in many states. This incident is another good example of the size of&lt;br /&gt;the hidden part of the iceberg.&lt;/p&gt;&lt;br&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;taxonomyName=security&amp;amp;articleId=9061858&amp;amp;taxonomyId=17&amp;amp;intsrc=kc_top&quot;&gt;Soccer league's online shoppers get kicked by security breach&lt;/a&gt; [Computer World, Feb 8 2008]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://doj.nh.gov/consumer/pdf/MLSgear.pdf&quot;&gt;MLSgear.com Notification to NH DOJ&lt;/a&gt; [New Hampshire DOJ, Feb 1 2008]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Sports&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA</description>      <pubDate>Wed, 16 Jun 2010 15:20:31 -0400</pubDate>      <ddb:attackedentityfield>Sports</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>February 10, 2008</ddb:dateoccured>      <ddb:entrytitle>WHID 2007-84: Soccer league&amp;#039;s online shoppers get kicked by security breach</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;It is already February, and we still add 2007 incidents. If&lt;br /&gt;you wonder why, it is because organizations such as MLS only now find&lt;br /&gt;out that they were hacked last year! Sometime between January and&lt;br /&gt;August of 2007, names, addresses, credit and debit card data, and&lt;br /&gt;passwords of an unknown number of people, including 169 New Hampshire&lt;br /&gt;residents were stolen from the site.&lt;/p&gt;&#13;&lt;p&gt;Why New Hampshire? Because the company has to report to the&lt;br /&gt;authorities there about the incidents, but only specify the number of&lt;br /&gt;individuals from this state affected. Why only New Hampshire? Since&lt;br /&gt;regulations and bills requiring disclosures exist in many states, one&lt;br /&gt;would expect that the company would have to provide such a testimonial&lt;br /&gt;in many states. This incident is another good example of the size of&lt;br /&gt;the hidden part of the iceberg.&lt;/p&gt;&#13;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;taxonomyName=security&amp;amp;articleId=9061858&amp;amp;taxonomyId=17&amp;amp;intsrc=kc_top&quot;&gt;Soccer league's online shoppers get kicked by security breach&lt;/a&gt; [Computer World, Feb 8 2008]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://doj.nh.gov/consumer/pdf/MLSgear.pdf&quot;&gt;MLSgear.com Notification to NH DOJ&lt;/a&gt; [New Hampshire DOJ, Feb 1 2008]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2007-84</ddb:whidid>    </item>    <item>      <title>WHID 2008-45: Comcast domain hijacked</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34980</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2008-45: Comcast domain hijacked&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2008-45&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;January 5, 2009&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Defacement&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Recently the domain names has been the focus on hacking activity. Hackers found that hijacking a domain is as effective if not more than attacking the web site itself.&lt;/p&gt;&lt;br&gt;&lt;p&gt;Are domain hacking a case of web hacking? should they be included in WHID? in this case it seems, according to the &lt;a href=&quot;http://blog.wired.com/27bstroke6/2008/05/comcast-hijacke.html&quot;&gt;Wired report&lt;/a&gt; that the hack itself involved attacking the domains registrar's (Network Solutions) web interface.&lt;/p&gt;&lt;br&gt;&lt;p&gt;However, we believe that the resulting &quot;virtual&quot; defacement of the web site by redirecting users to a fraudulent web site is still a web hack, even if the DNS hijacking is not web related.&lt;/p&gt;&lt;br&gt;&lt;p&gt;The defaced site, as logged by &lt;a href=&quot;http://www.theregister.co.uk/2008/05/29/comcast_domain_hijacked/&quot;&gt;the register&lt;/a&gt; was:&lt;/p&gt;&lt;br&gt;&lt;p&gt;&lt;img src=&quot;http://regmedia.co.uk/2008/05/29/comcast.jpg&quot; width=&quot;450&quot; height=&quot;115&quot; /&gt;&lt;/p&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Internet&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA</description>      <pubDate>Wed, 16 Jun 2010 14:46:58 -0400</pubDate>      <ddb:attackedentityfield>Internet</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>January 5, 2009</ddb:dateoccured>      <ddb:entrytitle>WHID 2008-45: Comcast domain hijacked</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Recently the domain names has been the focus on hacking activity. Hackers found that hijacking a domain is as effective if not more than attacking the web site itself.&lt;/p&gt;&#13;&lt;p&gt;Are domain hacking a case of web hacking? should they be included in WHID? in this case it seems, according to the &lt;a href=&quot;http://blog.wired.com/27bstroke6/2008/05/comcast-hijacke.html&quot;&gt;Wired report&lt;/a&gt; that the hack itself involved attacking the domains registrar's (Network Solutions) web interface.&lt;/p&gt;&#13;&lt;p&gt;However, we believe that the resulting &quot;virtual&quot; defacement of the web site by redirecting users to a fraudulent web site is still a web hack, even if the DNS hijacking is not web related.&lt;/p&gt;&#13;&lt;p&gt;The defaced site, as logged by &lt;a href=&quot;http://www.theregister.co.uk/2008/05/29/comcast_domain_hijacked/&quot;&gt;the register&lt;/a&gt; was:&lt;/p&gt;&#13;&lt;p&gt;&lt;img src=&quot;http://regmedia.co.uk/2008/05/29/comcast.jpg&quot; width=&quot;450&quot; height=&quot;115&quot; /&gt;&lt;/p></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Defacement</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2008-45</ddb:whidid>    </item>    <item>      <title>WHID 2008-10: Chinese hacker steals user information on 18 Million online shoppers at Auction.co.kr</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34762</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2008-10: Chinese hacker steals user information on 18 Million online shoppers at Auction.co.kr&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2008-10&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;February 12, 2008&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;&lt;strong&gt;&lt;em&gt;Update (January 5th 2009)&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt;&lt;br&gt;&lt;p&gt;We where informed by sources at eBay the Korean sites parent company that the issue was not CRSF or seesion hijacking. The Attack_Method was not disclosed.&lt;/p&gt;&lt;br&gt;&lt;hr /&gt;&lt;br&gt;&lt;p&gt;A Korean e-commerce site was hacked and a staggering number of record, 18 million, where stolen. In the US this would be front news. We don't know if it was front news in Korea, but did not get to the international media.&lt;/p&gt;&lt;br&gt;&lt;p&gt;The attack description is vague but can be best described as session hijacking.&lt;/p&gt;&lt;br&gt;&lt;p&gt;This incident is a great example of the lack of sufficient international coverage at WHID. Help us by sending us non English incidents! After all, it is not English speakers only that get hacked, but rather us, the WHID maintainers that speak only this language.&lt;/p&gt;&lt;br&gt;&lt;p&gt;More Information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.thedarkvisitor.com/tag/auctioncokr-chinese-hacker-attack/&quot;&gt;The Dark Visitor&lt;/a&gt;&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Retail&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;Korea</description>      <pubDate>Wed, 16 Jun 2010 15:10:51 -0400</pubDate>      <ddb:attackedentityfield>Retail</ddb:attackedentityfield>      <ddb:attackedentitygeography>Korea</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>February 12, 2008</ddb:dateoccured>      <ddb:entrytitle>WHID 2008-10: Chinese hacker steals user information on 18 Million online shoppers at Auction.co.kr</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;&lt;strong&gt;&lt;em&gt;Update (January 5th 2009)&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt;&#13;&lt;p&gt;We where informed by sources at eBay the Korean sites parent company that the issue was not CRSF or seesion hijacking. The Attack_Method was not disclosed.&lt;/p&gt;&#13;&lt;hr /&gt;&#13;&lt;p&gt;A Korean e-commerce site was hacked and a staggering number of record, 18 million, where stolen. In the US this would be front news. We don't know if it was front news in Korea, but did not get to the international media.&lt;/p&gt;&#13;&lt;p&gt;The attack description is vague but can be best described as session hijacking.&lt;/p&gt;&#13;&lt;p&gt;This incident is a great example of the lack of sufficient international coverage at WHID. Help us by sending us non English incidents! After all, it is not English speakers only that get hacked, but rather us, the WHID maintainers that speak only this language.&lt;/p&gt;&#13;&lt;p&gt;More Information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.thedarkvisitor.com/tag/auctioncokr-chinese-hacker-attack/&quot;&gt;The Dark Visitor&lt;/a&gt;&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2008-10</ddb:whidid>    </item>    <item>      <title>WHID 2009-33: eBay Fraud Abuses Zero Day XSS</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=35241</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2009-33: eBay Fraud Abuses Zero Day XSS&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2009-33&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;March 4, 2009&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Monetary Loss&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;A zero day XSS vector enables hackers to include in an eBay offer an arbitrary code which is executed by both FireFox and IE. As a result they were able to spoof the content of the offer, so that the user saw different information than the details known to eBay.&lt;/p&gt;&lt;br&gt;&lt;p&gt;A very detailed technical explanation of the vulnerability is included in a &lt;a href=&quot;https://bugzilla.mozilla.org/show_bug.cgi?id=481558&quot;&gt;FireFox community discussions&lt;/a&gt; on whether the issue is a browser or a web site issue. As usual, the truth is somewhere in the middle. The FireFox team selected to correct the issue discovered in FireFox. Microsoft claimed that the issue exploited in IE, which is &lt;a href=&quot;http://www.theregister.co.uk/2009/03/08/ebay_scam_wizardy/&quot;&gt;reported &lt;/a&gt;to be a CSS expression issue, is not feature and not a bug and the vulnerable web site should be fixed.&lt;/p&gt;&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Retail&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;https://bugzilla.mozilla.org/show_bug.cgi?id=481558&quot;&gt;https://bugzilla.mozilla.org/show_bug.cgi?id=481558&lt;/a></description>      <pubDate>Wed, 16 Jun 2010 14:14:46 -0400</pubDate>      <ddb:attackedentityfield>Retail</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>March 4, 2009</ddb:dateoccured>      <ddb:entrytitle>WHID 2009-33: eBay Fraud Abuses Zero Day XSS</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;A zero day XSS vector enables hackers to include in an eBay offer an arbitrary code which is executed by both FireFox and IE. As a result they were able to spoof the content of the offer, so that the user saw different information than the details known to eBay.&lt;/p&gt;&#13;&#10;&lt;p&gt;A very detailed technical explanation of the vulnerability is included in a &lt;a href=&quot;https://bugzilla.mozilla.org/show_bug.cgi?id=481558&quot;&gt;FireFox community discussions&lt;/a&gt; on whether the issue is a browser or a web site issue. As usual, the truth is somewhere in the middle. The FireFox team selected to correct the issue discovered in FireFox. Microsoft claimed that the issue exploited in IE, which is &lt;a href=&quot;http://www.theregister.co.uk/2009/03/08/ebay_scam_wizardy/&quot;&gt;reported &lt;/a&gt;to be a CSS expression issue, is not feature and not a bug and the vulnerable web site should be fixed.&lt;/p></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Monetary Loss</ddb:outcome>      <ddb:reference>https://bugzilla.mozilla.org/show_bug.cgi?id=481558</ddb:reference>      <ddb:whidid>2009-33</ddb:whidid>    </item>    <item>      <title>WHID 2008-11: Hacker breaks into Ecuador&amp;#039;s presidential website</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34768</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2008-11: Hacker breaks into Ecuador&amp;#039;s presidential website&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2008-11&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;February 12, 2008&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Defacement&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Was it defaced or not? In this extraordinary incident, a hacker broke to the web site of the Ecuadorian president and said nice things about him. So nice in fact that the presidential office had to apologize in front of the opposition leader. Was it a hack or an over enthusiastic marketing person?&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.thaindian.com/newsportal/uncategorized/hacker-breaks-into-ecuadors-presidential-website_10017070.html&quot;&gt;Hacker breaks into Ecuador's presidential website&lt;/a&gt; [Thaindian News, Feb 11 2008]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Government&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;Ecuador</description>      <pubDate>Wed, 16 Jun 2010 15:09:41 -0400</pubDate>      <ddb:attackedentityfield>Government</ddb:attackedentityfield>      <ddb:attackedentitygeography>Ecuador</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>February 12, 2008</ddb:dateoccured>      <ddb:entrytitle>WHID 2008-11: Hacker breaks into Ecuador&amp;#039;s presidential website</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Was it defaced or not? In this extraordinary incident, a hacker broke to the web site of the Ecuadorian president and said nice things about him. So nice in fact that the presidential office had to apologize in front of the opposition leader. Was it a hack or an over enthusiastic marketing person?&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.thaindian.com/newsportal/uncategorized/hacker-breaks-into-ecuadors-presidential-website_10017070.html&quot;&gt;Hacker breaks into Ecuador's presidential website&lt;/a&gt; [Thaindian News, Feb 11 2008]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Defacement</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2008-11</ddb:whidid>    </item>    <item>      <title>WHID 2008-44: Balkan cyber wars</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34969</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2008-44: Balkan cyber wars&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2008-44&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;April 1, 2008&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Downtime&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;The interesting &lt;a href=&quot;http://blogs.zdnet.com/security/?p=1145&quot;&gt;report &lt;/a&gt;in ZDnet about the cyber war around Kosovo is unique in describing the process. According to the report hacker groups on each side share information in order to make attacks more efficient. Some collect vulnerable web sites, while others use automatic defacement tools to attack.&lt;/p&gt;&lt;br&gt;&lt;p&gt;On the positive side, the report states that at the time of writing, there is a ceasefire and parties are negotiating. Is there room for cyber peace along side cyber war?&lt;/p&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Various</description>      <pubDate>Wed, 16 Jun 2010 14:47:48 -0400</pubDate>      <ddb:attackedentityfield>Various</ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>April 1, 2008</ddb:dateoccured>      <ddb:entrytitle>WHID 2008-44: Balkan cyber wars</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;The interesting &lt;a href=&quot;http://blogs.zdnet.com/security/?p=1145&quot;&gt;report &lt;/a&gt;in ZDnet about the cyber war around Kosovo is unique in describing the process. According to the report hacker groups on each side share information in order to make attacks more efficient. Some collect vulnerable web sites, while others use automatic defacement tools to attack.&lt;/p&gt;&#13;&lt;p&gt;On the positive side, the report states that at the time of writing, there is a ceasefire and parties are negotiating. Is there room for cyber peace along side cyber war?&lt;/p></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Downtime</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2008-44</ddb:whidid>    </item>    <item>      <title>WHID 2008-60: Miley Cyrus Pictures Leaked Due to a Web Hack (Updated)</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=35235</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2008-60: Miley Cyrus Pictures Leaked Due to a Web Hack (Updated)&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2008-60&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;October 20, 2008&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;&lt;span&gt;&lt;em&gt;&lt;strong&gt;Update (April 19th 2009)&lt;/strong&gt;&lt;/em&gt; - E!News &lt;a href=&quot;Update (April 19th 2009) - E!News provides additional interesting details about Josh Holly, the hacker who carried out the attack. They actually took the trouble to go to Holly's hometown and and ask people about him,providing an interesting insight into the celebs hacking phenomena. &quot;&gt;provides additional interesting&lt;/a&gt; details about Josh Holly, the hacker who carried out the attack. They actually took the trouble to go to Holly's hometown and and ask people about him,providing an interesting insight into the celebs hacking phenomena. &lt;/span&gt;&lt;/p&gt;&lt;br&gt;&lt;hr /&gt;&lt;br&gt;&lt;p&gt;Celebs are fast becoming a prime hacking target. Miley Cyrus already made her debut at WHID when her Twitter account was raided. But it seems that this was not her first cyber incident for her. As &lt;a href=&quot;http://blog.wired.com/27bstroke6/2008/10/miley-cyrus-hac.html&quot;&gt;reported by Wired&lt;/a&gt;, late last year a hacker named  Josh Holly published private photos of Ms. Cyrus stolen from her G-mail account.&lt;/p&gt;&lt;br&gt;&lt;p&gt;The hack was a relatively sophisticated one and a very good example of the risks of Web 2.0. Holly penetrated a MySpace administrator using social engineering. Using the account he gained access to a list of passwords which MySpace stored in an unencrypted form. Unbelievable. Since most of us use the same password for multiple services, Holly used Cyrus' MySpace password on her G-mail account gaining access and retrieving the photographs.&lt;/p&gt;&lt;br&gt;&lt;p&gt;In a related but yet unconfirmed story Holly claims to have used the MySpace administrative account for an advertising scam by which he gained $50,000.&lt;/p&gt;&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Web 2.0&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b></description>      <pubDate>Wed, 16 Jun 2010 14:27:32 -0400</pubDate>      <ddb:attackedentityfield>Web 2.0</ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>October 20, 2008</ddb:dateoccured>      <ddb:entrytitle>WHID 2008-60: Miley Cyrus Pictures Leaked Due to a Web Hack (Updated)</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;&lt;span&gt;&lt;em&gt;&lt;strong&gt;Update (April 19th 2009)&lt;/strong&gt;&lt;/em&gt; - E!News &lt;a href=&quot;Update (April 19th 2009) - E!News provides additional interesting details about Josh Holly, the hacker who carried out the attack. They actually took the trouble to go to Holly's hometown and and ask people about him,providing an interesting insight into the celebs hacking phenomena. &quot;&gt;provides additional interesting&lt;/a&gt; details about Josh Holly, the hacker who carried out the attack. They actually took the trouble to go to Holly's hometown and and ask people about him,providing an interesting insight into the celebs hacking phenomena. &lt;/span&gt;&lt;/p&gt;&#13;&#10;&lt;hr /&gt;&#13;&#10;&lt;p&gt;Celebs are fast becoming a prime hacking target. Miley Cyrus already made her debut at WHID when her Twitter account was raided. But it seems that this was not her first cyber incident for her. As &lt;a href=&quot;http://blog.wired.com/27bstroke6/2008/10/miley-cyrus-hac.html&quot;&gt;reported by Wired&lt;/a&gt;, late last year a hacker named  Josh Holly published private photos of Ms. Cyrus stolen from her G-mail account.&lt;/p&gt;&#13;&#10;&lt;p&gt;The hack was a relatively sophisticated one and a very good example of the risks of Web 2.0. Holly penetrated a MySpace administrator using social engineering. Using the account he gained access to a list of passwords which MySpace stored in an unencrypted form. Unbelievable. Since most of us use the same password for multiple services, Holly used Cyrus' MySpace password on her G-mail account gaining access and retrieving the photographs.&lt;/p&gt;&#13;&#10;&lt;p&gt;In a related but yet unconfirmed story Holly claims to have used the MySpace administrative account for an advertising scam by which he gained $50,000.&lt;/p></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2008-60</ddb:whidid>    </item>    <item>      <title>WHID 2008-12: Greek ministry websites hit by hacker intrusion</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34773</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2008-12: Greek ministry websites hit by hacker intrusion&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2008-12&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;February 17, 2008&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Defacement&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;This is yet another case of defacement of a governmental web site. It is amazing to note it is nearly never the large commercial and financial web sites that are defaced. It is either small mom and dad shops or government and political web sites. Don't you get the feeling the government IT is run like a mom and dad shop? Do you wonder if it is only the IT part that is run that way?&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.ekathimerini.com/4dcgi/_w_articles_politics_100018_31/01/2008_92784&quot;&gt;Ministry websites hit by hacker intrusion&lt;/a&gt; [Kathimerini, Jan 31 2008]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Government&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;Greece</description>      <pubDate>Wed, 16 Jun 2010 15:09:02 -0400</pubDate>      <ddb:attackedentityfield>Government</ddb:attackedentityfield>      <ddb:attackedentitygeography>Greece</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>February 17, 2008</ddb:dateoccured>      <ddb:entrytitle>WHID 2008-12: Greek ministry websites hit by hacker intrusion</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;This is yet another case of defacement of a governmental web site. It is amazing to note it is nearly never the large commercial and financial web sites that are defaced. It is either small mom and dad shops or government and political web sites. Don't you get the feeling the government IT is run like a mom and dad shop? Do you wonder if it is only the IT part that is run that way?&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.ekathimerini.com/4dcgi/_w_articles_politics_100018_31/01/2008_92784&quot;&gt;Ministry websites hit by hacker intrusion&lt;/a&gt; [Kathimerini, Jan 31 2008]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Defacement</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2008-12</ddb:whidid>    </item>    <item>      <title>WHID 2008-43: Russian nuclear power web sites attacked amid accident rumors</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34964</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2008-43: Russian nuclear power web sites attacked amid accident rumors&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2008-43&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;January 5, 2009&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Novosti, the Russian news agency &lt;a href=&quot;http://en.rian.ru/russia/20080523/108202288.html&quot;&gt;reports &lt;/a&gt;that in what seems to be a planned dual head attack to break panic by spreading a rumor about a nuclear accident near St. Petersburg.&lt;/p&gt;&lt;br&gt;&lt;p&gt;At the same time that e-mails spreading the rumor where distributed,   hackers blocked access to web sites enabling the public to check for themselves the status of the nuclear power pland intensifying the panic.&lt;/p&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Government&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;Russia</description>      <pubDate>Mon, 24 May 2010 13:54:42 -0400</pubDate>      <ddb:attackedentityfield>Government</ddb:attackedentityfield>      <ddb:attackedentitygeography>Russia</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>January 5, 2009</ddb:dateoccured>      <ddb:entrytitle>WHID 2008-43: Russian nuclear power web sites attacked amid accident rumors</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Novosti, the Russian news agency &lt;a href=&quot;http://en.rian.ru/russia/20080523/108202288.html&quot;&gt;reports &lt;/a&gt;that in what seems to be a planned dual head attack to break panic by spreading a rumor about a nuclear accident near St. Petersburg.&lt;/p&gt;&#13;&lt;p&gt;At the same time that e-mails spreading the rumor where distributed,   hackers blocked access to web sites enabling the public to check for themselves the status of the nuclear power pland intensifying the panic.&lt;/p></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome></ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2008-43</ddb:whidid>    </item>    <item>      <title>WHID 2006-14: Forgotten password clues create hacker risk</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34080</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2006-14: Forgotten password clues create hacker risk&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2006-14&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;April 4, 2006&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Disclosure Only&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;A UK Security Consulting firm reports that 54 UK sites that it has surveyed have flaws in the &quot;forgotten password&quot; feature.&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.theregister.co.uk/2006/03/20/forgotten_password_security_risk/&quot;&gt;Forgotten password clues create hacker risk&lt;/a&gt; [The Register, Mar 20 2006]&lt;/li&gt;&lt;br&gt;&lt;/ul></description>      <pubDate>Wed, 16 Jun 2010 18:36:52 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>April 4, 2006</ddb:dateoccured>      <ddb:entrytitle>WHID 2006-14: Forgotten password clues create hacker risk</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;A UK Security Consulting firm reports that 54 UK sites that it has surveyed have flaws in the &quot;forgotten password&quot; feature.&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.theregister.co.uk/2006/03/20/forgotten_password_security_risk/&quot;&gt;Forgotten password clues create hacker risk&lt;/a&gt; [The Register, Mar 20 2006]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Disclosure Only</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2006-14</ddb:whidid>    </item>    <item>      <title>WHID 2007-85: IndiaTimes.com Visitors Risk High Exposure To Malware</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34778</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2007-85: IndiaTimes.com Visitors Risk High Exposure To Malware&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2007-85&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;February 17, 2008&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Planting of Malware&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;The web site of a leading Indian newspaper is swamped with malware. A recent &lt;a href=&quot;http://www.theregister.co.uk/2008/01/23/embassy_sites_serve_malware/&quot;&gt;survey by WebSense&lt;/a&gt; cites by the Register found that of the sites hosing malware, 51% where legitimate sites that have been broken into. This is a major shift in the threat landscape, since keeping to web sites that you know is no longer a good protection strategy. Anecdotally undermining WebSense own web site classification technology as a security solution.&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.informationweek.com/news/showArticle.jhtml?articleID=202804433&quot;&gt;IndiaTimes.com Visitors Risk High Exposure To Malware&lt;/a&gt; [Information Week, Nov 9 2007]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Media&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;India</description>      <pubDate>Wed, 16 Jun 2010 15:19:24 -0400</pubDate>      <ddb:attackedentityfield>Media</ddb:attackedentityfield>      <ddb:attackedentitygeography>India</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>February 17, 2008</ddb:dateoccured>      <ddb:entrytitle>WHID 2007-85: IndiaTimes.com Visitors Risk High Exposure To Malware</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;The web site of a leading Indian newspaper is swamped with malware. A recent &lt;a href=&quot;http://www.theregister.co.uk/2008/01/23/embassy_sites_serve_malware/&quot;&gt;survey by WebSense&lt;/a&gt; cites by the Register found that of the sites hosing malware, 51% where legitimate sites that have been broken into. This is a major shift in the threat landscape, since keeping to web sites that you know is no longer a good protection strategy. Anecdotally undermining WebSense own web site classification technology as a security solution.&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.informationweek.com/news/showArticle.jhtml?articleID=202804433&quot;&gt;IndiaTimes.com Visitors Risk High Exposure To Malware&lt;/a&gt; [Information Week, Nov 9 2007]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Planting of Malware</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2007-85</ddb:whidid>    </item>    <item>      <title>WHID 2009-32: 750 Twitter Accounts Hacked</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=35229</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2009-32: 750 Twitter Accounts Hacked&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2009-32&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;March 10, 2009&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Link Spam&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Twitter reports in a &lt;a href=&quot;http://blog.twitter.com/2009/03/safekeeping-twitter-accounts.html&quot;&gt;blog entry&lt;/a&gt; that 750 accounts were hacked. The hacker posted messages linking to a porn webcam. While Twitter did not disclose how the attack was carried out, the suggested remediation hints that the account passwords were guessed, probably using a brute force attack.&lt;/p&gt;&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Web 2.0&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA&lt;br&gt;&lt;b&gt;Items Leaked: &lt;/b&gt;Password&lt;br&gt;&lt;b&gt;Number of Records: &lt;/b&gt;750</description>      <pubDate>Wed, 16 Jun 2010 14:14:50 -0400</pubDate>      <ddb:attackedentityfield>Web 2.0</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>March 10, 2009</ddb:dateoccured>      <ddb:entrytitle>WHID 2009-32: 750 Twitter Accounts Hacked</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Twitter reports in a &lt;a href=&quot;http://blog.twitter.com/2009/03/safekeeping-twitter-accounts.html&quot;&gt;blog entry&lt;/a&gt; that 750 accounts were hacked. The hacker posted messages linking to a porn webcam. While Twitter did not disclose how the attack was carried out, the suggested remediation hints that the account passwords were guessed, probably using a brute force attack.&lt;/p></ddb:incidentdescription>      <ddb:itemsleaked>Password</ddb:itemsleaked>      <ddb:numberofrecords>750</ddb:numberofrecords>      <ddb:outcome>Link Spam</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2009-32</ddb:whidid>    </item>    <item>      <title>WHID 2008-54: Hacker Redirects Obama&amp;#039;s site to Hillary Clinton&amp;#039;s</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=35061</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2008-54: Hacker Redirects Obama&amp;#039;s site to Hillary Clinton&amp;#039;s&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2008-54&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;April 18, 2008&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Defacement&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Netcraft &lt;a href=&quot;http://news.netcraft.com/archives/2008/04/21/hacker_redirects_barack_obamas_site_to_hillaryclintoncom.html&quot;&gt;reports &lt;/a&gt;that a hacker managed to redirect traffic from Barak Obama's web site to Hillary Clinton's site during the primaries held between the two.The culprit, an XSS bug in the Obama's site community blogs section, highlights the danger of user contributed content to web sites.&lt;/p&gt;&lt;br&gt;&lt;p&gt;An interesting side story is that Oliver Friedrichs from Symantec was &lt;a href=&quot;http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;articleId=9077198&quot;&gt;quoted in a Computer World article&lt;/a&gt; only a week earlier saying that presidential campaign web sites are &quot;clueless&quot; about security. Was this a prophecy of or the trigger for the hack?&lt;/p&gt;&lt;br&gt;&lt;p&gt;Additional technical information can be found on &lt;a href=&quot;http://xssed.com/news/65/Barack_Obamas_official_site_hacked/&quot;&gt;XSSed&lt;/a&gt;.&lt;/p&gt;&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Government&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA</description>      <pubDate>Wed, 16 Jun 2010 14:37:04 -0400</pubDate>      <ddb:attackedentityfield>Government</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>April 18, 2008</ddb:dateoccured>      <ddb:entrytitle>WHID 2008-54: Hacker Redirects Obama&amp;#039;s site to Hillary Clinton&amp;#039;s</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Netcraft &lt;a href=&quot;http://news.netcraft.com/archives/2008/04/21/hacker_redirects_barack_obamas_site_to_hillaryclintoncom.html&quot;&gt;reports &lt;/a&gt;that a hacker managed to redirect traffic from Barak Obama's web site to Hillary Clinton's site during the primaries held between the two.The culprit, an XSS bug in the Obama's site community blogs section, highlights the danger of user contributed content to web sites.&lt;/p&gt;&#13;&#10;&lt;p&gt;An interesting side story is that Oliver Friedrichs from Symantec was &lt;a href=&quot;http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;articleId=9077198&quot;&gt;quoted in a Computer World article&lt;/a&gt; only a week earlier saying that presidential campaign web sites are &quot;clueless&quot; about security. Was this a prophecy of or the trigger for the hack?&lt;/p&gt;&#13;&#10;&lt;p&gt;Additional technical information can be found on &lt;a href=&quot;http://xssed.com/news/65/Barack_Obamas_official_site_hacked/&quot;&gt;XSSed&lt;/a&gt;.&lt;/p></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Defacement</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2008-54</ddb:whidid>    </item>    <item>      <title>WHID 2008-59: Spotify Streaming Music Service Hacked and Millions of Records Leaked</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=35224</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2008-59: Spotify Streaming Music Service Hacked and Millions of Records Leaked&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2008-59&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;December 19, 2008&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;This time we may need to remove the word &quot;web&quot; leaving this &lt;a href=&quot;http://www.spotify.com/blog/archives/2009/03/04/spotify-security-notice/&quot;&gt;incident&lt;/a&gt; classified only as &quot;application security&quot;. Spotify is a new music streaming radio like service from Sweden. A weakness in &lt;a href=&quot;http://www.spotify.com&quot;&gt;Spotify &lt;/a&gt;streaming protocols enables hackers to gain access to users' encrypted passwords, email address, birth date, gender, postal code and billing receipt.&lt;/p&gt;&lt;br&gt;&lt;p&gt;An interesting aspect of this incident is that while the vulnerability has been discovered and fix on December 19&lt;sup&gt;th&lt;/sup&gt;, the fact that it was actually exploited was discovered only in March 2009. Many times companies report that a vulnerability was found on there site, but they are not aware of any exploit of the vulnerability. As this incident shows, even if the company is not aware, there is a chance that the vulnerability was exploited.&lt;/p&gt;&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Media&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;Sweden</description>      <pubDate>Wed, 16 Jun 2010 14:29:17 -0400</pubDate>      <ddb:attackedentityfield>Media</ddb:attackedentityfield>      <ddb:attackedentitygeography>Sweden</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>December 19, 2008</ddb:dateoccured>      <ddb:entrytitle>WHID 2008-59: Spotify Streaming Music Service Hacked and Millions of Records Leaked</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;This time we may need to remove the word &quot;web&quot; leaving this &lt;a href=&quot;http://www.spotify.com/blog/archives/2009/03/04/spotify-security-notice/&quot;&gt;incident&lt;/a&gt; classified only as &quot;application security&quot;. Spotify is a new music streaming radio like service from Sweden. A weakness in &lt;a href=&quot;http://www.spotify.com&quot;&gt;Spotify &lt;/a&gt;streaming protocols enables hackers to gain access to users' encrypted passwords, email address, birth date, gender, postal code and billing receipt.&lt;/p&gt;&#13;&#10;&lt;p&gt;An interesting aspect of this incident is that while the vulnerability has been discovered and fix on December 19&lt;sup&gt;th&lt;/sup&gt;, the fact that it was actually exploited was discovered only in March 2009. Many times companies report that a vulnerability was found on there site, but they are not aware of any exploit of the vulnerability. As this incident shows, even if the company is not aware, there is a chance that the vulnerability was exploited.&lt;/p></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2008-59</ddb:whidid>    </item>    <item>      <title>WHID 2009-31: Double Clickjacking Worm on Twitter</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=35218</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2009-31: Double Clickjacking Worm on Twitter&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2009-31&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;February 12, 2009&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Defacement&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Twitter is certainly bypassing Facebook as the most popular site out there, at least when it comes to security incidents.This time somebody decided abuse Twitter to demonstrate &lt;a href=&quot;http://www.sectheory.com/clickjacking.htm&quot;&gt;Clickjacking&lt;/a&gt;, an attack that RSname and Jeremiah Grossman re-christened in the OWASP conference in New York in September.&lt;/p&gt;&lt;br&gt;&lt;p&gt;A well placed button labeled &quot;don't click&quot; make people click on it actually sending a Twitter message. Sunlight labs have a very interesting &lt;a href=&quot;http://sunlightlabs.com/blog/2009/02/12/what-dont-click-business/&quot;&gt;report&lt;/a&gt; showing the rate of propagation of the worm.&lt;/p&gt;&lt;br&gt;&lt;p&gt;Cnet &lt;a href=&quot;http://news.cnet.com/8301-1009_3-10162812-83.html&quot;&gt;reports &lt;/a&gt;the worm spread on Feb 12&lt;sup&gt;th&lt;/sup&gt; in two pulses. After the Twitter people closed the loophole the 1st time, somebody &lt;a href=&quot;http://news.cnet.com/8301-1009_3-10163790-83.html&quot;&gt;bypassed the patch&lt;/a&gt; to restart the worm spread out.&lt;/p&gt;&lt;br&gt;&lt;p&gt;Chriss Shiflett provides a very good&lt;a href=&quot;http://shiflett.org/blog/2009/feb/twitter-dont-click-exploit&quot;&gt; technical analysis&lt;/a&gt; of the worm.&lt;/p&gt;&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Web 2.0&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;US</description>      <pubDate>Wed, 16 Jun 2010 14:15:07 -0400</pubDate>      <ddb:attackedentityfield>Web 2.0</ddb:attackedentityfield>      <ddb:attackedentitygeography>US</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>February 12, 2009</ddb:dateoccured>      <ddb:entrytitle>WHID 2009-31: Double Clickjacking Worm on Twitter</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Twitter is certainly bypassing Facebook as the most popular site out there, at least when it comes to security incidents.This time somebody decided abuse Twitter to demonstrate &lt;a href=&quot;http://www.sectheory.com/clickjacking.htm&quot;&gt;Clickjacking&lt;/a&gt;, an attack that RSname and Jeremiah Grossman re-christened in the OWASP conference in New York in September.&lt;/p&gt;&#13;&#10;&lt;p&gt;A well placed button labeled &quot;don't click&quot; make people click on it actually sending a Twitter message. Sunlight labs have a very interesting &lt;a href=&quot;http://sunlightlabs.com/blog/2009/02/12/what-dont-click-business/&quot;&gt;report&lt;/a&gt; showing the rate of propagation of the worm.&lt;/p&gt;&#13;&#10;&lt;p&gt;Cnet &lt;a href=&quot;http://news.cnet.com/8301-1009_3-10162812-83.html&quot;&gt;reports &lt;/a&gt;the worm spread on Feb 12&lt;sup&gt;th&lt;/sup&gt; in two pulses. After the Twitter people closed the loophole the 1st time, somebody &lt;a href=&quot;http://news.cnet.com/8301-1009_3-10163790-83.html&quot;&gt;bypassed the patch&lt;/a&gt; to restart the worm spread out.&lt;/p&gt;&#13;&#10;&lt;p&gt;Chriss Shiflett provides a very good&lt;a href=&quot;http://shiflett.org/blog/2009/feb/twitter-dont-click-exploit&quot;&gt; technical analysis&lt;/a&gt; of the worm.&lt;/p></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Defacement</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2009-31</ddb:whidid>    </item>    <item>      <title>WHID 2007-86: Mac Blogs defaced using XSS</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34788</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2007-86: Mac Blogs defaced using XSS&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2007-86&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;February 17, 2008&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Defacement&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;The standard disclaimer that we do not cover each and every defacement is relevant to this entry as well. So why do we include the defacement incident this time? First and foremost, it is known to be an XSS abusing a WordPress zero day bug. Secondly, it is a targeted attack aiming to deface only Mac related web sites. Usually targeted defacement attacks are carried out against political targets. Did attacking apple become a political issue? Was Apple transformed into a nation overnight? Well certainly into a cult.&lt;/p&gt;&lt;br&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://xssworm.blogvis.com/27/xssworm/mac-sites-are-being-hacked-by-blackhat-xss-hackers/&quot;&gt;Mac sites are being hacked by blackhat XSS hackers&lt;/a&gt; [XSSworm, Nov 23 2007]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.theregister.co.uk/2007/11/27/mac_site_defacer/&quot;&gt;Hacker defaces temples to OS X&lt;/a&gt; [The Register, Nov 27 2007]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Technology&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;Global&lt;br&gt;&lt;b&gt;Attacked System Technology: &lt;/b&gt;WordPress</description>      <pubDate>Wed, 16 Jun 2010 15:19:06 -0400</pubDate>      <ddb:attackedentityfield>Technology</ddb:attackedentityfield>      <ddb:attackedentitygeography>Global</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology>WordPress</ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>February 17, 2008</ddb:dateoccured>      <ddb:entrytitle>WHID 2007-86: Mac Blogs defaced using XSS</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;The standard disclaimer that we do not cover each and every defacement is relevant to this entry as well. So why do we include the defacement incident this time? First and foremost, it is known to be an XSS abusing a WordPress zero day bug. Secondly, it is a targeted attack aiming to deface only Mac related web sites. Usually targeted defacement attacks are carried out against political targets. Did attacking apple become a political issue? Was Apple transformed into a nation overnight? Well certainly into a cult.&lt;/p&gt;&#13;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://xssworm.blogvis.com/27/xssworm/mac-sites-are-being-hacked-by-blackhat-xss-hackers/&quot;&gt;Mac sites are being hacked by blackhat XSS hackers&lt;/a&gt; [XSSworm, Nov 23 2007]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.theregister.co.uk/2007/11/27/mac_site_defacer/&quot;&gt;Hacker defaces temples to OS X&lt;/a&gt; [The Register, Nov 27 2007]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Defacement</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2007-86</ddb:whidid>    </item>    <item>      <title>WHID 2008-55: Hackers hijack bitchy fashion blog</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=35066</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2008-55: Hackers hijack bitchy fashion blog&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2008-55&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;April 23, 2008&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Defacement&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;It might have been a random hack, but the &lt;a href=&quot;http://www.theaustralian.news.com.au/story/0,24897,23586843-7582,00.html&quot;&gt;pornographic pictures splashed on an insider fashion industry blog&lt;/a&gt; where quickly blamed on the fashion icons and magazines offended by the blog.&lt;/p&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Media&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA</description>      <pubDate>Wed, 16 Jun 2010 14:36:55 -0400</pubDate>      <ddb:attackedentityfield>Media</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>April 23, 2008</ddb:dateoccured>      <ddb:entrytitle>WHID 2008-55: Hackers hijack bitchy fashion blog</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;It might have been a random hack, but the &lt;a href=&quot;http://www.theaustralian.news.com.au/story/0,24897,23586843-7582,00.html&quot;&gt;pornographic pictures splashed on an insider fashion industry blog&lt;/a&gt; where quickly blamed on the fashion icons and magazines offended by the blog.&lt;/p></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Defacement</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2008-55</ddb:whidid>    </item>    <item>      <title>WHID 2008-13: Harvard site hacked and leaked on BitTorrent</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34793</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2008-13: Harvard site hacked and leaked on BitTorrent&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2008-13&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;February 20, 2008&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://torrentfreak.com/harvard-website-hacked-080218/&quot;&gt;Harvard Site Hacked and Leaked on BitTorrent&lt;/a&gt; [TorrentFreak, Feb 18 2008]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://virtualization.sys-con.com/read/503459.htm&quot;&gt;Harvard Web Site Hack is a Cautionary Tale&lt;/a&gt; [Virtualization News Desk, Feb 19 2008]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://walkah.net/blog/walkah/harvard-joomla-site-hacked-things-learn&quot;&gt;Harvard Joomla site hacked: things to learn?&lt;/a&gt; [James Walker, Feb 19 2008]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;articleId=9063198&quot;&gt;Harvard Web site hacked; database on file-sharing site&lt;/a&gt; [Computer World, Feb 18 2008]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.scmagazineus.com/Harvard-grad-school-site-hacked-files-distributed-on-BitTorrent-network/article/107028/&quot;&gt;Harvard grad school site hacked, files distributed on BitTorrent network&lt;/a&gt; [SC Magazine, Feb 19 2008]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Education&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA&lt;br&gt;&lt;b&gt;Attacked System Technology: &lt;/b&gt;Joomla</description>      <pubDate>Wed, 16 Jun 2010 15:05:49 -0400</pubDate>      <ddb:attackedentityfield>Education</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology>Joomla</ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>February 20, 2008</ddb:dateoccured>      <ddb:entrytitle>WHID 2008-13: Harvard site hacked and leaked on BitTorrent</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://torrentfreak.com/harvard-website-hacked-080218/&quot;&gt;Harvard Site Hacked and Leaked on BitTorrent&lt;/a&gt; [TorrentFreak, Feb 18 2008]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://virtualization.sys-con.com/read/503459.htm&quot;&gt;Harvard Web Site Hack is a Cautionary Tale&lt;/a&gt; [Virtualization News Desk, Feb 19 2008]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://walkah.net/blog/walkah/harvard-joomla-site-hacked-things-learn&quot;&gt;Harvard Joomla site hacked: things to learn?&lt;/a&gt; [James Walker, Feb 19 2008]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;articleId=9063198&quot;&gt;Harvard Web site hacked; database on file-sharing site&lt;/a&gt; [Computer World, Feb 18 2008]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.scmagazineus.com/Harvard-grad-school-site-hacked-files-distributed-on-BitTorrent-network/article/107028/&quot;&gt;Harvard grad school site hacked, files distributed on BitTorrent network&lt;/a&gt; [SC Magazine, Feb 19 2008]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2008-13</ddb:whidid>    </item>    <item>      <title>WHID 2009-1: Gaza conflict cyber war</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34950</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2009-1: Gaza conflict cyber war&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2009-1&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;January 5, 2009&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Downtime&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;Update (Jan 13, 2009) - Ynet, an Israeli paper, reports that many of the sites defaced where actually DNS hijacked following a break-in to the servers of DomainTheNet, an Israeli registrar. And just like other recent DNS hijacking incidents, the fault was lack of sufficient authentications and the hackers got hold of passwords to the administration system.&lt;br&gt;Update (Jan 10, 2009) - Zone-H reports that in addition to Israeli sites, Turkish hackers are also targetting USA and Nato web sites using SQL injection.&lt;br&gt;The war in Gaza, like most modern wars, moved immediately to cyberspace. Islamic and Arab groups all over the world are using the Internet to retaliate against Israeli web sites. Some of the reported incidents are:&lt;br&gt;&lt;a href=&quot;http://www.israelnationalnews.com/News/Flash.aspx/158570&quot;&gt;Israeli bank site hacked by an Islamic group&lt;/a&gt;&lt;/li&gt;&lt;br&gt;&lt;a href=&quot;http://www.darkreading.com/security/attacks/showArticle.jhtml?articleID=212700313&quot;&gt;Hundreds of Israeli web sites hacked in 'Propaganda War'&lt;/a&gt;&lt;br&gt;Like every war, this one is not one sided. Interestingly enough, since this is a war between a country and a Guerrilla organization, and the cyber war which focus on mostly on conquering the minds of people is shaped similarly. The Israeli cyber war activity is mostly funneled through legal channels rather than hacking, as described by &lt;a href=&quot;http://blog.wired.com/defense/2008/12/israels-info-wa.html&quot;&gt;Wired&lt;/a&gt;.&lt;br&gt;However, unlike the physical war in which only the Israeli military is conducting, in cyberspace Israelis join by themselves the hacking war. Artuz 7, an Israeli media site, &lt;a href=&quot;http://www.israelnationalnews.com/News/News.aspx/129223&quot;&gt;reports &lt;/a&gt;that a group of students released a tool that perform distributed denial of service attacks against Hamas web sites. The &lt;a href=&quot;http://www.help-israel-win.org/index.php?lang=eng&quot;&gt;students site itself&lt;/a&gt; provides news alerts about the cyber war between Israel and the Hamas.&lt;br&gt;Editor's notes: (1) As a policy, we decided to report each such conflict as a single incident, unless some hack is especiallly of interest. The author of this incident is Israeli.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Various&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://www.ynetnews.com/articles/0,7340,L-3649281,00.html&quot;&gt;http://www.ynetnews.com/articles/0,7340,L-3649281,00.html&lt;/a></description>      <pubDate>Wed, 16 Jun 2010 14:23:05 -0400</pubDate>      <ddb:attackedentityfield>Various</ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>January 5, 2009</ddb:dateoccured>      <ddb:entrytitle>WHID 2009-1: Gaza conflict cyber war</ddb:entrytitle>      <ddb:incidentdescription>Update (Jan 13, 2009) - Ynet, an Israeli paper, reports that many of the sites defaced where actually DNS hijacked following a break-in to the servers of DomainTheNet, an Israeli registrar. And just like other recent DNS hijacking incidents, the fault was lack of sufficient authentications and the hackers got hold of passwords to the administration system.&#13;&#10;&#13;&#10;Update (Jan 10, 2009) - Zone-H reports that in addition to Israeli sites, Turkish hackers are also targetting USA and Nato web sites using SQL injection.&#13;&#10;&#13;&#10;The war in Gaza, like most modern wars, moved immediately to cyberspace. Islamic and Arab groups all over the world are using the Internet to retaliate against Israeli web sites. Some of the reported incidents are:&#13;&#10;&lt;a href=&quot;http://www.israelnationalnews.com/News/Flash.aspx/158570&quot;&gt;Israeli bank site hacked by an Islamic group&lt;/a&gt;&lt;/li&gt;&#13;&#10;&lt;a href=&quot;http://www.darkreading.com/security/attacks/showArticle.jhtml?articleID=212700313&quot;&gt;Hundreds of Israeli web sites hacked in 'Propaganda War'&lt;/a&gt;&#13;&#10;&#13;&#10;Like every war, this one is not one sided. Interestingly enough, since this is a war between a country and a Guerrilla organization, and the cyber war which focus on mostly on conquering the minds of people is shaped similarly. The Israeli cyber war activity is mostly funneled through legal channels rather than hacking, as described by &lt;a href=&quot;http://blog.wired.com/defense/2008/12/israels-info-wa.html&quot;&gt;Wired&lt;/a&gt;.&#13;&#10;&#13;&#10;However, unlike the physical war in which only the Israeli military is conducting, in cyberspace Israelis join by themselves the hacking war. Artuz 7, an Israeli media site, &lt;a href=&quot;http://www.israelnationalnews.com/News/News.aspx/129223&quot;&gt;reports &lt;/a&gt;that a group of students released a tool that perform distributed denial of service attacks against Hamas web sites. The &lt;a href=&quot;http://www.help-israel-win.org/index.php?lang=eng&quot;&gt;students site itself&lt;/a&gt; provides news alerts about the cyber war between Israel and the Hamas.&#13;&#10;&#13;&#10;Editor's notes: (1) As a policy, we decided to report each such conflict as a single incident, unless some hack is especiallly of interest. The author of this incident is Israeli.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Downtime</ddb:outcome>      <ddb:reference>http://www.ynetnews.com/articles/0,7340,L-3649281,00.html</ddb:reference>      <ddb:whidid>2009-1</ddb:whidid>    </item>    <item>      <title>WHID 2009-30: Sage SaaS Withdrawn Due to Security Flaws</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=35212</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2009-30: Sage SaaS Withdrawn Due to Security Flaws&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2009-30&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;January 21, 2009&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Monetary Loss&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;While we have no public record of an exploit in this case, it seems that the mare discovery of vulnerabilities in sage new SaaS (software as a service) offering created so much damage to classify it as an incident.&lt;/p&gt;&lt;br&gt;&lt;p&gt;Sage is the leading provider of accounting software in the UK and it was about to launch a trendy small business SaaS offering. However as &lt;a href=&quot;http://blogs.zdnet.com/SAAS/?p=655&quot;&gt;ZDnet reports&lt;/a&gt;, serious security flaws were discovered in the public beta and the company has to call off the launch. Who discovered the issues? naturally the competition. Duane Jackson, the CEO of a tiny rival company &lt;a href=&quot;http://blog.kashflow.com/2009/01/21/sage-live-security/&quot;&gt;reported&lt;/a&gt; them on his blog&lt;span class=&quot;post-author vcard&quot;&gt;&lt;span class=&quot;fn&quot;&gt;.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;br&gt;&lt;p&gt;&lt;span class=&quot;post-author vcard&quot;&gt;&lt;span class=&quot;fn&quot;&gt;More than anything, the incident shows how difficult it is for developers to migrate from desktop software to a web based offering. This is a whole new ball game, and security is one of the more difficult issues to adjust to. On the other hand it also shows that on line services are much more exposed to scrutiny, which may result in better security down the line.&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;br&gt;&lt;p&gt;&lt;span class=&quot;post-author vcard&quot;&gt;&lt;span class=&quot;fn&quot;&gt;As for the technical details, the reports found that the following issues in the application:&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;span class=&quot;post-author vcard&quot;&gt;&lt;span class=&quot;fn&quot;&gt;Password displayed in clear text and sent in the request line.&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;span class=&quot;post-author vcard&quot;&gt;&lt;span class=&quot;fn&quot;&gt;Remember me is on by default on any login.&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;span class=&quot;post-author vcard&quot;&gt;&lt;span class=&quot;fn&quot;&gt;Access to management sections of the site and other users data.&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Technology&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;UK&lt;br&gt;&lt;b&gt;Attacked System Technology: &lt;/b&gt;Sage</description>      <pubDate>Wed, 16 Jun 2010 14:15:52 -0400</pubDate>      <ddb:attackedentityfield>Technology</ddb:attackedentityfield>      <ddb:attackedentitygeography>UK</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology>Sage</ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>January 21, 2009</ddb:dateoccured>      <ddb:entrytitle>WHID 2009-30: Sage SaaS Withdrawn Due to Security Flaws</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;While we have no public record of an exploit in this case, it seems that the mare discovery of vulnerabilities in sage new SaaS (software as a service) offering created so much damage to classify it as an incident.&lt;/p&gt;&#13;&#10;&lt;p&gt;Sage is the leading provider of accounting software in the UK and it was about to launch a trendy small business SaaS offering. However as &lt;a href=&quot;http://blogs.zdnet.com/SAAS/?p=655&quot;&gt;ZDnet reports&lt;/a&gt;, serious security flaws were discovered in the public beta and the company has to call off the launch. Who discovered the issues? naturally the competition. Duane Jackson, the CEO of a tiny rival company &lt;a href=&quot;http://blog.kashflow.com/2009/01/21/sage-live-security/&quot;&gt;reported&lt;/a&gt; them on his blog&lt;span class=&quot;post-author vcard&quot;&gt;&lt;span class=&quot;fn&quot;&gt;.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&#13;&#10;&lt;p&gt;&lt;span class=&quot;post-author vcard&quot;&gt;&lt;span class=&quot;fn&quot;&gt;More than anything, the incident shows how difficult it is for developers to migrate from desktop software to a web based offering. This is a whole new ball game, and security is one of the more difficult issues to adjust to. On the other hand it also shows that on line services are much more exposed to scrutiny, which may result in better security down the line.&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&#13;&#10;&lt;p&gt;&lt;span class=&quot;post-author vcard&quot;&gt;&lt;span class=&quot;fn&quot;&gt;As for the technical details, the reports found that the following issues in the application:&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&#13;&#10;&lt;ul&gt;&#13;&#10;&lt;li&gt;&lt;span class=&quot;post-author vcard&quot;&gt;&lt;span class=&quot;fn&quot;&gt;Password displayed in clear text and sent in the request line.&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&#13;&#10;&lt;li&gt;&lt;span class=&quot;post-author vcard&quot;&gt;&lt;span class=&quot;fn&quot;&gt;Remember me is on by default on any login.&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&#13;&#10;&lt;li&gt;&lt;span class=&quot;post-author vcard&quot;&gt;&lt;span class=&quot;fn&quot;&gt;Access to management sections of the site and other users data.&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&#13;&#10;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Monetary Loss</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2009-30</ddb:whidid>    </item>    <item>      <title>WHID 2009-29: FBI &amp; Secret Service warn of a sophisticated HSM attack</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=35206</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2009-29: FBI &amp; Secret Service warn of a sophisticated HSM attack&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2009-29&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;February 25, 2009&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Monetary Loss&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;A very interesting &lt;a href=&quot;http://usa.visa.com/download/merchants/20090212-usss_fbi_advisory.pdf&quot;&gt;report &lt;/a&gt;by the FBI together with the US Secret service outlines a scheme exploiting SQL injection to steal credit card information from financial institutes.  The attack involves directly attacking HSMs, the banks key vaults in charge of verifying ATM PINs in order to brute force PIN numbers.&lt;/p&gt;&lt;br&gt;&lt;p&gt;The report is unique in describing an attack on financial services. Such attacks are know to happen but are seldom reported, certainly not with the amount of details in this report. However, the report does not indicate which incident it is based on. Is the close proximity of the report release to  the Heartland incident just a coincidence?&lt;/p&gt;&lt;br&gt;&lt;p&gt;Getting to this report took some effort and the only non blogshpere copy we found is on the Visa web site. If you know anything about this incident, please help us complete the information by leaving a comment on &lt;a href=&quot;/contact&quot;&gt;contacting us&lt;/a&gt;.&lt;/p&gt;&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Finance&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA</description>      <pubDate>Wed, 16 Jun 2010 14:15:53 -0400</pubDate>      <ddb:attackedentityfield>Finance</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>February 25, 2009</ddb:dateoccured>      <ddb:entrytitle>WHID 2009-29: FBI &amp; Secret Service warn of a sophisticated HSM attack</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;A very interesting &lt;a href=&quot;http://usa.visa.com/download/merchants/20090212-usss_fbi_advisory.pdf&quot;&gt;report &lt;/a&gt;by the FBI together with the US Secret service outlines a scheme exploiting SQL injection to steal credit card information from financial institutes.  The attack involves directly attacking HSMs, the banks key vaults in charge of verifying ATM PINs in order to brute force PIN numbers.&lt;/p&gt;&#13;&#10;&lt;p&gt;The report is unique in describing an attack on financial services. Such attacks are know to happen but are seldom reported, certainly not with the amount of details in this report. However, the report does not indicate which incident it is based on. Is the close proximity of the report release to  the Heartland incident just a coincidence?&lt;/p&gt;&#13;&#10;&lt;p&gt;Getting to this report took some effort and the only non blogshpere copy we found is on the Visa web site. If you know anything about this incident, please help us complete the information by leaving a comment on &lt;a href=&quot;/contact&quot;&gt;contacting us&lt;/a&gt;.&lt;/p></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Monetary Loss</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2009-29</ddb:whidid>    </item>    <item>      <title>WHID 2008-14: Hacker takes over Dallas police Web site</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34799</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2008-14: Hacker takes over Dallas police Web site&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2008-14&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;February 21, 2008&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Defacement&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;### Dallas say the department shut down its Internet presence after a hacker took over its Web site and filled it with anti-American rants.&lt;br /&gt;&lt;br /&gt;The vandalized Web pages included a doctored photograph showing American troops watching over four people lined up against a wall.&lt;br /&gt;&lt;br /&gt;Each of the four prisoners had lines leading away from their faces to individual head shots of President George W. Bush, Vice President Dick Cheney, Secretary of State Condoleezza Rice and Sen. John McCain&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.upi.com/NewsTrack/Top_News/2008/02/19/hacker_defaces_dallas_police_web_site/5990/&quot;&gt;Hacker defaces Dallas police Web site&lt;/a&gt; [United Press, Feb 19 2008]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.foxnews.com/story/0,2933,331201,00.html&quot;&gt;Dallas Police Web Site Hacked, Defaced&lt;/a&gt; [Fox (AP), Feb 19 2008]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Security &amp;amp; Law Enforcement&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA</description>      <pubDate>Wed, 16 Jun 2010 15:05:03 -0400</pubDate>      <ddb:attackedentityfield>Security &amp;amp; Law Enforcement</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>February 21, 2008</ddb:dateoccured>      <ddb:entrytitle>WHID 2008-14: Hacker takes over Dallas police Web site</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;### Dallas say the department shut down its Internet presence after a hacker took over its Web site and filled it with anti-American rants.&lt;br /&gt;&lt;br /&gt;The vandalized Web pages included a doctored photograph showing American troops watching over four people lined up against a wall.&lt;br /&gt;&lt;br /&gt;Each of the four prisoners had lines leading away from their faces to individual head shots of President George W. Bush, Vice President Dick Cheney, Secretary of State Condoleezza Rice and Sen. John McCain&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.upi.com/NewsTrack/Top_News/2008/02/19/hacker_defaces_dallas_police_web_site/5990/&quot;&gt;Hacker defaces Dallas police Web site&lt;/a&gt; [United Press, Feb 19 2008]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.foxnews.com/story/0,2933,331201,00.html&quot;&gt;Dallas Police Web Site Hacked, Defaced&lt;/a&gt; [Fox (AP), Feb 19 2008]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Defacement</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2008-14</ddb:whidid>    </item>    <item>      <title>WHID 2009-8: Wired.com Image Viewer Hacked to Create Phony Steve Jobs Health Story</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=35071</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2009-8: Wired.com Image Viewer Hacked to Create Phony Steve Jobs Health Story&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2009-8&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;January 22, 2009&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Disinformation&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;John Abell from Wired magazine often writes about Apple's CEO health. However, &lt;a href=&quot;http://www.alleyinsider.com/2009/1/vandalized-wiredcom-falsely-repo&quot;&gt;this report&lt;/a&gt; about Job suffering a cardiac arrest, was neither his nor true. The culprit was Wired public image viewing utility which lets people upload am image and than presented the image as part of the Wired web site, banner and domain included.&lt;/p&gt;&lt;br&gt;&lt;p&gt;This is a wonderful example of a web application design flaw. There was nothing wrong with the code, however the design of the feature enabled it to be abused.&lt;/p&gt;&lt;br&gt;&lt;p style=&quot;text-align: center;&quot;&gt;&lt;img src=&quot;/sites/default/files/images/hacked_wired_page.gif&quot; width=&quot;372&quot; height=&quot;251&quot; /&gt;&lt;/p&gt;&lt;br&gt;&lt;p&gt;Further information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://blog.wired.com/business/2009/01/wiredcom-imagev.html&quot;&gt;Abell's own report on the incident&lt;/a&gt;&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Media&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA</description>      <pubDate>Wed, 16 Jun 2010 14:23:05 -0400</pubDate>      <ddb:attackedentityfield>Media</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>January 22, 2009</ddb:dateoccured>      <ddb:entrytitle>WHID 2009-8: Wired.com Image Viewer Hacked to Create Phony Steve Jobs Health Story</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;John Abell from Wired magazine often writes about Apple's CEO health. However, &lt;a href=&quot;http://www.alleyinsider.com/2009/1/vandalized-wiredcom-falsely-repo&quot;&gt;this report&lt;/a&gt; about Job suffering a cardiac arrest, was neither his nor true. The culprit was Wired public image viewing utility which lets people upload am image and than presented the image as part of the Wired web site, banner and domain included.&lt;/p&gt;&#13;&lt;p&gt;This is a wonderful example of a web application design flaw. There was nothing wrong with the code, however the design of the feature enabled it to be abused.&lt;/p&gt;&#13;&lt;p style=&quot;text-align: center;&quot;&gt;&lt;img src=&quot;/sites/default/files/images/hacked_wired_page.gif&quot; width=&quot;372&quot; height=&quot;251&quot; /&gt;&lt;/p&gt;&#13;&lt;p&gt;Further information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://blog.wired.com/business/2009/01/wiredcom-imagev.html&quot;&gt;Abell's own report on the incident&lt;/a&gt;&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Disinformation</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2009-8</ddb:whidid>    </item>    <item>      <title>WHID 2009-28: Serious Leakage on Mac clone Maker's site</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=35201</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2009-28: Serious Leakage on Mac clone Maker's site&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2009-28&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;February 11, 2009&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;The Register &lt;a href=&quot;http://www.theregister.co.uk/2009/02/11/psystart_website/&quot;&gt;reports &lt;/a&gt;that the online shop of Psystar, a maker of Mac compatible equipment is heavily leaking technical information that can  be expoited to hack the site.&lt;/p&gt;&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Retail&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA</description>      <pubDate>Wed, 16 Jun 2010 14:15:57 -0400</pubDate>      <ddb:attackedentityfield>Retail</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>February 11, 2009</ddb:dateoccured>      <ddb:entrytitle>WHID 2009-28: Serious Leakage on Mac clone Maker's site</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;The Register &lt;a href=&quot;http://www.theregister.co.uk/2009/02/11/psystart_website/&quot;&gt;reports &lt;/a&gt;that the online shop of Psystar, a maker of Mac compatible equipment is heavily leaking technical information that can  be expoited to hack the site.&lt;/p></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2009-28</ddb:whidid>    </item>    <item>      <title>WHID 2007-87: Hacker uses Insider information to gain on the stock exhange</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34805</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2007-87: Hacker uses Insider information to gain on the stock exhange&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2007-87&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;February 21, 2008&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;###&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://jeremiahgrossman.blogspot.com/2008/02/it-pays-to-be-hacker.html&quot;&gt;It pays to be a hacker&lt;/a&gt; [Jeremiah Grossman, Feb 19 2008]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.nytimes.com/2008/02/15/business/15norris.html&quot;&gt;Make Big Profits Illegally (and Maybe Keep Them, Too)&lt;/a&gt; [New York Times (free subscription required), Feb 15 2008]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.theregister.co.uk/2008/02/19/insider_trading_catch22/&quot;&gt;Hacker holds onto ill-gotten gains thanks to US courts&lt;/a&gt; [The Register, Feb 17 2008]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Health</description>      <pubDate>Mon, 24 May 2010 13:54:42 -0400</pubDate>      <ddb:attackedentityfield>Health</ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>February 21, 2008</ddb:dateoccured>      <ddb:entrytitle>WHID 2007-87: Hacker uses Insider information to gain on the stock exhange</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;###&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://jeremiahgrossman.blogspot.com/2008/02/it-pays-to-be-hacker.html&quot;&gt;It pays to be a hacker&lt;/a&gt; [Jeremiah Grossman, Feb 19 2008]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.nytimes.com/2008/02/15/business/15norris.html&quot;&gt;Make Big Profits Illegally (and Maybe Keep Them, Too)&lt;/a&gt; [New York Times (free subscription required), Feb 15 2008]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.theregister.co.uk/2008/02/19/insider_trading_catch22/&quot;&gt;Hacker holds onto ill-gotten gains thanks to US courts&lt;/a&gt; [The Register, Feb 17 2008]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome></ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2007-87</ddb:whidid>    </item>    <item>      <title>WHID 2007-87: Hacker uses Insider information to gain on the stock exhange</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34806</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2007-87: Hacker uses Insider information to gain on the stock exhange&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2007-87&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;February 21, 2008&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;###&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://jeremiahgrossman.blogspot.com/2008/02/it-pays-to-be-hacker.html&quot;&gt;It pays to be a hacker&lt;/a&gt; [Jeremiah Grossman, Feb 19 2008]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.nytimes.com/2008/02/15/business/15norris.html&quot;&gt;Make Big Profits Illegally (and Maybe Keep Them, Too)&lt;/a&gt; [New York Times (free subscription required), Feb 15 2008]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.theregister.co.uk/2008/02/19/insider_trading_catch22/&quot;&gt;Hacker holds onto ill-gotten gains thanks to US courts&lt;/a&gt; [The Register, Feb 17 2008]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;Ukrain&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Health</description>      <pubDate>Mon, 24 May 2010 13:54:42 -0400</pubDate>      <ddb:attackedentityfield>Health</ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography>Ukrain</ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>February 21, 2008</ddb:dateoccured>      <ddb:entrytitle>WHID 2007-87: Hacker uses Insider information to gain on the stock exhange</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;###&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://jeremiahgrossman.blogspot.com/2008/02/it-pays-to-be-hacker.html&quot;&gt;It pays to be a hacker&lt;/a&gt; [Jeremiah Grossman, Feb 19 2008]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.nytimes.com/2008/02/15/business/15norris.html&quot;&gt;Make Big Profits Illegally (and Maybe Keep Them, Too)&lt;/a&gt; [New York Times (free subscription required), Feb 15 2008]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.theregister.co.uk/2008/02/19/insider_trading_catch22/&quot;&gt;Hacker holds onto ill-gotten gains thanks to US courts&lt;/a&gt; [The Register, Feb 17 2008]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome></ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2007-87</ddb:whidid>    </item>    <item>      <title>WHID 2007-87: Hacker uses Insider information to gain on the stock exhange</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34807</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2007-87: Hacker uses Insider information to gain on the stock exhange&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2007-87&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;February 21, 2008&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;###&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://jeremiahgrossman.blogspot.com/2008/02/it-pays-to-be-hacker.html&quot;&gt;It pays to be a hacker&lt;/a&gt; [Jeremiah Grossman, Feb 19 2008]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.nytimes.com/2008/02/15/business/15norris.html&quot;&gt;Make Big Profits Illegally (and Maybe Keep Them, Too)&lt;/a&gt; [New York Times (free subscription required), Feb 15 2008]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.theregister.co.uk/2008/02/19/insider_trading_catch22/&quot;&gt;Hacker holds onto ill-gotten gains thanks to US courts&lt;/a&gt; [The Register, Feb 17 2008]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Health&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA</description>      <pubDate>Mon, 24 May 2010 13:54:42 -0400</pubDate>      <ddb:attackedentityfield>Health</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>February 21, 2008</ddb:dateoccured>      <ddb:entrytitle>WHID 2007-87: Hacker uses Insider information to gain on the stock exhange</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;###&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://jeremiahgrossman.blogspot.com/2008/02/it-pays-to-be-hacker.html&quot;&gt;It pays to be a hacker&lt;/a&gt; [Jeremiah Grossman, Feb 19 2008]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.nytimes.com/2008/02/15/business/15norris.html&quot;&gt;Make Big Profits Illegally (and Maybe Keep Them, Too)&lt;/a&gt; [New York Times (free subscription required), Feb 15 2008]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.theregister.co.uk/2008/02/19/insider_trading_catch22/&quot;&gt;Hacker holds onto ill-gotten gains thanks to US courts&lt;/a&gt; [The Register, Feb 17 2008]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome></ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2007-87</ddb:whidid>    </item>    <item>      <title>WHID 2007-87: Hacker uses Insider information to gain on the stock exhange</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34808</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2007-87: Hacker uses Insider information to gain on the stock exhange&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2007-87&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;February 21, 2008&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;###&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://jeremiahgrossman.blogspot.com/2008/02/it-pays-to-be-hacker.html&quot;&gt;It pays to be a hacker&lt;/a&gt; [Jeremiah Grossman, Feb 19 2008]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.nytimes.com/2008/02/15/business/15norris.html&quot;&gt;Make Big Profits Illegally (and Maybe Keep Them, Too)&lt;/a&gt; [New York Times (free subscription required), Feb 15 2008]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.theregister.co.uk/2008/02/19/insider_trading_catch22/&quot;&gt;Hacker holds onto ill-gotten gains thanks to US courts&lt;/a&gt; [The Register, Feb 17 2008]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Health</description>      <pubDate>Mon, 24 May 2010 13:54:42 -0400</pubDate>      <ddb:attackedentityfield>Health</ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>February 21, 2008</ddb:dateoccured>      <ddb:entrytitle>WHID 2007-87: Hacker uses Insider information to gain on the stock exhange</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;###&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://jeremiahgrossman.blogspot.com/2008/02/it-pays-to-be-hacker.html&quot;&gt;It pays to be a hacker&lt;/a&gt; [Jeremiah Grossman, Feb 19 2008]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.nytimes.com/2008/02/15/business/15norris.html&quot;&gt;Make Big Profits Illegally (and Maybe Keep Them, Too)&lt;/a&gt; [New York Times (free subscription required), Feb 15 2008]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.theregister.co.uk/2008/02/19/insider_trading_catch22/&quot;&gt;Hacker holds onto ill-gotten gains thanks to US courts&lt;/a&gt; [The Register, Feb 17 2008]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome></ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2007-87</ddb:whidid>    </item>    <item>      <title>WHID 2008-42: Chinese hackers steal 9 million items of personal information from South Koreans</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34944</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2008-42: Chinese hackers steal 9 million items of personal information from South Koreans&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2008-42&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;December 30, 2008&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;The &lt;a href=&quot;http://209.85.129.132/search?q=cache:B3oFg-OQmAQJ:www.thedarkvisitor.com/2008/07/chinese-hackers-steal-9-million-items-of-personal-information-from-south-koreans/+chinese-hackers-steal-9-million-items-of-personal-information-from-south-koreans/&amp;amp;hl=en&amp;amp;ct=clnk&amp;amp;cd=1&quot;&gt;Dark Visitor&lt;/a&gt;, a Chinese hacking insider site, and the Korean &lt;a href=&quot;http://english.chosun.com/w21data/html/news/200807/200807280013.html&quot;&gt;Chuson&lt;/a&gt; reports that a Chinese  hacker used a commercially available SQL injection tool called HDMI to penetrate a large number of South Korean sites and still 9 million personal information items, which he than sold for approximately $15,000 to South Koreans for them to abuse.&lt;/p&gt;&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;China&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Various&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;South Korea</description>      <pubDate>Wed, 16 Jun 2010 14:47:56 -0400</pubDate>      <ddb:attackedentityfield>Various</ddb:attackedentityfield>      <ddb:attackedentitygeography>South Korea</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography>China</ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>December 30, 2008</ddb:dateoccured>      <ddb:entrytitle>WHID 2008-42: Chinese hackers steal 9 million items of personal information from South Koreans</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;The &lt;a href=&quot;http://209.85.129.132/search?q=cache:B3oFg-OQmAQJ:www.thedarkvisitor.com/2008/07/chinese-hackers-steal-9-million-items-of-personal-information-from-south-koreans/+chinese-hackers-steal-9-million-items-of-personal-information-from-south-koreans/&amp;amp;hl=en&amp;amp;ct=clnk&amp;amp;cd=1&quot;&gt;Dark Visitor&lt;/a&gt;, a Chinese hacking insider site, and the Korean &lt;a href=&quot;http://english.chosun.com/w21data/html/news/200807/200807280013.html&quot;&gt;Chuson&lt;/a&gt; reports that a Chinese  hacker used a commercially available SQL injection tool called HDMI to penetrate a large number of South Korean sites and still 9 million personal information items, which he than sold for approximately $15,000 to South Koreans for them to abuse.&lt;/p></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2008-42</ddb:whidid>    </item>    <item>      <title>WHID 2007-87: Hacker uses Insider information to gain on the stock exhange</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34809</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2007-87: Hacker uses Insider information to gain on the stock exhange&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2007-87&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;February 21, 2008&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;###&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://jeremiahgrossman.blogspot.com/2008/02/it-pays-to-be-hacker.html&quot;&gt;It pays to be a hacker&lt;/a&gt; [Jeremiah Grossman, Feb 19 2008]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.nytimes.com/2008/02/15/business/15norris.html&quot;&gt;Make Big Profits Illegally (and Maybe Keep Them, Too)&lt;/a&gt; [New York Times (free subscription required), Feb 15 2008]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.theregister.co.uk/2008/02/19/insider_trading_catch22/&quot;&gt;Hacker holds onto ill-gotten gains thanks to US courts&lt;/a&gt; [The Register, Feb 17 2008]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Health</description>      <pubDate>Mon, 24 May 2010 13:54:42 -0400</pubDate>      <ddb:attackedentityfield>Health</ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>February 21, 2008</ddb:dateoccured>      <ddb:entrytitle>WHID 2007-87: Hacker uses Insider information to gain on the stock exhange</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;###&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://jeremiahgrossman.blogspot.com/2008/02/it-pays-to-be-hacker.html&quot;&gt;It pays to be a hacker&lt;/a&gt; [Jeremiah Grossman, Feb 19 2008]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.nytimes.com/2008/02/15/business/15norris.html&quot;&gt;Make Big Profits Illegally (and Maybe Keep Them, Too)&lt;/a&gt; [New York Times (free subscription required), Feb 15 2008]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.theregister.co.uk/2008/02/19/insider_trading_catch22/&quot;&gt;Hacker holds onto ill-gotten gains thanks to US courts&lt;/a&gt; [The Register, Feb 17 2008]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome></ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2007-87</ddb:whidid>    </item>    <item>      <title>WHID 2007-87: Hacker uses Insider information to gain on the stock exhange</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34810</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2007-87: Hacker uses Insider information to gain on the stock exhange&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2007-87&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;February 21, 2008&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;###&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://jeremiahgrossman.blogspot.com/2008/02/it-pays-to-be-hacker.html&quot;&gt;It pays to be a hacker&lt;/a&gt; [Jeremiah Grossman, Feb 19 2008]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.nytimes.com/2008/02/15/business/15norris.html&quot;&gt;Make Big Profits Illegally (and Maybe Keep Them, Too)&lt;/a&gt; [New York Times (free subscription required), Feb 15 2008]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.theregister.co.uk/2008/02/19/insider_trading_catch22/&quot;&gt;Hacker holds onto ill-gotten gains thanks to US courts&lt;/a&gt; [The Register, Feb 17 2008]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Health</description>      <pubDate>Mon, 24 May 2010 13:54:42 -0400</pubDate>      <ddb:attackedentityfield>Health</ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>February 21, 2008</ddb:dateoccured>      <ddb:entrytitle>WHID 2007-87: Hacker uses Insider information to gain on the stock exhange</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;###&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://jeremiahgrossman.blogspot.com/2008/02/it-pays-to-be-hacker.html&quot;&gt;It pays to be a hacker&lt;/a&gt; [Jeremiah Grossman, Feb 19 2008]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.nytimes.com/2008/02/15/business/15norris.html&quot;&gt;Make Big Profits Illegally (and Maybe Keep Them, Too)&lt;/a&gt; [New York Times (free subscription required), Feb 15 2008]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.theregister.co.uk/2008/02/19/insider_trading_catch22/&quot;&gt;Hacker holds onto ill-gotten gains thanks to US courts&lt;/a&gt; [The Register, Feb 17 2008]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome></ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2007-87</ddb:whidid>    </item>    <item>      <title>WHID 2008-15: ValueClick to Pay $2.9 Million to Settle FTC Charges</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34811</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2008-15: ValueClick to Pay $2.9 Million to Settle FTC Charges&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2008-15&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;March 24, 2008&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Monetary Loss&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;In this case SQL injection was not the root cause, but rather the justification. Just as Al Capone was arrested at the end of the day for tax evasion, ValueClick, which seems to infuriate the FTC over many nasty commercial misdeeds, was caught at the end of the day for SQL injection, presumably left open against the company written security policy.&lt;/p&gt;&lt;br&gt;&lt;p&gt;The FTC settlement cost ValueClick a record amount of $2.9 million dollars, plus 20 years of rigorous security procedures that will probably cost as much if not more. On top of that, eBay, a major partner, left ValueClick as a result.&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.ftc.gov/opa/2008/03/vc.shtm&quot;&gt;ValueClick to Pay $2.9 Million to Settle FTC Charges&lt;/a&gt; [Federal Trade Commision, Mar 17 2008]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.theregister.co.uk/2008/03/17/ebay_dumps_valueclick/&quot;&gt;eBay dumps ValueClick&lt;/a&gt; [The Register, Mar 17 2008]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Marketing&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA</description>      <pubDate>Wed, 16 Jun 2010 15:03:38 -0400</pubDate>      <ddb:attackedentityfield>Marketing</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>March 24, 2008</ddb:dateoccured>      <ddb:entrytitle>WHID 2008-15: ValueClick to Pay $2.9 Million to Settle FTC Charges</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;In this case SQL injection was not the root cause, but rather the justification. Just as Al Capone was arrested at the end of the day for tax evasion, ValueClick, which seems to infuriate the FTC over many nasty commercial misdeeds, was caught at the end of the day for SQL injection, presumably left open against the company written security policy.&lt;/p&gt;&#13;&lt;p&gt;The FTC settlement cost ValueClick a record amount of $2.9 million dollars, plus 20 years of rigorous security procedures that will probably cost as much if not more. On top of that, eBay, a major partner, left ValueClick as a result.&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.ftc.gov/opa/2008/03/vc.shtm&quot;&gt;ValueClick to Pay $2.9 Million to Settle FTC Charges&lt;/a&gt; [Federal Trade Commision, Mar 17 2008]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.theregister.co.uk/2008/03/17/ebay_dumps_valueclick/&quot;&gt;eBay dumps ValueClick&lt;/a&gt; [The Register, Mar 17 2008]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Monetary Loss</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2008-15</ddb:whidid>    </item>    <item>      <title>WHID 2009-9: MetaFilter suffers an SQL injection attack</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=35076</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2009-9: MetaFilter suffers an SQL injection attack&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2009-9&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;January 24, 2009&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Planting of Malware&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;MetaFilter &lt;a href=&quot;http://en.wikipedia.org/wiki/MetaFilter#Moderation&quot;&gt;philosophy &lt;/a&gt;is that social norms and peer pressure, referred to as &quot;self-policing&quot;, will ensure the quality of the content of the site. However is seems that this philosophy does not extend to hackers who &lt;a href=&quot;http://status.metafilter.com/2009/01/sql-inject-problem.html&quot;&gt;abuse the site's software to plant Malware&lt;/a&gt; affecting MetaFilter users.&lt;/p&gt;&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Web 2.0&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA</description>      <pubDate>Wed, 16 Jun 2010 14:23:05 -0400</pubDate>      <ddb:attackedentityfield>Web 2.0</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>January 24, 2009</ddb:dateoccured>      <ddb:entrytitle>WHID 2009-9: MetaFilter suffers an SQL injection attack</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;MetaFilter &lt;a href=&quot;http://en.wikipedia.org/wiki/MetaFilter#Moderation&quot;&gt;philosophy &lt;/a&gt;is that social norms and peer pressure, referred to as &quot;self-policing&quot;, will ensure the quality of the content of the site. However is seems that this philosophy does not extend to hackers who &lt;a href=&quot;http://status.metafilter.com/2009/01/sql-inject-problem.html&quot;&gt;abuse the site's software to plant Malware&lt;/a&gt; affecting MetaFilter users.&lt;/p></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Planting of Malware</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2009-9</ddb:whidid>    </item>    <item>      <title>WHID 2008-16: Turkish PM supporters hack hacker&amp;#039;s Web site</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34816</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2008-16: Turkish PM supporters hack hacker&amp;#039;s Web site&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2008-16&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;May 11, 2008&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Defacement&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;In a twist on the classical defacement incident, supporters of the Turkish PM defaced, as a retaliation, the web site of hackers who just recently defaced the PM web site. A disturbing question is whether this is a juvenile mischief or was the act planned and executed by PM supporters. Did the political spin reached web site hacking?&lt;/p&gt;&lt;br&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.turkishdailynews.com.tr/article.php?enewsid=104028&quot;&gt;Erdogan supporters hack hacker's Web site&lt;/a&gt; [Turkish Daily News, May 9 2008]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Politics&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;Turkey</description>      <pubDate>Wed, 16 Jun 2010 15:03:25 -0400</pubDate>      <ddb:attackedentityfield>Politics</ddb:attackedentityfield>      <ddb:attackedentitygeography>Turkey</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>May 11, 2008</ddb:dateoccured>      <ddb:entrytitle>WHID 2008-16: Turkish PM supporters hack hacker&amp;#039;s Web site</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;In a twist on the classical defacement incident, supporters of the Turkish PM defaced, as a retaliation, the web site of hackers who just recently defaced the PM web site. A disturbing question is whether this is a juvenile mischief or was the act planned and executed by PM supporters. Did the political spin reached web site hacking?&lt;/p&gt;&#13;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.turkishdailynews.com.tr/article.php?enewsid=104028&quot;&gt;Erdogan supporters hack hacker's Web site&lt;/a&gt; [Turkish Daily News, May 9 2008]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Defacement</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2008-16</ddb:whidid>    </item>    <item>      <title>WHID 2009-27: Panasonic Products for Cheap</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=35195</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2009-27: Panasonic Products for Cheap&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2009-27&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;February 14, 2009&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Monetary Loss&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;A &lt;a href=&quot;http://www.zdnet.co.uk/talkback/0,1000001161,39610697-39001058c-20100458o,00.htm&quot;&gt;report &lt;/a&gt;suggests that the UK retail site of the electronic equipment giant Panasonic was hacked and prices of products where set to pennies. Since the incident followed a layoff of 15,000 employees, it is assumed to be a disgruntled employees doing.&lt;/p&gt;&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Retail&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;UK</description>      <pubDate>Wed, 16 Jun 2010 14:16:19 -0400</pubDate>      <ddb:attackedentityfield>Retail</ddb:attackedentityfield>      <ddb:attackedentitygeography>UK</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>February 14, 2009</ddb:dateoccured>      <ddb:entrytitle>WHID 2009-27: Panasonic Products for Cheap</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;A &lt;a href=&quot;http://www.zdnet.co.uk/talkback/0,1000001161,39610697-39001058c-20100458o,00.htm&quot;&gt;report &lt;/a&gt;suggests that the UK retail site of the electronic equipment giant Panasonic was hacked and prices of products where set to pennies. Since the incident followed a layoff of 15,000 employees, it is assumed to be a disgruntled employees doing.&lt;/p></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Monetary Loss</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2009-27</ddb:whidid>    </item>    <item>      <title>WHID 2008-41: A Joomla first day exploit</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34938</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2008-41: A Joomla first day exploit&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2008-41&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;August 12, 2008&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Defacement&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Joomla is a widely used open source  content management system. Many &lt;a href=&quot;http://theprogrammerx.wordpress.com/2008/08/23/what-the-hack-is-going-on-three-attacks-within-a-week/&quot;&gt;administrators reports&lt;/a&gt; that &lt;a href=&quot;http://developer.joomla.org/security/news/241-20080801-core-password-remind-functionality.html&quot;&gt;a vulnerability announced August 12&lt;sup&gt;th&lt;/sup&gt;&lt;/a&gt; was immediately exploited by hackers to attack Joomla based web sites. Another report shows a specific site that was defaced by exploiting the same vulnerability.&lt;/p&gt;&lt;br&gt;&lt;p&gt;This incident shows the importance of timely patching, but also brings back the age old debate around publication of vulnerabilities by researchers. Does it contribute to software security or just helps the hackers?&lt;/p&gt;&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Various&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked System Technology: &lt;/b&gt;Joomla</description>      <pubDate>Wed, 16 Jun 2010 14:51:18 -0400</pubDate>      <ddb:attackedentityfield>Various</ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology>Joomla</ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>August 12, 2008</ddb:dateoccured>      <ddb:entrytitle>WHID 2008-41: A Joomla first day exploit</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Joomla is a widely used open source  content management system. Many &lt;a href=&quot;http://theprogrammerx.wordpress.com/2008/08/23/what-the-hack-is-going-on-three-attacks-within-a-week/&quot;&gt;administrators reports&lt;/a&gt; that &lt;a href=&quot;http://developer.joomla.org/security/news/241-20080801-core-password-remind-functionality.html&quot;&gt;a vulnerability announced August 12&lt;sup&gt;th&lt;/sup&gt;&lt;/a&gt; was immediately exploited by hackers to attack Joomla based web sites. Another report shows a specific site that was defaced by exploiting the same vulnerability.&lt;/p&gt;&#13;&#10;&lt;p&gt;This incident shows the importance of timely patching, but also brings back the age old debate around publication of vulnerabilities by researchers. Does it contribute to software security or just helps the hackers?&lt;/p></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Defacement</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2008-41</ddb:whidid>    </item>    <item>      <title>WHID 2009-26: F-Secure Joins The Breached AV Vendors Club</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=35189</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2009-26: F-Secure Joins The Breached AV Vendors Club&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2009-26&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;February 11, 2009&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;It wasn't surprising that after attacking a &lt;a href=&quot;/whid/2009/19/kaspersky_site_breached&quot;&gt;Kaspereski &lt;/a&gt;and a &lt;a href=&quot;/whid/2009/20/bitdefender_joins_kasperski_on_the_breached_side&quot;&gt;BitDefender&lt;/a&gt; web sites, Uno, the Romanian hacker,  would continue to strike anti-virus vendors. This time he found a vulnerability in the web site of Finish AV vendor F-Secure. Somewhat less severe than the others, the vulnerability enabled the hacker only to access virus statistics.&lt;/p&gt;&lt;br&gt;&lt;p&gt;As usual, the marketing department &lt;a href=&quot;http://news.cnet.com/8301-1009_3-10163227-83.html&quot;&gt;response &lt;/a&gt;is amazing, mentioning that &quot;&lt;em&gt;the problem with its site was due to a bug in a Web application and not related to an unpatched system&lt;/em&gt;&quot;. Does that make it better?&lt;/p&gt;&lt;br&gt;&lt;p&gt;Frankly, I don't envy the marketing department role. The company, any company for that matter, is spending too little on web application security, sites are taken down daily, and the marketing people are send to fend off the public. They must have a thick skin to survive in marketing.&lt;/p&gt;&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;Romania&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Technology&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;Finland</description>      <pubDate>Wed, 16 Jun 2010 14:16:22 -0400</pubDate>      <ddb:attackedentityfield>Technology</ddb:attackedentityfield>      <ddb:attackedentitygeography>Finland</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography>Romania</ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>February 11, 2009</ddb:dateoccured>      <ddb:entrytitle>WHID 2009-26: F-Secure Joins The Breached AV Vendors Club</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;It wasn't surprising that after attacking a &lt;a href=&quot;/whid/2009/19/kaspersky_site_breached&quot;&gt;Kaspereski &lt;/a&gt;and a &lt;a href=&quot;/whid/2009/20/bitdefender_joins_kasperski_on_the_breached_side&quot;&gt;BitDefender&lt;/a&gt; web sites, Uno, the Romanian hacker,  would continue to strike anti-virus vendors. This time he found a vulnerability in the web site of Finish AV vendor F-Secure. Somewhat less severe than the others, the vulnerability enabled the hacker only to access virus statistics.&lt;/p&gt;&#13;&#10;&lt;p&gt;As usual, the marketing department &lt;a href=&quot;http://news.cnet.com/8301-1009_3-10163227-83.html&quot;&gt;response &lt;/a&gt;is amazing, mentioning that &quot;&lt;em&gt;the problem with its site was due to a bug in a Web application and not related to an unpatched system&lt;/em&gt;&quot;. Does that make it better?&lt;/p&gt;&#13;&#10;&lt;p&gt;Frankly, I don't envy the marketing department role. The company, any company for that matter, is spending too little on web application security, sites are taken down daily, and the marketing people are send to fend off the public. They must have a thick skin to survive in marketing.&lt;/p></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2009-26</ddb:whidid>    </item>    <item>      <title>WHID 2009-10: MacRumorsLive feed hack</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=35081</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2009-10: MacRumorsLive feed hack&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2009-10&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;January 7, 2009&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Disinformation&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;It seems that if the worse thing that can happen to hackers is a real accident to Apple's CEO Steve Jobs. The number of hacks devoted to informing us about his fictitious accidents is just overwhelming. In this case &lt;a href=&quot;http://anantasec.blogspot.com/2009/01/i-was-watching-macrumors-live-feed.html&quot;&gt;AnantaSec reports&lt;/a&gt; a hack into Mac Rumors feed that was possible simply because a file with the administrator password was laying around accessible to anyone due to an administration error.&lt;/p&gt;&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Media&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA</description>      <pubDate>Wed, 16 Jun 2010 14:23:05 -0400</pubDate>      <ddb:attackedentityfield>Media</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>January 7, 2009</ddb:dateoccured>      <ddb:entrytitle>WHID 2009-10: MacRumorsLive feed hack</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;It seems that if the worse thing that can happen to hackers is a real accident to Apple's CEO Steve Jobs. The number of hacks devoted to informing us about his fictitious accidents is just overwhelming. In this case &lt;a href=&quot;http://anantasec.blogspot.com/2009/01/i-was-watching-macrumors-live-feed.html&quot;&gt;AnantaSec reports&lt;/a&gt; a hack into Mac Rumors feed that was possible simply because a file with the administrator password was laying around accessible to anyone due to an administration error.&lt;/p></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Disinformation</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2009-10</ddb:whidid>    </item>    <item>      <title>WHID 2008-17: Hackers&amp;#039; posts on epilepsy forum cause migraines, seizures</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34821</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2008-17: Hackers&amp;#039; posts on epilepsy forum cause migraines, seizures&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2008-17&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;May 11, 2008&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Planting of Malware&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Up to now we never registered at WHID an incident that caused physical pain on its victims. Unfortunately, there is always a first. In an attack which gives a whole new dimension to the term &quot;malicious&quot;,hackers recently injected to the Epilepsy Foundation's Web site hundreds of pictures and links to pages with rapidly flashing images.&lt;/p&gt;&lt;br&gt;&lt;p&gt;The breach caused severe migraines and near-seizure reactions in some site visitors who viewed the images. People with photosensitive epilepsy can get seizures when they're exposed to flickering images, a response also caused by some video games and cartoons.&lt;/p&gt;&lt;br&gt;&lt;p&gt;The Attack_Method is only described as an exploit of a security hole in the foundation's publishing software. However, the attack looks very much like a variation of the popular iframe injection SQL bots, used for malice rather than profit, hinting that this was an SQL injection attack.&lt;/p&gt;&lt;br&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://ap.google.com/article/ALeqM5jEG2MsrwWkzr9_q60h8dojhHsArgD90H3NV01&quot;&gt;Hackers' posts on epilepsy forum cause migraines, seizures&lt;/a&gt; [AP, May 7 2008]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Health&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA</description>      <pubDate>Wed, 16 Jun 2010 15:02:19 -0400</pubDate>      <ddb:attackedentityfield>Health</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>May 11, 2008</ddb:dateoccured>      <ddb:entrytitle>WHID 2008-17: Hackers&amp;#039; posts on epilepsy forum cause migraines, seizures</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Up to now we never registered at WHID an incident that caused physical pain on its victims. Unfortunately, there is always a first. In an attack which gives a whole new dimension to the term &quot;malicious&quot;,hackers recently injected to the Epilepsy Foundation's Web site hundreds of pictures and links to pages with rapidly flashing images.&lt;/p&gt;&#13;&lt;p&gt;The breach caused severe migraines and near-seizure reactions in some site visitors who viewed the images. People with photosensitive epilepsy can get seizures when they're exposed to flickering images, a response also caused by some video games and cartoons.&lt;/p&gt;&#13;&lt;p&gt;The Attack_Method is only described as an exploit of a security hole in the foundation's publishing software. However, the attack looks very much like a variation of the popular iframe injection SQL bots, used for malice rather than profit, hinting that this was an SQL injection attack.&lt;/p&gt;&#13;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://ap.google.com/article/ALeqM5jEG2MsrwWkzr9_q60h8dojhHsArgD90H3NV01&quot;&gt;Hackers' posts on epilepsy forum cause migraines, seizures&lt;/a&gt; [AP, May 7 2008]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Planting of Malware</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2008-17</ddb:whidid>    </item>    <item>      <title>WHID 2008-40: Olympics news sites hit with attacks</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34933</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2008-40: Olympics news sites hit with attacks&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2008-40&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;August 12, 2008&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Planting of Malware&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Like many Asprox bot SQL injection attacks, the one on NDTV.com, a New Delhi TV station's web site has its unique aspects.&lt;/p&gt;&lt;br&gt;&lt;p&gt;First, the attack came at absolutely the wrong time, just when all eyes (and mouse clicks) where turned to the Olympic games in Beijing, the NDTV web site which carried real time information from the games was hacked, greatly extending the infection rate.&lt;/p&gt;&lt;br&gt;&lt;p&gt;In addition, the information was syndicated from a French news agency. While apparently the agency did not have anything to do with the hack, the did catch some fire over the incident as some experts suggested it should help its customers to protect their systems.&lt;/p&gt;&lt;br&gt;&lt;p&gt;More information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.scmagazineus.com/Olympics-news-sites-hit-with-attacks/article/113781/&quot;&gt;SC Magazine&lt;/a&gt;, Aug 12th 2008&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.sophos.com/blogs/gc/g/2008/08/11/olympic-games-coverage-on-news-website-hit-by-sql-injection/&quot;&gt;Graham Cluley's blog entry&lt;/a&gt;, Aug 11th 2008&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Information Services&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;India</description>      <pubDate>Wed, 16 Jun 2010 15:02:19 -0400</pubDate>      <ddb:attackedentityfield>Information Services</ddb:attackedentityfield>      <ddb:attackedentitygeography>India</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>August 12, 2008</ddb:dateoccured>      <ddb:entrytitle>WHID 2008-40: Olympics news sites hit with attacks</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Like many Asprox bot SQL injection attacks, the one on NDTV.com, a New Delhi TV station's web site has its unique aspects.&lt;/p&gt;&#13;&lt;p&gt;First, the attack came at absolutely the wrong time, just when all eyes (and mouse clicks) where turned to the Olympic games in Beijing, the NDTV web site which carried real time information from the games was hacked, greatly extending the infection rate.&lt;/p&gt;&#13;&lt;p&gt;In addition, the information was syndicated from a French news agency. While apparently the agency did not have anything to do with the hack, the did catch some fire over the incident as some experts suggested it should help its customers to protect their systems.&lt;/p&gt;&#13;&lt;p&gt;More information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.scmagazineus.com/Olympics-news-sites-hit-with-attacks/article/113781/&quot;&gt;SC Magazine&lt;/a&gt;, Aug 12th 2008&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.sophos.com/blogs/gc/g/2008/08/11/olympic-games-coverage-on-news-website-hit-by-sql-injection/&quot;&gt;Graham Cluley's blog entry&lt;/a&gt;, Aug 11th 2008&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Planting of Malware</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2008-40</ddb:whidid>    </item>    <item>      <title>WHID 2008-56: Soulja Boy Myspace Hacked</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=35087</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2008-56: Soulja Boy Myspace Hacked&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2008-56&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;September 1, 2008&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Extortion&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;This is a first time a hacking report is a &lt;a href=&quot;http://www.youtube.com/watch?v=iHOCC99UaKs&quot;&gt;video flick&lt;/a&gt;. If, like me, you find it hard to understand, you can read a written summary on this &lt;a href=&quot;http://www.stuff.co.nz/4678287a28.html&quot;&gt;Kiwi site&lt;/a&gt;. I guess that their readers also needed a translation of the speech in the video to English.&lt;/p&gt;&lt;br&gt;&lt;p&gt;In a nutshell, hackers defaced &lt;a href=&quot;http://en.wikipedia.org/wiki/Soulja_Boy_Tell_%27Em&quot;&gt;Soulja Boy's&lt;/a&gt; MySpace page and published his e-mail and YouTube passwords on the net. They demanded $2,500 to give him his web presence back. For an artist that grew our of the Internet this presence is naturally very important, however he is now important enough that his record label was able to contact the different sites to get him his web properties back without paying the money.&lt;/p&gt;&lt;br&gt;&lt;p&gt;In this case I have decided to categorize the attacked entity as Soulja Boy and not MySpace or YouTube, as I used to do in the past. The fact that the attack was against Soulja Boy properties around the web makes him, rather than any technology platform, the attack target.&lt;/p&gt;&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Entertainment&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b></description>      <pubDate>Wed, 16 Jun 2010 14:36:23 -0400</pubDate>      <ddb:attackedentityfield>Entertainment</ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>September 1, 2008</ddb:dateoccured>      <ddb:entrytitle>WHID 2008-56: Soulja Boy Myspace Hacked</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;This is a first time a hacking report is a &lt;a href=&quot;http://www.youtube.com/watch?v=iHOCC99UaKs&quot;&gt;video flick&lt;/a&gt;. If, like me, you find it hard to understand, you can read a written summary on this &lt;a href=&quot;http://www.stuff.co.nz/4678287a28.html&quot;&gt;Kiwi site&lt;/a&gt;. I guess that their readers also needed a translation of the speech in the video to English.&lt;/p&gt;&#13;&#10;&lt;p&gt;In a nutshell, hackers defaced &lt;a href=&quot;http://en.wikipedia.org/wiki/Soulja_Boy_Tell_%27Em&quot;&gt;Soulja Boy's&lt;/a&gt; MySpace page and published his e-mail and YouTube passwords on the net. They demanded $2,500 to give him his web presence back. For an artist that grew our of the Internet this presence is naturally very important, however he is now important enough that his record label was able to contact the different sites to get him his web properties back without paying the money.&lt;/p&gt;&#13;&#10;&lt;p&gt;In this case I have decided to categorize the attacked entity as Soulja Boy and not MySpace or YouTube, as I used to do in the past. The fact that the attack was against Soulja Boy properties around the web makes him, rather than any technology platform, the attack target.&lt;/p></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Extortion</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2008-56</ddb:whidid>    </item>    <item>      <title>WHID 2009-11: Lil Kim Facebook Hacked</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=35093</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2009-11: Lil Kim Facebook Hacked&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2009-11&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;January 26, 2009&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Disinformation&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;I am not sure why rappers web presence is so often hacked. They might be the first generation of artists to use the web, brightly combining great Internet skills with technophobia which leads to basic operational errors. Or it might be the underground nature of the artists that (mis)manage their web presence by themselves.&lt;/p&gt;&lt;br&gt;&lt;p&gt;Lil Kim is joining Soulja Boy in being cyber abuse, or so &lt;a href=&quot;http://hiphop.popcrunch.com/lil-kim-facebook-hacked/&quot;&gt;she claims&lt;/a&gt;, saying that a blog entry calling Naturi Naughton, the actress who portrays her in a new film, &amp;ldquo;tasteless and talentless.&amp;rdquo;, is a fake.&lt;/p&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Entertainment&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA</description>      <pubDate>Wed, 16 Jun 2010 14:23:05 -0400</pubDate>      <ddb:attackedentityfield>Entertainment</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>January 26, 2009</ddb:dateoccured>      <ddb:entrytitle>WHID 2009-11: Lil Kim Facebook Hacked</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;I am not sure why rappers web presence is so often hacked. They might be the first generation of artists to use the web, brightly combining great Internet skills with technophobia which leads to basic operational errors. Or it might be the underground nature of the artists that (mis)manage their web presence by themselves.&lt;/p&gt;&#13;&lt;p&gt;Lil Kim is joining Soulja Boy in being cyber abuse, or so &lt;a href=&quot;http://hiphop.popcrunch.com/lil-kim-facebook-hacked/&quot;&gt;she claims&lt;/a&gt;, saying that a blog entry calling Naturi Naughton, the actress who portrays her in a new film, &amp;ldquo;tasteless and talentless.&amp;rdquo;, is a fake.&lt;/p></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Disinformation</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2009-11</ddb:whidid>    </item>    <item>      <title>WHID 2008-18: Winzipices SQL bot</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34827</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2008-18: Winzipices SQL bot&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2008-18&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;May 11, 2008&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Planting of Malware&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Another member of the wave of SQL injection bots injecting malware inflicting code to web sites.&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://isc.sans.org/diary.html?storyid=4393&quot;&gt;SQL Injection Worm on the Loose&lt;/a&gt; [SANS Internet Storm Center, May 7 2008]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.shadowserver.org/wiki/pmwiki.php?n=Calendar.20080507&quot;&gt;New SQL Injection Attacks and New Malware: winzipices.cn&lt;/a&gt; [ShadowServer, May 7 2008]&lt;/li&gt;&lt;br&gt;&lt;/ul></description>      <pubDate>Wed, 16 Jun 2010 15:02:19 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>May 11, 2008</ddb:dateoccured>      <ddb:entrytitle>WHID 2008-18: Winzipices SQL bot</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Another member of the wave of SQL injection bots injecting malware inflicting code to web sites.&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://isc.sans.org/diary.html?storyid=4393&quot;&gt;SQL Injection Worm on the Loose&lt;/a&gt; [SANS Internet Storm Center, May 7 2008]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.shadowserver.org/wiki/pmwiki.php?n=Calendar.20080507&quot;&gt;New SQL Injection Attacks and New Malware: winzipices.cn&lt;/a&gt; [ShadowServer, May 7 2008]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Planting of Malware</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2008-18</ddb:whidid>    </item>    <item>      <title>WHID 2009-25: Zone-H defaced</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=35184</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2009-25: Zone-H defaced&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2009-25&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;February 13, 2009&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Defacement&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;&lt;img src=&quot;/sites/default/files/images/zone-h_defaced.jpg&quot; alt=&quot;Zone-H Defaced&quot; width=&quot;284&quot; height=&quot;275&quot; align=&quot;right&quot; /&gt;Whenever a defacement appears in WHID we need to explain why. After all isn't Zone-H a better repository of simple defacement. Well, yes, but according to this &lt;a href=&quot;http://www.theregister.co.uk/2009/02/13/zone_h_defaced/&quot;&gt;report &lt;/a&gt;by The Register this time it was Zone-H which was defaced. The defaced site seen on the right, is available &lt;a href=&quot;http://209.85.129.132/search?q=cache:4eY0ub7aCt4J:www.zone-h.org/+zone+h&amp;amp;hl=pl&amp;amp;ct=clnk&amp;amp;cd=1&amp;amp;gl=pl&amp;amp;client=firefox-a&quot;&gt;here&lt;/a&gt;. I am sure it is just a matter of time before we add a WHID defacement to WHID...&lt;/p&gt;&lt;br&gt;&lt;p&gt;The Register article is interesting due to another perspective: when discussing the future of Zone-H, John Leyden writes:&lt;/p&gt;&lt;br&gt;&lt;p&gt;&lt;table border=&quot;0&quot;&gt;&lt;br&gt;&lt;tbody&gt;&lt;br&gt;&lt;tr&gt;&lt;br&gt;&lt;td&gt;But in an age where SQL injection assaults against legitimate sites are used to run drive-by download attacks without leaving any obvious signs of attack, perhaps the recording of blatant web graffiti attacks is no longer as relevant as it once was&lt;/td&gt;&lt;br&gt;&lt;/tr&gt;&lt;br&gt;&lt;/tbody&gt;&lt;br&gt;&lt;/table&gt;&lt;br&gt;&lt;/p&gt;&lt;br&gt;&lt;p&gt;We at the Web Hacking Incident Database try to provide the answer for this new age. I hope we help.&lt;/p&gt;&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Media&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b></description>      <pubDate>Wed, 16 Jun 2010 14:17:29 -0400</pubDate>      <ddb:attackedentityfield>Media</ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>February 13, 2009</ddb:dateoccured>      <ddb:entrytitle>WHID 2009-25: Zone-H defaced</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;&lt;img src=&quot;/sites/default/files/images/zone-h_defaced.jpg&quot; alt=&quot;Zone-H Defaced&quot; width=&quot;284&quot; height=&quot;275&quot; align=&quot;right&quot; /&gt;Whenever a defacement appears in WHID we need to explain why. After all isn't Zone-H a better repository of simple defacement. Well, yes, but according to this &lt;a href=&quot;http://www.theregister.co.uk/2009/02/13/zone_h_defaced/&quot;&gt;report &lt;/a&gt;by The Register this time it was Zone-H which was defaced. The defaced site seen on the right, is available &lt;a href=&quot;http://209.85.129.132/search?q=cache:4eY0ub7aCt4J:www.zone-h.org/+zone+h&amp;amp;hl=pl&amp;amp;ct=clnk&amp;amp;cd=1&amp;amp;gl=pl&amp;amp;client=firefox-a&quot;&gt;here&lt;/a&gt;. I am sure it is just a matter of time before we add a WHID defacement to WHID...&lt;/p&gt;&#13;&#10;&lt;p&gt;The Register article is interesting due to another perspective: when discussing the future of Zone-H, John Leyden writes:&lt;/p&gt;&#13;&#10;&lt;p&gt;&lt;table border=&quot;0&quot;&gt;&#13;&#10;&lt;tbody&gt;&#13;&#10;&lt;tr&gt;&#13;&#10;&lt;td&gt;But in an age where SQL injection assaults against legitimate sites are used to run drive-by download attacks without leaving any obvious signs of attack, perhaps the recording of blatant web graffiti attacks is no longer as relevant as it once was&lt;/td&gt;&#13;&#10;&lt;/tr&gt;&#13;&#10;&lt;/tbody&gt;&#13;&#10;&lt;/table&gt;&#13;&#10;&lt;/p&gt;&#13;&#10;&lt;p&gt;We at the Web Hacking Incident Database try to provide the answer for this new age. I hope we help.&lt;/p></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Defacement</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2009-25</ddb:whidid>    </item>    <item>      <title>WHID 2008-19: OSU breach raises fears of ID theft</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34833</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2008-19: OSU breach raises fears of ID theft&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2008-19&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;May 19, 2008&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;At the Oklahoma State Universitiy (OSU) a security breach has exposed the names, addresses and Social Security numbers of 70,000 students, faculty and staff who bought parking and transit services permits in the past six years. The university failed to report the incident to affected individuals for two months after it was detected.&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.cr80news.com/news/2008/05/16/osu-breach-raises-fears-of-id-theft/&quot;&gt;OSU breach raises fears of ID theft&lt;/a&gt; [cr80 News, May 16 2008]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Education&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA</description>      <pubDate>Wed, 16 Jun 2010 15:02:19 -0400</pubDate>      <ddb:attackedentityfield>Education</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>May 19, 2008</ddb:dateoccured>      <ddb:entrytitle>WHID 2008-19: OSU breach raises fears of ID theft</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;At the Oklahoma State Universitiy (OSU) a security breach has exposed the names, addresses and Social Security numbers of 70,000 students, faculty and staff who bought parking and transit services permits in the past six years. The university failed to report the incident to affected individuals for two months after it was detected.&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.cr80news.com/news/2008/05/16/osu-breach-raises-fears-of-id-theft/&quot;&gt;OSU breach raises fears of ID theft&lt;/a&gt; [cr80 News, May 16 2008]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2008-19</ddb:whidid>    </item>    <item>      <title>WHID 2009-24: New Phishing Attacks Combine Wildcard DNS and XSS</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=35178</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2009-24: New Phishing Attacks Combine Wildcard DNS and XSS&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2009-24&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;February 10, 2009&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Phishing&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Netcraft, one of the leading authorities on phising research, &lt;a href=&quot;http://news.netcraft.com/archives/2009/02/17/new_phishing_attacks_combine_wildcard_dns_and_xss.html&quot;&gt;reports&lt;/a&gt; a Phishing scam that involves XSS.&lt;/p&gt;&lt;br&gt;&lt;p&gt;The scam exploits an XSS vulnerability in &lt;a href=&quot;http://www.scripts24.com/iredirector/subdomain/index.php&quot;&gt;iRedirector&lt;/a&gt;, a software used to map sub-domains into paths on the site, in order to hijack domains and use them as Phishing targets. Since iRedirector enables virtually any sub domain to be defined, the attacker can now create an endless number of combinations of domain names built to fool users and web filters alike.&lt;/p&gt;&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Various&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;Various&lt;br&gt;&lt;b&gt;Attacked System Technology: &lt;/b&gt;iRedorector</description>      <pubDate>Wed, 16 Jun 2010 14:17:29 -0400</pubDate>      <ddb:attackedentityfield>Various</ddb:attackedentityfield>      <ddb:attackedentitygeography>Various</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology>iRedorector</ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>February 10, 2009</ddb:dateoccured>      <ddb:entrytitle>WHID 2009-24: New Phishing Attacks Combine Wildcard DNS and XSS</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Netcraft, one of the leading authorities on phising research, &lt;a href=&quot;http://news.netcraft.com/archives/2009/02/17/new_phishing_attacks_combine_wildcard_dns_and_xss.html&quot;&gt;reports&lt;/a&gt; a Phishing scam that involves XSS.&lt;/p&gt;&#13;&#10;&lt;p&gt;The scam exploits an XSS vulnerability in &lt;a href=&quot;http://www.scripts24.com/iredirector/subdomain/index.php&quot;&gt;iRedirector&lt;/a&gt;, a software used to map sub-domains into paths on the site, in order to hijack domains and use them as Phishing targets. Since iRedirector enables virtually any sub domain to be defined, the attacker can now create an endless number of combinations of domain names built to fool users and web filters alike.&lt;/p></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Phishing</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2009-24</ddb:whidid>    </item>    <item>      <title>WHID 2009-23: Miley Cyrus Twitter Account Hit By Sex-Obsessed Hacker</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=35173</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2009-23: Miley Cyrus Twitter Account Hit By Sex-Obsessed Hacker&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2009-23&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;February 17, 2009&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;It is Twitter again, it is a celebrity again. Why don't they keep their password to themselves. This &lt;a href=&quot;http://www.entertainmentwise.com/news/47172/miley-cyrus-twitter-account-hit-by-sexobsessed-hacker&quot;&gt;incident &lt;/a&gt;is even uglier as the attacker posted obscene content on the Twitter account of the 16 years old actress Miley Cyrus. This is not the first attack targeting Miley Cyrus. As r&lt;a href=&quot;http://www.xiom.com/whid/2008/60/miley_cyrus_myspace_gmail&quot;&gt;eported by WHID&lt;/a&gt;, her personal G-mail account was hacked last year and personal pictures were stolen and published online.&lt;/p&gt;&lt;br&gt;&lt;p&gt;We assume that he just guessed the password. Was it a trivial one? did he find a way to brute force it? Or was it something entirely different like yet another Twitter CSRF bug? time will tell.&lt;/p&gt;&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Web 2.0&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA</description>      <pubDate>Wed, 16 Jun 2010 14:17:29 -0400</pubDate>      <ddb:attackedentityfield>Web 2.0</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>February 17, 2009</ddb:dateoccured>      <ddb:entrytitle>WHID 2009-23: Miley Cyrus Twitter Account Hit By Sex-Obsessed Hacker</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;It is Twitter again, it is a celebrity again. Why don't they keep their password to themselves. This &lt;a href=&quot;http://www.entertainmentwise.com/news/47172/miley-cyrus-twitter-account-hit-by-sexobsessed-hacker&quot;&gt;incident &lt;/a&gt;is even uglier as the attacker posted obscene content on the Twitter account of the 16 years old actress Miley Cyrus. This is not the first attack targeting Miley Cyrus. As r&lt;a href=&quot;http://www.xiom.com/whid/2008/60/miley_cyrus_myspace_gmail&quot;&gt;eported by WHID&lt;/a&gt;, her personal G-mail account was hacked last year and personal pictures were stolen and published online.&lt;/p&gt;&#13;&#10;&lt;p&gt;We assume that he just guessed the password. Was it a trivial one? did he find a way to brute force it? Or was it something entirely different like yet another Twitter CSRF bug? time will tell.&lt;/p></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2009-23</ddb:whidid>    </item>    <item>      <title>WHID 2008-20: XSS Worm At Justin.tv Affects 2525 Profiles</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34838</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2008-20: XSS Worm At Justin.tv Affects 2525 Profiles&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2008-20&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;July 16, 2008&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Worm&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;A proof of concept XSS worm crawled justin.tv, a popular lifecasting platform. The warm succeeded in planting a self replicating code on 2525 accounts in less than 24 hours before the vulnerability was fixed.&lt;/p&gt;&lt;br&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://cyberinsecure.com/xss-worm-at-justintv-affects-2525-profiles/&quot;&gt;XSS Worm At Justin.tv Affects 2525 Profiles&lt;/a&gt; [CyberInsecure, Jul 15 2008]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Web 2.0</description>      <pubDate>Wed, 16 Jun 2010 15:02:19 -0400</pubDate>      <ddb:attackedentityfield>Web 2.0</ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>July 16, 2008</ddb:dateoccured>      <ddb:entrytitle>WHID 2008-20: XSS Worm At Justin.tv Affects 2525 Profiles</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;A proof of concept XSS worm crawled justin.tv, a popular lifecasting platform. The warm succeeded in planting a self replicating code on 2525 accounts in less than 24 hours before the vulnerability was fixed.&lt;/p&gt;&#13;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://cyberinsecure.com/xss-worm-at-justintv-affects-2525-profiles/&quot;&gt;XSS Worm At Justin.tv Affects 2525 Profiles&lt;/a&gt; [CyberInsecure, Jul 15 2008]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Worm</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2008-20</ddb:whidid>    </item>    <item>      <title>WHID 2008-39: Hacker compromises a south african political party web site</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34928</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2008-39: Hacker compromises a south african political party web site&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2008-39&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;August 7, 2008&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Planting of Malware&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;The South African Democratic Alliance party's web site seems like another random victim of the Asprox family of bots. This specific incident demonstrates several issues:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;Aprox successfully attacks organizations that should really know better.&lt;/li&gt;&lt;br&gt;&lt;li&gt;While most known cases of Asprox attacks result in planting of malware on the web site, since this is easily detected by malware search services, the very brutal injection used by Asprox probably takes down more sites than it infects with malware.&lt;/li&gt;&lt;br&gt;&lt;li&gt;According to one comment, the site used an outdated version of WordPress, stressing again the problem with not upgrading in a timely manner, especially open source software.&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;p&gt;More information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.mg.co.za/article/2008-08-15-hacker-compromises-da-website&quot;&gt;Mail &amp;amp; Guardian&lt;/a&gt;, Aug 15th 2008&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;Russia&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Government&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;South Africa&lt;br&gt;&lt;b&gt;Attacked System Technology: &lt;/b&gt;WordPress</description>      <pubDate>Wed, 16 Jun 2010 15:02:19 -0400</pubDate>      <ddb:attackedentityfield>Government</ddb:attackedentityfield>      <ddb:attackedentitygeography>South Africa</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology>WordPress</ddb:attackedsystemtechnology>      <ddb:attacksourcegeography>Russia</ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>August 7, 2008</ddb:dateoccured>      <ddb:entrytitle>WHID 2008-39: Hacker compromises a south african political party web site</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;The South African Democratic Alliance party's web site seems like another random victim of the Asprox family of bots. This specific incident demonstrates several issues:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;Aprox successfully attacks organizations that should really know better.&lt;/li&gt;&#13;&lt;li&gt;While most known cases of Asprox attacks result in planting of malware on the web site, since this is easily detected by malware search services, the very brutal injection used by Asprox probably takes down more sites than it infects with malware.&lt;/li&gt;&#13;&lt;li&gt;According to one comment, the site used an outdated version of WordPress, stressing again the problem with not upgrading in a timely manner, especially open source software.&lt;/li&gt;&#13;&lt;/ul&gt;&#13;&lt;p&gt;More information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.mg.co.za/article/2008-08-15-hacker-compromises-da-website&quot;&gt;Mail &amp;amp; Guardian&lt;/a&gt;, Aug 15th 2008&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Planting of Malware</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2008-39</ddb:whidid>    </item>    <item>      <title>WHID 2008-38: DNSChanger Trojans v4.0</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34923</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2008-38: DNSChanger Trojans v4.0&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2008-38&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;December 4, 2008&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Fraud&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;The DNSchanger Trojan uses different methods to manipulate the DNS lookup of the victim. One of the most malicious techniques is using CSRF to attack the ADSL or cable router and modify its DNS tables.&lt;/p&gt;&lt;br&gt;&lt;p&gt;More Information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.avertlabs.com/research/blog/index.php/2008/12/04/dnschanger-trojans-v40&quot;&gt;McAfee: DNSChanger Trojans v4.0&lt;/a&gt;, Dec 4th 2008&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Various</description>      <pubDate>Wed, 16 Jun 2010 15:02:19 -0400</pubDate>      <ddb:attackedentityfield>Various</ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>December 4, 2008</ddb:dateoccured>      <ddb:entrytitle>WHID 2008-38: DNSChanger Trojans v4.0</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;The DNSchanger Trojan uses different methods to manipulate the DNS lookup of the victim. One of the most malicious techniques is using CSRF to attack the ADSL or cable router and modify its DNS tables.&lt;/p&gt;&#13;&lt;p&gt;More Information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.avertlabs.com/research/blog/index.php/2008/12/04/dnschanger-trojans-v40&quot;&gt;McAfee: DNSChanger Trojans v4.0&lt;/a&gt;, Dec 4th 2008&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Fraud</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2008-38</ddb:whidid>    </item>    <item>      <title>WHID 2008-21: Information about organ and tissue donors open to all</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34844</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2008-21: Information about organ and tissue donors open to all&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2008-21&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;July 20, 2008&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;The Agency for Health Care Administration (AHCA) Florida's database of organ and tissue donor registry was open to the public due to an unspecified software glitch. Personal details of 55,000 people, including name, address, date of birth, driver license number and social security number where exposed.&lt;/p&gt;&lt;br&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.fdhc.state.fl.us/Organ/faq.htm&quot;&gt;AHCA Incident Faq&lt;/a&gt; [AHCA, ]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.fdhc.state.fl.us/Executive/Communications/Press_Releases/pdf/Organ_Tissue7708.pdf&quot;&gt;AHCA Incident PR&lt;/a&gt; [AHCA, Jul 7 2008]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.examiner.com/a-1476582~Breach_in_Fla__donor_registry_may_have_exposed_IDs.html&quot;&gt;Breach in Fla. donor registry may have exposed IDs&lt;/a&gt; [Associated Press, Jul 7 2008]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Government&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA</description>      <pubDate>Wed, 16 Jun 2010 15:02:19 -0400</pubDate>      <ddb:attackedentityfield>Government</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>July 20, 2008</ddb:dateoccured>      <ddb:entrytitle>WHID 2008-21: Information about organ and tissue donors open to all</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;The Agency for Health Care Administration (AHCA) Florida's database of organ and tissue donor registry was open to the public due to an unspecified software glitch. Personal details of 55,000 people, including name, address, date of birth, driver license number and social security number where exposed.&lt;/p&gt;&#13;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.fdhc.state.fl.us/Organ/faq.htm&quot;&gt;AHCA Incident Faq&lt;/a&gt; [AHCA, ]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.fdhc.state.fl.us/Executive/Communications/Press_Releases/pdf/Organ_Tissue7708.pdf&quot;&gt;AHCA Incident PR&lt;/a&gt; [AHCA, Jul 7 2008]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.examiner.com/a-1476582~Breach_in_Fla__donor_registry_may_have_exposed_IDs.html&quot;&gt;Breach in Fla. donor registry may have exposed IDs&lt;/a&gt; [Associated Press, Jul 7 2008]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2008-21</ddb:whidid>    </item>    <item>      <title>WHID 2009-12: Embassy of India in Spain found serving remote malware through iFrame attack</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=35098</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2009-12: Embassy of India in Spain found serving remote malware through iFrame attack&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2009-12&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;January 26, 2009&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Planting of Malware&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Ismael Valenzuela sent us &lt;a href=&quot;http://blog.ismaelvalenzuela.com/2009/01/26/embassy-of-india-in-spain-found-serving-remote-malware-through-iframe-attack/&quot;&gt;a story&lt;/a&gt; about yet another malware through iFrame serving site. This time it is an official one, belonging to the Indian government official branch in Spain - it's embassy.&lt;/p&gt;&lt;br&gt;&lt;p&gt;We can hardly include every malware service site in WHID, after all there are hundred of thousands, if not millions, of those. Why pick on the Indian embassy in Spain? One good reason is that we finally got in an input from a reader and wanted to honor the event and include the incident. But there is another more important reason.&lt;/p&gt;&lt;br&gt;&lt;p&gt;First, &lt;a href=&quot;http://www.theregister.co.uk/2008/01/23/embassy_sites_serve_malware/&quot;&gt;hacked embassy sites are becoming a major issue&lt;/a&gt; which points to a much larger issue: cyber crime is endangering the Internet as we know it. While we come to rely on the web to provide us with all the information and services that we need, we do not have the tools to make it a safe place, and embassy web sites are a good example.&lt;/p&gt;&lt;br&gt;&lt;p&gt;Practically the only way to provide sufficient security to a web site is not to have it in the first place. Instead small organizations must rely on the services of huge brokers, such as Amazon, eBay or Google sites. However not everyone can use this services. Embassies are a good example as they need to be &quot;doubly localized&quot; for both the originating and target countries which makes it nearly impossible to create a uniform service for them. Therefore even embassies of larger countries need to create small home made and insecure web sites, as they need to adjust their site content, language and site look to the local community served.&lt;/p&gt;&lt;br&gt;&lt;p&gt;&lt;a href=&quot;http://blog.trendmicro.com/embassy-site-attack-reveals-other-compromised-sites/&quot;&gt;Thechnical analysis&lt;/a&gt; of the planted malware was done by Trend Micro.&lt;/p&gt;&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Government&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b></description>      <pubDate>Wed, 16 Jun 2010 14:23:05 -0400</pubDate>      <ddb:attackedentityfield>Government</ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>January 26, 2009</ddb:dateoccured>      <ddb:entrytitle>WHID 2009-12: Embassy of India in Spain found serving remote malware through iFrame attack</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Ismael Valenzuela sent us &lt;a href=&quot;http://blog.ismaelvalenzuela.com/2009/01/26/embassy-of-india-in-spain-found-serving-remote-malware-through-iframe-attack/&quot;&gt;a story&lt;/a&gt; about yet another malware through iFrame serving site. This time it is an official one, belonging to the Indian government official branch in Spain - it's embassy.&lt;/p&gt;&#13;&#10;&lt;p&gt;We can hardly include every malware service site in WHID, after all there are hundred of thousands, if not millions, of those. Why pick on the Indian embassy in Spain? One good reason is that we finally got in an input from a reader and wanted to honor the event and include the incident. But there is another more important reason.&lt;/p&gt;&#13;&#10;&lt;p&gt;First, &lt;a href=&quot;http://www.theregister.co.uk/2008/01/23/embassy_sites_serve_malware/&quot;&gt;hacked embassy sites are becoming a major issue&lt;/a&gt; which points to a much larger issue: cyber crime is endangering the Internet as we know it. While we come to rely on the web to provide us with all the information and services that we need, we do not have the tools to make it a safe place, and embassy web sites are a good example.&lt;/p&gt;&#13;&#10;&lt;p&gt;Practically the only way to provide sufficient security to a web site is not to have it in the first place. Instead small organizations must rely on the services of huge brokers, such as Amazon, eBay or Google sites. However not everyone can use this services. Embassies are a good example as they need to be &quot;doubly localized&quot; for both the originating and target countries which makes it nearly impossible to create a uniform service for them. Therefore even embassies of larger countries need to create small home made and insecure web sites, as they need to adjust their site content, language and site look to the local community served.&lt;/p&gt;&#13;&#10;&lt;p&gt;&lt;a href=&quot;http://blog.trendmicro.com/embassy-site-attack-reveals-other-compromised-sites/&quot;&gt;Thechnical analysis&lt;/a&gt; of the planted malware was done by Trend Micro.&lt;/p></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Planting of Malware</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2009-12</ddb:whidid>    </item>    <item>      <title>WHID 2009-22: Federal Travel Booking Site Spreads Malware (Updated)</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=35167</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2009-22: Federal Travel Booking Site Spreads Malware (Updated)&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2009-22&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;February 11, 2009&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Planting of Malware&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;&lt;em&gt;&lt;strong&gt;Updated (Feb 22&lt;sup&gt;nd&lt;/sup&gt; 2009)&lt;/strong&gt;&lt;/em&gt; - the Washington Post &lt;a href=&quot;http://voices.washingtonpost.com/securityfix/2009/02/travel-booking_site_for_federa.html&quot;&gt;updates &lt;/a&gt;that the hack exploited a problem with the default configuration of the authentication module used for authenticating remote administrators. As a result we categorized this incident under &quot;insufficient authentication&quot; and &quot;misconfiguration&quot;.&lt;/p&gt;&lt;br&gt;&lt;hr /&gt;&lt;br&gt;&lt;p&gt;Whenever we include a site inflicted with malware in WHID we need to explain why this one is worthy of WHID, after hundreds of thousands of web sites are planted with malware annually.&lt;/p&gt;&lt;br&gt;&lt;p&gt;The &lt;a href=&quot;http://voices.washingtonpost.com/securityfix/2009/02/travel-booking_site_for_federa.html&quot;&gt;Washington Post&lt;/a&gt; report about govtrip.com spreading malware is unique because this is an official US General Services Administration (GSA)&amp;nbsp; web site and many US federal departments employees are required to reserve travel through it. In addition, the site is run by a major defense contractor, Northrop Grumman, who you would think would know better. How secure are their defense projects when it comes to application security?&lt;/p&gt;&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Retail&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA</description>      <pubDate>Wed, 16 Jun 2010 14:23:05 -0400</pubDate>      <ddb:attackedentityfield>Retail</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>February 11, 2009</ddb:dateoccured>      <ddb:entrytitle>WHID 2009-22: Federal Travel Booking Site Spreads Malware (Updated)</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;&lt;em&gt;&lt;strong&gt;Updated (Feb 22&lt;sup&gt;nd&lt;/sup&gt; 2009)&lt;/strong&gt;&lt;/em&gt; - the Washington Post &lt;a href=&quot;http://voices.washingtonpost.com/securityfix/2009/02/travel-booking_site_for_federa.html&quot;&gt;updates &lt;/a&gt;that the hack exploited a problem with the default configuration of the authentication module used for authenticating remote administrators. As a result we categorized this incident under &quot;insufficient authentication&quot; and &quot;misconfiguration&quot;.&lt;/p&gt;&#13;&#10;&lt;hr /&gt;&#13;&#10;&lt;p&gt;Whenever we include a site inflicted with malware in WHID we need to explain why this one is worthy of WHID, after hundreds of thousands of web sites are planted with malware annually.&lt;/p&gt;&#13;&#10;&lt;p&gt;The &lt;a href=&quot;http://voices.washingtonpost.com/securityfix/2009/02/travel-booking_site_for_federa.html&quot;&gt;Washington Post&lt;/a&gt; report about govtrip.com spreading malware is unique because this is an official US General Services Administration (GSA)&amp;nbsp; web site and many US federal departments employees are required to reserve travel through it. In addition, the site is run by a major defense contractor, Northrop Grumman, who you would think would know better. How secure are their defense projects when it comes to application security?&lt;/p></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Planting of Malware</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2009-22</ddb:whidid>    </item>    <item>      <title>WHID 2008-22: Hacker changes news releases on sheriff&amp;#039;s Web site</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34849</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2008-22: Hacker changes news releases on sheriff&amp;#039;s Web site&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2008-22&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;July 21, 2008&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Defacement&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt; A targeted defacement that modified two specific press releases to ridicule the local government.&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.dailybulletin.com/ci_9668183&quot;&gt;Nosy hacker alters sheriff's news releases&lt;/a&gt; [The Daily Bulletin, Jun 22 2008]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Security &amp;amp; Law Enforcement&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA</description>      <pubDate>Wed, 16 Jun 2010 15:02:19 -0400</pubDate>      <ddb:attackedentityfield>Security &amp;amp; Law Enforcement</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>July 21, 2008</ddb:dateoccured>      <ddb:entrytitle>WHID 2008-22: Hacker changes news releases on sheriff&amp;#039;s Web site</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt; A targeted defacement that modified two specific press releases to ridicule the local government.&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.dailybulletin.com/ci_9668183&quot;&gt;Nosy hacker alters sheriff's news releases&lt;/a&gt; [The Daily Bulletin, Jun 22 2008]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Defacement</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2008-22</ddb:whidid>    </item>    <item>      <title>WHID 2009-21: This Time Uno is after the Herald Tribute</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=35162</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2009-21: This Time Uno is after the Herald Tribute&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2009-21&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;February 17, 2009&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;I must admit that Uno, the Romanian hacker behind a series of intrusions in recent days is a bit of a cheat for the Web Hacking Incident Database. We usually do not report vulnerabilities that where not exploited. While we understand their importance, they do not fall under the &lt;a href=&quot;/whid-faq&quot;&gt;criteria &lt;/a&gt;set for WHID. For now we list them in a &lt;a href=&quot;/research-web-site-vuln&quot;&gt;separate page&lt;/a&gt;, waiting for a place to be files in.&lt;/p&gt;&lt;br&gt;&lt;p&gt;Uno presents a dilemma: he finds a vulnerability, exploits it to a limit and publish the results. Therefore the incident does not have a sizable outcome and not damage is done, but nevertheless it is interesting. We are not the only one to note that. Kasperski stressed the point the no data was actually compromised in their &lt;a href=&quot;http://www.kaspersky.com/news?id=207575753&quot;&gt;response &lt;/a&gt;to the event. So should we add it to WHID as an incident? should we skip it as just a vulnerability? for now we put them in.&lt;/p&gt;&lt;br&gt;&lt;p&gt;So what is Uno's mischeif this time? &lt;a href=&quot;http://hackersblog.org/2009/02/17/international-herald-tribune-nytimescom-sqlinjection/&quot;&gt;This time&lt;/a&gt; it is the International Herald Tribune Uno is after. The impact of this attack, if carried out by a malicious hacker might have been profound as it seems that Uno got access to user name and passwords of editors and contributors, posibily enabling a malicious hacker to publish information on their behalf on this very prestigious newspaper.&lt;/p&gt;&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;Romania&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Media&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA</description>      <pubDate>Wed, 16 Jun 2010 14:23:05 -0400</pubDate>      <ddb:attackedentityfield>Media</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography>Romania</ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>February 17, 2009</ddb:dateoccured>      <ddb:entrytitle>WHID 2009-21: This Time Uno is after the Herald Tribute</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;I must admit that Uno, the Romanian hacker behind a series of intrusions in recent days is a bit of a cheat for the Web Hacking Incident Database. We usually do not report vulnerabilities that where not exploited. While we understand their importance, they do not fall under the &lt;a href=&quot;/whid-faq&quot;&gt;criteria &lt;/a&gt;set for WHID. For now we list them in a &lt;a href=&quot;/research-web-site-vuln&quot;&gt;separate page&lt;/a&gt;, waiting for a place to be files in.&lt;/p&gt;&#13;&#10;&lt;p&gt;Uno presents a dilemma: he finds a vulnerability, exploits it to a limit and publish the results. Therefore the incident does not have a sizable outcome and not damage is done, but nevertheless it is interesting. We are not the only one to note that. Kasperski stressed the point the no data was actually compromised in their &lt;a href=&quot;http://www.kaspersky.com/news?id=207575753&quot;&gt;response &lt;/a&gt;to the event. So should we add it to WHID as an incident? should we skip it as just a vulnerability? for now we put them in.&lt;/p&gt;&#13;&#10;&lt;p&gt;So what is Uno's mischeif this time? &lt;a href=&quot;http://hackersblog.org/2009/02/17/international-herald-tribune-nytimescom-sqlinjection/&quot;&gt;This time&lt;/a&gt; it is the International Herald Tribune Uno is after. The impact of this attack, if carried out by a malicious hacker might have been profound as it seems that Uno got access to user name and passwords of editors and contributors, posibily enabling a malicious hacker to publish information on their behalf on this very prestigious newspaper.&lt;/p></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2009-21</ddb:whidid>    </item>    <item>      <title>WHID 2008-23: Sony PlayStation</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34854</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2008-23: Sony PlayStation&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2008-23&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;July 21, 2008&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Planting of Malware&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Yet another iframe injection in a very prominent web site, proving yet again that nobody is immune.&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.thetechherald.com/article.php/200827/1393/Sony-PlayStation-s-site-hit-with-SQL-Injection&quot;&gt;Sony PlayStation&lt;br&gt;&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Retail&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA</description>      <pubDate>Wed, 16 Jun 2010 15:02:19 -0400</pubDate>      <ddb:attackedentityfield>Retail</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>July 21, 2008</ddb:dateoccured>      <ddb:entrytitle>WHID 2008-23: Sony PlayStation</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Yet another iframe injection in a very prominent web site, proving yet again that nobody is immune.&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.thetechherald.com/article.php/200827/1393/Sony-PlayStation-s-site-hit-with-SQL-Injection&quot;&gt;Sony PlayStation&#13;&lt;/a&gt;&lt;/li&gt;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Planting of Malware</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2008-23</ddb:whidid>    </item>    <item>      <title>WHID 2009-20: BitDefender joins Kasperski on the Breached side</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=35156</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2009-20: BitDefender joins Kasperski on the Breached side&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2009-20&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;February 9, 2009&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Uno, the Romanian hacker responsible for &lt;a href=&quot;/whid/2009/19/kaspersky_site_breached&quot;&gt;penetrating the Kasperski web site&lt;/a&gt;, reported &lt;a href=&quot;http://hackersblog.org/2009/02/09/hackedbitdefender-portugal-exposes-sensitive-customer-data/&quot;&gt;repeating the trick&lt;/a&gt; also on the web site of the Polish distributor of BitDefender, another anti-virus software vendor.&lt;/p&gt;&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;Romania&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Technology&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b></description>      <pubDate>Wed, 16 Jun 2010 14:23:05 -0400</pubDate>      <ddb:attackedentityfield>Technology</ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography>Romania</ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>February 9, 2009</ddb:dateoccured>      <ddb:entrytitle>WHID 2009-20: BitDefender joins Kasperski on the Breached side</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Uno, the Romanian hacker responsible for &lt;a href=&quot;/whid/2009/19/kaspersky_site_breached&quot;&gt;penetrating the Kasperski web site&lt;/a&gt;, reported &lt;a href=&quot;http://hackersblog.org/2009/02/09/hackedbitdefender-portugal-exposes-sensitive-customer-data/&quot;&gt;repeating the trick&lt;/a&gt; also on the web site of the Polish distributor of BitDefender, another anti-virus software vendor.&lt;/p></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2009-20</ddb:whidid>    </item>    <item>      <title>WHID 2008-57:  Craigslist&amp;#039;s Battle Against Spammers</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=35104</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2008-57:  Craigslist&amp;#039;s Battle Against Spammers&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2008-57&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;May 22, 2008&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Link Spam&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Insufficient Anti-Automation is fat becoming the #1 threat to web sites. Since Captcha has been proved practically &lt;a href=&quot;http://en.wikipedia.org/wiki/Captcha#Circumvention&quot;&gt;useless&lt;/a&gt;, especially when there is a financial gain from automating access to the site, sites are pretty much defenceless against harmful automation. &lt;a href=&quot;http://techdirt.com/articles/20080523/0327151211.shtml&quot;&gt;Techdirt's story&lt;/a&gt; about Craigslist losing the battle against automation tool is a very good example of this serious problem.&lt;/p&gt;&lt;br&gt;&lt;p&gt;Read the comments, they are enlightening. As usual, one of the problem when spam is involved is defining if and what is a wrong doing and what is a  valid action. Some commenters say that Craigslist has become useless due to the spam, while others say that Craiglist is the worst censors on the Internet not letting small time businesses work. Other argue about whether this is a crime or not. 132 comments, and they keep coming 8 months after the article has been published.&lt;/p&gt;&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Information Services&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b></description>      <pubDate>Wed, 16 Jun 2010 14:31:17 -0400</pubDate>      <ddb:attackedentityfield>Information Services</ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>May 22, 2008</ddb:dateoccured>      <ddb:entrytitle>WHID 2008-57:  Craigslist&amp;#039;s Battle Against Spammers</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Insufficient Anti-Automation is fat becoming the #1 threat to web sites. Since Captcha has been proved practically &lt;a href=&quot;http://en.wikipedia.org/wiki/Captcha#Circumvention&quot;&gt;useless&lt;/a&gt;, especially when there is a financial gain from automating access to the site, sites are pretty much defenceless against harmful automation. &lt;a href=&quot;http://techdirt.com/articles/20080523/0327151211.shtml&quot;&gt;Techdirt's story&lt;/a&gt; about Craigslist losing the battle against automation tool is a very good example of this serious problem.&lt;/p&gt;&#13;&#10;&lt;p&gt;Read the comments, they are enlightening. As usual, one of the problem when spam is involved is defining if and what is a wrong doing and what is a  valid action. Some commenters say that Craigslist has become useless due to the spam, while others say that Craiglist is the worst censors on the Internet not letting small time businesses work. Other argue about whether this is a crime or not. 132 comments, and they keep coming 8 months after the article has been published.&lt;/p></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Link Spam</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2008-57</ddb:whidid>    </item>    <item>      <title>WHID 2008-58: New Orkut Worm in Brazil</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=35149</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2008-58: New Orkut Worm in Brazil&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2008-58&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;October 4, 2008&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Planting of Malware&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;XSSed &lt;a href=&quot;http://www.xssed.com/news/77/New_Orkut_XSS_worm_by_Brazilian_web_security_group/&quot;&gt;reports &lt;/a&gt;another XSS worm in Orkut. Since Orkut is big in Brazil, it is quite natural that a Brazilian group created the worm.&lt;/p&gt;&lt;br&gt;&lt;p&gt;I have used this occasion to sort out worms reporting in WHID.&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;A worm is now considered an Attack_Method rather than an outcome. If nothing else, the outcome of a worm is &quot;planting of malware&quot;: itself.&lt;/li&gt;&lt;br&gt;&lt;li&gt;I have added a &quot;Web 2.0&quot; organization type as many of the XSS worms infect Web 2.0 sites.&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;Brazil&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Web 2.0&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b></description>      <pubDate>Wed, 16 Jun 2010 14:30:01 -0400</pubDate>      <ddb:attackedentityfield>Web 2.0</ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography>Brazil</ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>October 4, 2008</ddb:dateoccured>      <ddb:entrytitle>WHID 2008-58: New Orkut Worm in Brazil</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;XSSed &lt;a href=&quot;http://www.xssed.com/news/77/New_Orkut_XSS_worm_by_Brazilian_web_security_group/&quot;&gt;reports &lt;/a&gt;another XSS worm in Orkut. Since Orkut is big in Brazil, it is quite natural that a Brazilian group created the worm.&lt;/p&gt;&#13;&#10;&lt;p&gt;I have used this occasion to sort out worms reporting in WHID.&lt;/p&gt;&#13;&#10;&lt;ul&gt;&#13;&#10;&lt;li&gt;A worm is now considered an Attack_Method rather than an outcome. If nothing else, the outcome of a worm is &quot;planting of malware&quot;: itself.&lt;/li&gt;&#13;&#10;&lt;li&gt;I have added a &quot;Web 2.0&quot; organization type as many of the XSS worms infect Web 2.0 sites.&lt;/li&gt;&#13;&#10;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Planting of Malware</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2008-58</ddb:whidid>    </item>    <item>      <title>WHID 2007-89: The big TJX hack</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34916</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2007-89: The big TJX hack&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2007-89&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;December 29, 2008&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Credit Card Leakage&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;&lt;em&gt;&lt;strong&gt;Update (January 12&lt;sup&gt;th&lt;/sup&gt; 2009)&lt;/strong&gt;&lt;/em&gt; An Ukrainian hacker who who was a member of the TJX hack ring &lt;a href=&quot;http://www.theregister.co.uk/2009/01/08/hacker_30yr_jail_stretch_turkey/&quot;&gt;was sentenced to 30 years in jail by a Turkish court&lt;/a&gt;. According to investigation papers Maksym Yastremskiy made approximately 11 million dollars from the hack!&lt;/p&gt;&lt;br&gt;&lt;hr /&gt;&lt;br&gt;&lt;p&gt;The TJX breach is one of most publicized hacking incident in recent years. However, until now it was not part of the Web Hacking Incidents Database. And for a good reason: early report described the hack as a war driving hack, in which the attackers drive around and find a wireless network not properly secured.&lt;/p&gt;&lt;br&gt;&lt;p&gt;However new information from the trial of the identity theft ring leader Albert Gonzalez, reveals that in order to penetrate TJX data center from the captured end points, the hackers employed different techniques including password sniffing and SQL injection. The later justifies getting the TJX incident for the 1st time into WHID.&lt;/p&gt;&lt;br&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.networkworld.com/news/2008/080608-id-theft-ring-attacked-retailers.html?page=1&quot;&gt;Network World&lt;/a&gt;, June 8th 2008&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Retail&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA</description>      <pubDate>Thu, 17 Jun 2010 18:22:11 -0400</pubDate>      <ddb:attackedentityfield>Retail</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>December 29, 2008</ddb:dateoccured>      <ddb:entrytitle>WHID 2007-89: The big TJX hack</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;&lt;em&gt;&lt;strong&gt;Update (January 12&lt;sup&gt;th&lt;/sup&gt; 2009)&lt;/strong&gt;&lt;/em&gt; An Ukrainian hacker who who was a member of the TJX hack ring &lt;a href=&quot;http://www.theregister.co.uk/2009/01/08/hacker_30yr_jail_stretch_turkey/&quot;&gt;was sentenced to 30 years in jail by a Turkish court&lt;/a&gt;. According to investigation papers Maksym Yastremskiy made approximately 11 million dollars from the hack!&lt;/p&gt;&#13;&lt;hr /&gt;&#13;&lt;p&gt;The TJX breach is one of most publicized hacking incident in recent years. However, until now it was not part of the Web Hacking Incidents Database. And for a good reason: early report described the hack as a war driving hack, in which the attackers drive around and find a wireless network not properly secured.&lt;/p&gt;&#13;&lt;p&gt;However new information from the trial of the identity theft ring leader Albert Gonzalez, reveals that in order to penetrate TJX data center from the captured end points, the hackers employed different techniques including password sniffing and SQL injection. The later justifies getting the TJX incident for the 1st time into WHID.&lt;/p&gt;&#13;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.networkworld.com/news/2008/080608-id-theft-ring-attacked-retailers.html?page=1&quot;&gt;Network World&lt;/a&gt;, June 8th 2008&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Credit Card Leakage</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2007-89</ddb:whidid>    </item>    <item>      <title>WHID 2009-19: Kaspersky site breached using SQL injection, sensitive data exposed (Updated)</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=35143</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2009-19: Kaspersky site breached using SQL injection, sensitive data exposed (Updated)&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2008-19&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;February 7, 2009&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;&lt;em&gt;&lt;strong&gt;Update (Feb 22&lt;sup&gt;nd&lt;/sup&gt; 2009)&lt;/strong&gt;&lt;/em&gt; - We were probably not the only ones not satisfied with Kasperski official press release on the subject. An interesting &lt;a href=&quot;http://www.viruslist.com/en/weblog?discuss=208187633&amp;amp;return=1&quot;&gt;report &lt;/a&gt;on Kasperski viruslist blog by a person on the investigating team provides answers: the data was neither secured well nor the hacker incapable. The hacker made a mistake in his attack vector and decided to pursue no further. The data was available for any hacker who was really after it.&lt;/p&gt;&lt;br&gt;&lt;p&gt;I must tkae my hat off to Kasperski for this frank analysis, which is very uncommon to companies who were breached and can really help to highlight the importance of application security.&lt;/p&gt;&lt;br&gt;&lt;hr /&gt;&lt;br&gt;&lt;p&gt;&lt;em&gt;&lt;strong&gt;Update (Feb 13&lt;sup&gt;th&lt;/sup&gt; 2009)&lt;/strong&gt;&lt;/em&gt; - Kasperski hired David Litchfield, a well known database security expert, to analyze the incident. In their &lt;a href=&quot;http://www.kaspersky.com/news?id=207575753&quot;&gt;response, &lt;/a&gt;Ksaperski point that no sensitive data was actually compromised  to the event. The report points that the hacker and others following his hints did try to access sensitive data but did not succeed. The carefully worded report does leave many questions open:&lt;/p&gt;&lt;br&gt;&lt;p&gt; &lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;Was the data secured well, or were the hackers who tried to access it just not capable?&lt;/li&gt;&lt;br&gt;&lt;li&gt;Was no data vulnerable or just &quot;sensitive data&quot; and if so what is the data that was exposed?&lt;/li&gt;&lt;br&gt;&lt;li&gt;Did the investigation go back to check that no one hacked the system prior to the published incident, potentially abusing it and avoiding publication?&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;hr /&gt;&lt;br&gt;&lt;p&gt;A researcher &lt;a href=&quot;http://hackersblog.org/2009/02/07/usakasperskycom-hacked-full-database-acces-sql-injection/&quot;&gt;found and exploited&lt;/a&gt; a serious SQL injection vulnerability in US web site of Kasperski, an anti-virus software vendor, exposing the full customers database. Well, the full database actually as the list of tables exposed proves. &lt;a href=&quot;http://www.theregister.co.uk/2009/02/09/kaspersky_compromise_follow_up/&quot;&gt;Apparently&lt;/a&gt;, the vulnerability existed for some time and the researched informed Kasperski about it to no avail before making it public.&lt;/p&gt;&lt;br&gt;&lt;p&gt; &lt;/p&gt;&lt;br&gt;&lt;p&gt;This is another example of how fatal is SQL injection. SQL Injection is considered one of the more well understood attack vectors, easy to find during a security review, and therefore easy to get rid of. However one of its variants, blind SQL injection, can appear everywhere in the application and not just in key pages managing sensitive information and expose the entire database, making a review and fix of the application from it much harder.&lt;/p&gt;&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;Romania&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Technology&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b></description>      <pubDate>Thu, 17 Jun 2010 18:26:15 -0400</pubDate>      <ddb:attackedentityfield>Technology</ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography>Romania</ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>February 7, 2009</ddb:dateoccured>      <ddb:entrytitle>WHID 2009-19: Kaspersky site breached using SQL injection, sensitive data exposed (Updated)</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;&lt;em&gt;&lt;strong&gt;Update (Feb 22&lt;sup&gt;nd&lt;/sup&gt; 2009)&lt;/strong&gt;&lt;/em&gt; - We were probably not the only ones not satisfied with Kasperski official press release on the subject. An interesting &lt;a href=&quot;http://www.viruslist.com/en/weblog?discuss=208187633&amp;amp;return=1&quot;&gt;report &lt;/a&gt;on Kasperski viruslist blog by a person on the investigating team provides answers: the data was neither secured well nor the hacker incapable. The hacker made a mistake in his attack vector and decided to pursue no further. The data was available for any hacker who was really after it.&lt;/p&gt;&#13;&#10;&lt;p&gt;I must tkae my hat off to Kasperski for this frank analysis, which is very uncommon to companies who were breached and can really help to highlight the importance of application security.&lt;/p&gt;&#13;&#10;&lt;hr /&gt;&#13;&#10;&lt;p&gt;&lt;em&gt;&lt;strong&gt;Update (Feb 13&lt;sup&gt;th&lt;/sup&gt; 2009)&lt;/strong&gt;&lt;/em&gt; - Kasperski hired David Litchfield, a well known database security expert, to analyze the incident. In their &lt;a href=&quot;http://www.kaspersky.com/news?id=207575753&quot;&gt;response, &lt;/a&gt;Ksaperski point that no sensitive data was actually compromised  to the event. The report points that the hacker and others following his hints did try to access sensitive data but did not succeed. The carefully worded report does leave many questions open:&lt;/p&gt;&#13;&#10;&lt;p&gt; &lt;/p&gt;&#13;&#10;&lt;ul&gt;&#13;&#10;&lt;li&gt;Was the data secured well, or were the hackers who tried to access it just not capable?&lt;/li&gt;&#13;&#10;&lt;li&gt;Was no data vulnerable or just &quot;sensitive data&quot; and if so what is the data that was exposed?&lt;/li&gt;&#13;&#10;&lt;li&gt;Did the investigation go back to check that no one hacked the system prior to the published incident, potentially abusing it and avoiding publication?&lt;/li&gt;&#13;&#10;&lt;/ul&gt;&#13;&#10;&lt;hr /&gt;&#13;&#10;&lt;p&gt;A researcher &lt;a href=&quot;http://hackersblog.org/2009/02/07/usakasperskycom-hacked-full-database-acces-sql-injection/&quot;&gt;found and exploited&lt;/a&gt; a serious SQL injection vulnerability in US web site of Kasperski, an anti-virus software vendor, exposing the full customers database. Well, the full database actually as the list of tables exposed proves. &lt;a href=&quot;http://www.theregister.co.uk/2009/02/09/kaspersky_compromise_follow_up/&quot;&gt;Apparently&lt;/a&gt;, the vulnerability existed for some time and the researched informed Kasperski about it to no avail before making it public.&lt;/p&gt;&#13;&#10;&lt;p&gt; &lt;/p&gt;&#13;&#10;&lt;p&gt;This is another example of how fatal is SQL injection. SQL Injection is considered one of the more well understood attack vectors, easy to find during a security review, and therefore easy to get rid of. However one of its variants, blind SQL injection, can appear everywhere in the application and not just in key pages managing sensitive information and expose the entire database, making a review and fix of the application from it much harder.&lt;/p></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2008-19</ddb:whidid>    </item>    <item>      <title>WHID 2008-24: SQL attacks lob onto ATP Web site</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34859</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2008-24: SQL attacks lob onto ATP Web site&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2008-24&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;July 21, 2008&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Planting of Malware&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Not a day goes by without yet another prominenent web site hacked by an SQL injection attack planting Malware.&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.networkworld.com/news/2008/070208-sql-attacks-lob-onto-tennis.html&quot;&gt;SQL attacks lob onto tennis association Web site&lt;/a&gt; [Network World, Jul 4 2008]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Sports&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;Global</description>      <pubDate>Wed, 16 Jun 2010 15:02:19 -0400</pubDate>      <ddb:attackedentityfield>Sports</ddb:attackedentityfield>      <ddb:attackedentitygeography>Global</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>July 21, 2008</ddb:dateoccured>      <ddb:entrytitle>WHID 2008-24: SQL attacks lob onto ATP Web site</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Not a day goes by without yet another prominenent web site hacked by an SQL injection attack planting Malware.&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.networkworld.com/news/2008/070208-sql-attacks-lob-onto-tennis.html&quot;&gt;SQL attacks lob onto tennis association Web site&lt;/a&gt; [Network World, Jul 4 2008]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Planting of Malware</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2008-24</ddb:whidid>    </item>    <item>      <title>WHID 2009-13: Wikipedia Biography Hacking</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=35111</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2009-13: Wikipedia Biography Hacking&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2009-13&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;January 27, 2009&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Disinformation&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;This incident might have not gotten into the Web Hacking Incident Database a year ago. However a heated discussion on the &lt;a href=&quot;http://www.webappsec.org&quot;&gt;Web Application Security Consortium&lt;/a&gt; &lt;a href=&quot;http://www.webappsec.org/projects/threat/&quot;&gt;threat classification&lt;/a&gt; project reminded me that content spoofing is a potent attack vector by itself, actually one of the most dangerous there.&lt;/p&gt;&lt;br&gt;&lt;p&gt;Wiki is one of those platforms that by design allow content be changed. It is its philosophy, and &lt;a href=&quot;http://en.wikipedia.org&quot;&gt;Wikipedia&lt;/a&gt; is the premier wiki out there. It is not a surprise that it is a prime target to content spoofing, as the &lt;a href=&quot;http://www.abc.net.au/pm/content/2008/s2475604.htm&quot;&gt;story&lt;/a&gt; about the unexpected demise of two US senators during Obama's inauguration.&lt;/p&gt;&lt;br&gt;&lt;p&gt;You can read more about the unique security philosophy of Wikis in my recent &lt;a href=&quot;/research/wiki_security&quot;&gt;article and presentation&lt;/a&gt; about the subject.&lt;/p&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Web 2.0&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA</description>      <pubDate>Thu, 17 Jun 2010 18:27:19 -0400</pubDate>      <ddb:attackedentityfield>Web 2.0</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>January 27, 2009</ddb:dateoccured>      <ddb:entrytitle>WHID 2009-13: Wikipedia Biography Hacking</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;This incident might have not gotten into the Web Hacking Incident Database a year ago. However a heated discussion on the &lt;a href=&quot;http://www.webappsec.org&quot;&gt;Web Application Security Consortium&lt;/a&gt; &lt;a href=&quot;http://www.webappsec.org/projects/threat/&quot;&gt;threat classification&lt;/a&gt; project reminded me that content spoofing is a potent attack vector by itself, actually one of the most dangerous there.&lt;/p&gt;&#13;&lt;p&gt;Wiki is one of those platforms that by design allow content be changed. It is its philosophy, and &lt;a href=&quot;http://en.wikipedia.org&quot;&gt;Wikipedia&lt;/a&gt; is the premier wiki out there. It is not a surprise that it is a prime target to content spoofing, as the &lt;a href=&quot;http://www.abc.net.au/pm/content/2008/s2475604.htm&quot;&gt;story&lt;/a&gt; about the unexpected demise of two US senators during Obama's inauguration.&lt;/p&gt;&#13;&lt;p&gt;You can read more about the unique security philosophy of Wikis in my recent &lt;a href=&quot;/research/wiki_security&quot;&gt;article and presentation&lt;/a&gt; about the subject.&lt;/p></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Disinformation</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2009-13</ddb:whidid>    </item>    <item>      <title>WHID 2008-25: BusinessWeek website attacked and hosts malware</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34864</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2008-25: BusinessWeek website attacked and hosts malware&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2008-25&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;September 20, 2008&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Planting of Malware&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Another site hit by the SQL injection bot&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.net-security.org/malware_news.php?id=990&quot;&gt;BusinessWeek website attacked and hosts malware&lt;/a&gt; [Net-Security, Sep 15 2008]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Information Services&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA</description>      <pubDate>Wed, 16 Jun 2010 15:02:19 -0400</pubDate>      <ddb:attackedentityfield>Information Services</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>September 20, 2008</ddb:dateoccured>      <ddb:entrytitle>WHID 2008-25: BusinessWeek website attacked and hosts malware</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Another site hit by the SQL injection bot&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.net-security.org/malware_news.php?id=990&quot;&gt;BusinessWeek website attacked and hosts malware&lt;/a&gt; [Net-Security, Sep 15 2008]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Planting of Malware</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2008-25</ddb:whidid>    </item>    <item>      <title>WHID 2009-18: phpBB web site hacked using LFI</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=35137</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2009-18: phpBB web site hacked using LFI&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2009-18&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;February 1, 2009&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;phpBB was known for years as one of the most insecure software packages out there. It is responsible for one for one of the 1st application layer worm, &lt;a href=&quot;/whid-2004-14&quot;&gt;Santy&lt;/a&gt; back in 2004. How ironic is that its own web site was seriously breached due to a vulnerability in another software package used...&lt;/p&gt;&lt;br&gt;&lt;p&gt;The culprit was an&lt;a href=&quot;http://www.bugreport.ir/index_60.htm&quot;&gt; LFI (Local File Inclusion) vulnerability in PHPlist&lt;/a&gt;, an application for managing newsletters which enables the hacker to grab phpBB users list. Another researcher &lt;a href=&quot;http://www.suspekt.org/2009/02/06/some-facts-about-the-phplist-vulnerability-and-the-phpbbcom-hack/&quot;&gt;claims &lt;/a&gt;that this is not an LFI but a super-globals-overwrite, which is still used to include files.&lt;/p&gt;&lt;br&gt;&lt;p&gt;However, phpBB is not entirely off the hook, as the phpBB team &lt;a href=&quot;http://area51.phpbb.com/phpBB/viewtopic.php?f=71&amp;amp;t=29973&quot;&gt;admits&lt;/a&gt;. The stolen files included only hashed passwords, however phpBB 2 hash was unsalted and the hackers successfully brute forced 28,000 passwords. While phpBB 3, which is used on the phpBB site uses better password hashing, the upgrade procedure did not upgrade existing users waiting for their 1st login to upgrade. Anyone who did not log-in to the web site since the upgrade still had weakly hashed password in the database.&lt;/p&gt;&lt;br&gt;&lt;p&gt;A &lt;a href=&quot;http://hackedphpbb.blogspot.com/2009/01/place-holder.html&quot;&gt;very detailed report &lt;/a&gt;of the incident by the hacker shed light on how such hacks are carried out, including what the hacker went after and his exploitation techniques . The hacker found the exploit on &lt;a href=&quot;http://www.milw0rm.com/exploits/7778&quot;&gt;milw0rm&lt;/a&gt;, a well known exploit repository, showing that public disclosure of vulnerabilities has its price, especially when it precedes the release if the patch.&lt;/p&gt;&lt;br&gt;&lt;p&gt;A copy of the report in case the original disappears can be found &lt;a href=&quot;http://ravenphpscripts.com/modules.php?name=News&amp;amp;file=article&amp;amp;sid=3540&quot;&gt;here&lt;/a&gt;.&lt;/p&gt;&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Technology&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Items Leaked: &lt;/b&gt;Password&lt;br&gt;&lt;b&gt;Number of Records: &lt;/b&gt;28,000</description>      <pubDate>Wed, 16 Jun 2010 14:23:05 -0400</pubDate>      <ddb:attackedentityfield>Technology</ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>February 1, 2009</ddb:dateoccured>      <ddb:entrytitle>WHID 2009-18: phpBB web site hacked using LFI</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;phpBB was known for years as one of the most insecure software packages out there. It is responsible for one for one of the 1st application layer worm, &lt;a href=&quot;/whid-2004-14&quot;&gt;Santy&lt;/a&gt; back in 2004. How ironic is that its own web site was seriously breached due to a vulnerability in another software package used...&lt;/p&gt;&#13;&#10;&lt;p&gt;The culprit was an&lt;a href=&quot;http://www.bugreport.ir/index_60.htm&quot;&gt; LFI (Local File Inclusion) vulnerability in PHPlist&lt;/a&gt;, an application for managing newsletters which enables the hacker to grab phpBB users list. Another researcher &lt;a href=&quot;http://www.suspekt.org/2009/02/06/some-facts-about-the-phplist-vulnerability-and-the-phpbbcom-hack/&quot;&gt;claims &lt;/a&gt;that this is not an LFI but a super-globals-overwrite, which is still used to include files.&lt;/p&gt;&#13;&#10;&lt;p&gt;However, phpBB is not entirely off the hook, as the phpBB team &lt;a href=&quot;http://area51.phpbb.com/phpBB/viewtopic.php?f=71&amp;amp;t=29973&quot;&gt;admits&lt;/a&gt;. The stolen files included only hashed passwords, however phpBB 2 hash was unsalted and the hackers successfully brute forced 28,000 passwords. While phpBB 3, which is used on the phpBB site uses better password hashing, the upgrade procedure did not upgrade existing users waiting for their 1st login to upgrade. Anyone who did not log-in to the web site since the upgrade still had weakly hashed password in the database.&lt;/p&gt;&#13;&#10;&lt;p&gt;A &lt;a href=&quot;http://hackedphpbb.blogspot.com/2009/01/place-holder.html&quot;&gt;very detailed report &lt;/a&gt;of the incident by the hacker shed light on how such hacks are carried out, including what the hacker went after and his exploitation techniques . The hacker found the exploit on &lt;a href=&quot;http://www.milw0rm.com/exploits/7778&quot;&gt;milw0rm&lt;/a&gt;, a well known exploit repository, showing that public disclosure of vulnerabilities has its price, especially when it precedes the release if the patch.&lt;/p&gt;&#13;&#10;&lt;p&gt;A copy of the report in case the original disappears can be found &lt;a href=&quot;http://ravenphpscripts.com/modules.php?name=News&amp;amp;file=article&amp;amp;sid=3540&quot;&gt;here&lt;/a&gt;.&lt;/p></ddb:incidentdescription>      <ddb:itemsleaked>Password</ddb:itemsleaked>      <ddb:numberofrecords>28,000</ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2009-18</ddb:whidid>    </item>    <item>      <title>WHID 2008-37: Pakistani hacker attacks Indian Rail site, threatens cyber war on India</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34910</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2008-37: Pakistani hacker attacks Indian Rail site, threatens cyber war on India&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2008-37&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;December 24, 2008&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Planting of Malware&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;The web site of the Indian Eastern Railway company was hacked. The hacker planted malware on the site and added a message to the home page declaring a cyber war on Indian Cyberspace.&lt;/p&gt;&lt;br&gt;&lt;p&gt;Additional Information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.financialexpress.com/news/pak-hacker-attacks-e-rlys-site-threatens-cyber-war-on-india/402609/0&quot;&gt;The Financial Express&lt;/a&gt;, Dec 25th 2008&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;Pakistan&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Government&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;India</description>      <pubDate>Wed, 16 Jun 2010 15:02:19 -0400</pubDate>      <ddb:attackedentityfield>Government</ddb:attackedentityfield>      <ddb:attackedentitygeography>India</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography>Pakistan</ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>December 24, 2008</ddb:dateoccured>      <ddb:entrytitle>WHID 2008-37: Pakistani hacker attacks Indian Rail site, threatens cyber war on India</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;The web site of the Indian Eastern Railway company was hacked. The hacker planted malware on the site and added a message to the home page declaring a cyber war on Indian Cyberspace.&lt;/p&gt;&#13;&lt;p&gt;Additional Information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.financialexpress.com/news/pak-hacker-attacks-e-rlys-site-threatens-cyber-war-on-india/402609/0&quot;&gt;The Financial Express&lt;/a&gt;, Dec 25th 2008&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Planting of Malware</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2008-37</ddb:whidid>    </item>    <item>      <title>WHID 2008-26: Palin&amp;#039;s private e-mail hacked, posted to Net</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34869</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2008-26: Palin&amp;#039;s private e-mail hacked, posted to Net&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2008-26&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;September 20, 2008&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;The activist group called &quot;anonymous,&quot; best known for its jousts with the Church of Scientology, has apparently hacked into the private Yahoo e-mail account of Alaska Gov. Sarah Palin, the Republican candidate for vice president.&lt;/p&gt;&lt;br&gt;&lt;p&gt;Contents of that account, including two sample e-mails, an index of messages and Palin family photos, have been posted by the whistle blower site Wikileaks, which contends that they constitute evidence that Palin has improperly used her private e-mail to shield government business from public scrutiny, an issue that had already been raised by others.&lt;/p&gt;&lt;br&gt;&lt;p&gt;&lt;span style=&quot;text-decoration: underline;&quot;&gt;&lt;em&gt;Update (Oct 8)&lt;br /&gt;&lt;/em&gt;&lt;/span&gt;&lt;/p&gt;&lt;br&gt;&lt;p&gt;David Kernell, the 20-year-old Tennessee college student was indicted with the hack. The most interesting aspect of the identity of the hacker is that his father Mike Kernell is a longtime Democratic state representative from Memphis&lt;/p&gt;&lt;br&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://wikileaks.org/wiki/VP_contender_Sarah_Palin_hacked&quot;&gt;VP contender Sarah Palin hacked&lt;/a&gt; [Wiki Leaks, Sep 16 2008]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.networkworld.com/community/node/32838&quot;&gt;Palin's private e-mail hacked, posted to 'Net&lt;/a&gt; [Network Wold, Sep 17 2008]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.internetnews.com/security/article.php/3776696&quot;&gt;Student Indicted in Palin E-Mail Hack&lt;/a&gt; [Internet News, Oct 8 2008)&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.usdoj.gov/opa/documents/indictment.pdf&quot;&gt;Court indictment document&lt;/a&gt;, Oct 7 2008&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Politics&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA</description>      <pubDate>Wed, 16 Jun 2010 15:02:19 -0400</pubDate>      <ddb:attackedentityfield>Politics</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>September 20, 2008</ddb:dateoccured>      <ddb:entrytitle>WHID 2008-26: Palin&amp;#039;s private e-mail hacked, posted to Net</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;The activist group called &quot;anonymous,&quot; best known for its jousts with the Church of Scientology, has apparently hacked into the private Yahoo e-mail account of Alaska Gov. Sarah Palin, the Republican candidate for vice president.&lt;/p&gt;&#13;&lt;p&gt;Contents of that account, including two sample e-mails, an index of messages and Palin family photos, have been posted by the whistle blower site Wikileaks, which contends that they constitute evidence that Palin has improperly used her private e-mail to shield government business from public scrutiny, an issue that had already been raised by others.&lt;/p&gt;&#13;&lt;p&gt;&lt;span style=&quot;text-decoration: underline;&quot;&gt;&lt;em&gt;Update (Oct 8)&lt;br /&gt;&lt;/em&gt;&lt;/span&gt;&lt;/p&gt;&#13;&lt;p&gt;David Kernell, the 20-year-old Tennessee college student was indicted with the hack. The most interesting aspect of the identity of the hacker is that his father Mike Kernell is a longtime Democratic state representative from Memphis&lt;/p&gt;&#13;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://wikileaks.org/wiki/VP_contender_Sarah_Palin_hacked&quot;&gt;VP contender Sarah Palin hacked&lt;/a&gt; [Wiki Leaks, Sep 16 2008]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.networkworld.com/community/node/32838&quot;&gt;Palin's private e-mail hacked, posted to 'Net&lt;/a&gt; [Network Wold, Sep 17 2008]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.internetnews.com/security/article.php/3776696&quot;&gt;Student Indicted in Palin E-Mail Hack&lt;/a&gt; [Internet News, Oct 8 2008)&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.usdoj.gov/opa/documents/indictment.pdf&quot;&gt;Court indictment document&lt;/a&gt;, Oct 7 2008&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2008-26</ddb:whidid>    </item>    <item>      <title>WHID 2009-14: My.BarackObama.com Infects Visitors With Trojan</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=35116</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2009-14: My.BarackObama.com Infects Visitors With Trojan&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2008-14&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;January 27, 2009&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Planting of Malware&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Websense &lt;a href=&quot;http://cyberinsecure.com/my-barackobama-com-infects-visitors-with-trojan/&quot;&gt;reports&lt;/a&gt; that my.barackobama.com, an open blogging service which is part of &lt;a href=&quot;https://www.barackobama.com/&quot;&gt;Obama's campaign web site&lt;/a&gt; has been used to point users to malware infecting content.&lt;/p&gt;&lt;br&gt;&lt;p&gt;The scam is a good example of the dangers of Web 2.0 user generated content and mashups. There was no malicious code on the Obama's site, however an allowed HTML code looking like a YouTube embedded flick pointed to an external site which carried the malware.&lt;/p&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Government&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA</description>      <pubDate>Wed, 16 Jun 2010 15:05:03 -0400</pubDate>      <ddb:attackedentityfield>Government</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>January 27, 2009</ddb:dateoccured>      <ddb:entrytitle>WHID 2009-14: My.BarackObama.com Infects Visitors With Trojan</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Websense &lt;a href=&quot;http://cyberinsecure.com/my-barackobama-com-infects-visitors-with-trojan/&quot;&gt;reports&lt;/a&gt; that my.barackobama.com, an open blogging service which is part of &lt;a href=&quot;https://www.barackobama.com/&quot;&gt;Obama's campaign web site&lt;/a&gt; has been used to point users to malware infecting content.&lt;/p&gt;&#13;&lt;p&gt;The scam is a good example of the dangers of Web 2.0 user generated content and mashups. There was no malicious code on the Obama's site, however an allowed HTML code looking like a YouTube embedded flick pointed to an external site which carried the malware.&lt;/p></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Planting of Malware</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2008-14</ddb:whidid>    </item>    <item>      <title>WHID 2007-88: Police Academy in India Hosting a Phishing Site</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34874</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2007-88: Police Academy in India Hosting a Phishing Site&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2007-88&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;September 20, 2008&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;The SVP National Police Academy in Hyderabad, India has had some sort of compromise on their website resulting in a Bank of America phishing site operating on one of their servers.&lt;/p&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Government&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;India</description>      <pubDate>Mon, 24 May 2010 13:54:42 -0400</pubDate>      <ddb:attackedentityfield>Government</ddb:attackedentityfield>      <ddb:attackedentitygeography>India</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>September 20, 2008</ddb:dateoccured>      <ddb:entrytitle>WHID 2007-88: Police Academy in India Hosting a Phishing Site</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;The SVP National Police Academy in Hyderabad, India has had some sort of compromise on their website resulting in a Bank of America phishing site operating on one of their servers.&lt;/p></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome></ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2007-88</ddb:whidid>    </item>    <item>      <title>WHID 2009-17: Passwords are optional at SpeedDate</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=35132</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2009-17: Passwords are optional at SpeedDate&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2009-17&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;February 3, 2009&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;TechCrunch &lt;a href=&quot;http://www.techcrunch.com/2009/02/03/password-optionalhuge-security-breach-hits-speeddate/&quot;&gt;reports &lt;/a&gt;that for a short period of time, SpeedDate, an online dating service did not require a password. If you knew someone's user name you could login. Talking about &quot;lack of sufficient authentication controls...&quot;&lt;/p&gt;&lt;br&gt;&lt;p&gt; &lt;/p&gt;&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Entertainment&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA</description>      <pubDate>Wed, 16 Jun 2010 14:23:05 -0400</pubDate>      <ddb:attackedentityfield>Entertainment</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>February 3, 2009</ddb:dateoccured>      <ddb:entrytitle>WHID 2009-17: Passwords are optional at SpeedDate</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;TechCrunch &lt;a href=&quot;http://www.techcrunch.com/2009/02/03/password-optionalhuge-security-breach-hits-speeddate/&quot;&gt;reports &lt;/a&gt;that for a short period of time, SpeedDate, an online dating service did not require a password. If you knew someone's user name you could login. Talking about &quot;lack of sufficient authentication controls...&quot;&lt;/p&gt;&#13;&#10;&lt;p&gt; &lt;/p></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2009-17</ddb:whidid>    </item>    <item>      <title>WHID 2008-27: U.K&amp;#039;s Crime Reduction Portal Hosting Phishing Pages</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34879</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2008-27: U.K&amp;#039;s Crime Reduction Portal Hosting Phishing Pages&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2008-27&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;September 20, 2008&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Phishing&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Poste Italiane seems to have relocated to a brand new location online, in this case the U.K's Crime Reduction Portal which is currently hosting a phishing page.&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;&quot;&gt;U.K's Crime Reduction Portal Hosting Phishing Pages&lt;/a&gt; [Dancho Danchev, Jun 2 2008]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Government&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;UK</description>      <pubDate>Wed, 16 Jun 2010 15:02:19 -0400</pubDate>      <ddb:attackedentityfield>Government</ddb:attackedentityfield>      <ddb:attackedentitygeography>UK</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>September 20, 2008</ddb:dateoccured>      <ddb:entrytitle>WHID 2008-27: U.K&amp;#039;s Crime Reduction Portal Hosting Phishing Pages</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Poste Italiane seems to have relocated to a brand new location online, in this case the U.K's Crime Reduction Portal which is currently hosting a phishing page.&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;&quot;&gt;U.K's Crime Reduction Portal Hosting Phishing Pages&lt;/a&gt; [Dancho Danchev, Jun 2 2008]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Phishing</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2008-27</ddb:whidid>    </item>    <item>      <title>WHID 2008-36: RBS WorldPay Data Breach Hits 1.5 Million (Updated)</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34904</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2008-36: RBS WorldPay Data Breach Hits 1.5 Million (Updated)&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2008-36&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;November 10, 2008&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;&lt;em&gt;&lt;strong&gt;Update (Feb 4&lt;sup&gt;th&lt;/sup&gt; 2009)&lt;/strong&gt;&lt;/em&gt;: While RBS reported that just 100 cards where abused in the incident, the news now &lt;a href=&quot;http://blog.wired.com/27bstroke6/2009/02/atm.html&quot;&gt;surfaced&lt;/a&gt;, that those cards where heavily abused as the hacker managed to lift the withdrawal limit and distribute the card copies around the world so that in total 9 million dollars where withdrawn from them in a matter of hours before they where blocked. At least, as the saying goes, losing a $100 is your problem; losing a million is the banks.&lt;/p&gt;&lt;br&gt;&lt;p&gt;&lt;hr /&gt;&lt;br&gt;The Royal Bank of Scotland (RBS) confirmed that a hacker perform a &quot;sophisticated cyber intrusion&quot; on RBS WorldPay Unit web site. 1.5 Million credit card numbers and 1.1 million social security numbers may have been stolen.&lt;/p&gt;&lt;br&gt;&lt;p&gt;At this time the only abuse known is a fraudulent use of about a 100 reloadable cards, which are used by companies to pay their employees.&lt;/p&gt;&lt;br&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://sev.prnewswire.com/banking-financial-services/20081223/NY5456423122008-1.html&quot;&gt;Company press release&lt;/a&gt;, December 23rd 2008&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.internetnews.com/security/article.php/3793386/RBS+WorldPay+Data+Breach+Hits+15+Million.htm&quot;&gt;Internet News&lt;/a&gt;, December 24th 2008&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Finance&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA</description>      <pubDate>Wed, 16 Jun 2010 15:02:19 -0400</pubDate>      <ddb:attackedentityfield>Finance</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>November 10, 2008</ddb:dateoccured>      <ddb:entrytitle>WHID 2008-36: RBS WorldPay Data Breach Hits 1.5 Million (Updated)</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;&lt;em&gt;&lt;strong&gt;Update (Feb 4&lt;sup&gt;th&lt;/sup&gt; 2009)&lt;/strong&gt;&lt;/em&gt;: While RBS reported that just 100 cards where abused in the incident, the news now &lt;a href=&quot;http://blog.wired.com/27bstroke6/2009/02/atm.html&quot;&gt;surfaced&lt;/a&gt;, that those cards where heavily abused as the hacker managed to lift the withdrawal limit and distribute the card copies around the world so that in total 9 million dollars where withdrawn from them in a matter of hours before they where blocked. At least, as the saying goes, losing a $100 is your problem; losing a million is the banks.&lt;/p&gt;&#13;&lt;p&gt;&lt;hr /&gt;&#13;The Royal Bank of Scotland (RBS) confirmed that a hacker perform a &quot;sophisticated cyber intrusion&quot; on RBS WorldPay Unit web site. 1.5 Million credit card numbers and 1.1 million social security numbers may have been stolen.&lt;/p&gt;&#13;&lt;p&gt;At this time the only abuse known is a fraudulent use of about a 100 reloadable cards, which are used by companies to pay their employees.&lt;/p&gt;&#13;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://sev.prnewswire.com/banking-financial-services/20081223/NY5456423122008-1.html&quot;&gt;Company press release&lt;/a&gt;, December 23rd 2008&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.internetnews.com/security/article.php/3793386/RBS+WorldPay+Data+Breach+Hits+15+Million.htm&quot;&gt;Internet News&lt;/a&gt;, December 24th 2008&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2008-36</ddb:whidid>    </item>    <item>      <title>WHID 2008-28: Confidential data on thousands of students exposed by test preparatory firm</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34884</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2008-28: Confidential data on thousands of students exposed by test preparatory firm&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2008-28&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;September 20, 2008&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;While moving to a new hosting provider, a system by Princeton Review used by student to prepare for a state assessment program exposed due to misconfiguration approximately 34,000 students from 2&lt;sup&gt;nd&lt;/sup&gt; to 10&lt;sup&gt;th&lt;/sup&gt; grade. The information included names, Florida ID (which is nearly identical to the US social security number) and the students exam report.&lt;/p&gt;&lt;br&gt;&lt;p&gt;The information was available for available online from late June to early August.&lt;/p&gt;&lt;br&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.securitypronews.com/insiderreports/insider/spn-49-20080819CompetitorTellsPaperNotRivalAboutSecurityFlaw.html&quot;&gt;Competitor Tells Paper, Not Rival, About Security Flaw&lt;/a&gt; [Security Pro News, Aug 19 2008]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.nytimes.com/2008/08/19/technology/19review.html?_r=2&amp;amp;adxnnl=1&amp;amp;oref=slogin&amp;amp;adxnnlx=1221859844-4bHK03P+zrmLhJ5Ul2SlPA&quot;&gt;Student Files Are Exposed on Web Site&lt;/a&gt; [New York Times, Aug 18 2008]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Education&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA</description>      <pubDate>Wed, 16 Jun 2010 15:02:19 -0400</pubDate>      <ddb:attackedentityfield>Education</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>September 20, 2008</ddb:dateoccured>      <ddb:entrytitle>WHID 2008-28: Confidential data on thousands of students exposed by test preparatory firm</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;While moving to a new hosting provider, a system by Princeton Review used by student to prepare for a state assessment program exposed due to misconfiguration approximately 34,000 students from 2&lt;sup&gt;nd&lt;/sup&gt; to 10&lt;sup&gt;th&lt;/sup&gt; grade. The information included names, Florida ID (which is nearly identical to the US social security number) and the students exam report.&lt;/p&gt;&#13;&lt;p&gt;The information was available for available online from late June to early August.&lt;/p&gt;&#13;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.securitypronews.com/insiderreports/insider/spn-49-20080819CompetitorTellsPaperNotRivalAboutSecurityFlaw.html&quot;&gt;Competitor Tells Paper, Not Rival, About Security Flaw&lt;/a&gt; [Security Pro News, Aug 19 2008]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.nytimes.com/2008/08/19/technology/19review.html?_r=2&amp;amp;adxnnl=1&amp;amp;oref=slogin&amp;amp;adxnnlx=1221859844-4bHK03P+zrmLhJ5Ul2SlPA&quot;&gt;Student Files Are Exposed on Web Site&lt;/a&gt; [New York Times, Aug 18 2008]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2008-28</ddb:whidid>    </item>    <item>      <title>WHID 2008-31: Hacker takes $50,000 a few cents at a time</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34899</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2008-31: Hacker takes $50,000 a few cents at a time&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2008-31&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;September 20, 2008&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Monetary Loss&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Californian Michael Largent used an automated script to open 58,000 such accounts, collecting many thousands of the small payments used to verify credit cards when openning accounts.&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.pcpro.co.uk/news/201252/hacker-takes-50000-a-few-cents-at-a-time.html&quot;&gt;Hacker takes $50,000 a few cents at a time&lt;/a&gt; [PC Pro, May 28 2008]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://blog.wired.com/27bstroke6/2008/05/man-allegedly-b.html&quot;&gt;Man Allegedly Bilks E-trade, Schwab of $50,000 by Collecting Lots of Free 'Micro-Deposits'&lt;/a&gt; [Wired, May 27 2008]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://blog.wired.com/27bstroke6/files/largent_affidavit.pdf&quot;&gt;Secret Service search warrant affidavit&lt;/a&gt; [Secret Service, May 7 2008]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Internet&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA</description>      <pubDate>Wed, 16 Jun 2010 15:02:19 -0400</pubDate>      <ddb:attackedentityfield>Internet</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>September 20, 2008</ddb:dateoccured>      <ddb:entrytitle>WHID 2008-31: Hacker takes $50,000 a few cents at a time</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Californian Michael Largent used an automated script to open 58,000 such accounts, collecting many thousands of the small payments used to verify credit cards when openning accounts.&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.pcpro.co.uk/news/201252/hacker-takes-50000-a-few-cents-at-a-time.html&quot;&gt;Hacker takes $50,000 a few cents at a time&lt;/a&gt; [PC Pro, May 28 2008]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://blog.wired.com/27bstroke6/2008/05/man-allegedly-b.html&quot;&gt;Man Allegedly Bilks E-trade, Schwab of $50,000 by Collecting Lots of Free 'Micro-Deposits'&lt;/a&gt; [Wired, May 27 2008]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://blog.wired.com/27bstroke6/files/largent_affidavit.pdf&quot;&gt;Secret Service search warrant affidavit&lt;/a&gt; [Secret Service, May 7 2008]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Monetary Loss</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2008-31</ddb:whidid>    </item>    <item>      <title>WHID 2009-15: Kanye West has been Hacked</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=35121</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2009-15: Kanye West has been Hacked&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2009-15&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;January 23, 2009&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Disinformation&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Celebrities web presence hacking is topping 2009 incidents list, and rappers seem to lead. However this &lt;a href=&quot;http://network.nationalpost.com/np/blogs/theampersand/archive/2009/01/23/kanye-west-has-been-hacked.aspx&quot;&gt;report&lt;/a&gt; in the Ampersand, like the &lt;a href=&quot;/WHID/2009/11/Lil_Kim_Facebook_Hacked&quot;&gt;Lil Kim story f&lt;/a&gt;rom the same week,is somewhat questionable. In both cases it seem that uncomfortable content was blamed on hacking.&lt;/p&gt;&lt;br&gt;&lt;p&gt;West's story is somewhat ironic as he used his blog to remind users of the untruthfulness of his web presence.&lt;/p&gt;&lt;br&gt;&lt;p&gt;When reviewing all the rappers incidents, my conclusion is that they are more susceptible to content spoofing because it is much easier for hackers to imitate their language and style.&lt;/p&gt;&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Entertainment&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA</description>      <pubDate>Wed, 16 Jun 2010 14:23:05 -0400</pubDate>      <ddb:attackedentityfield>Entertainment</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>January 23, 2009</ddb:dateoccured>      <ddb:entrytitle>WHID 2009-15: Kanye West has been Hacked</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Celebrities web presence hacking is topping 2009 incidents list, and rappers seem to lead. However this &lt;a href=&quot;http://network.nationalpost.com/np/blogs/theampersand/archive/2009/01/23/kanye-west-has-been-hacked.aspx&quot;&gt;report&lt;/a&gt; in the Ampersand, like the &lt;a href=&quot;/WHID/2009/11/Lil_Kim_Facebook_Hacked&quot;&gt;Lil Kim story f&lt;/a&gt;rom the same week,is somewhat questionable. In both cases it seem that uncomfortable content was blamed on hacking.&lt;/p&gt;&#13;&#10;&lt;p&gt;West's story is somewhat ironic as he used his blog to remind users of the untruthfulness of his web presence.&lt;/p&gt;&#13;&#10;&lt;p&gt;When reviewing all the rappers incidents, my conclusion is that they are more susceptible to content spoofing because it is much easier for hackers to imitate their language and style.&lt;/p></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Disinformation</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2009-15</ddb:whidid>    </item>    <item>      <title>WHID 2009-16: Primary schools hit by smut hack</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=35127</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2009-16: Primary schools hit by smut hack&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2009-16&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;January 30, 2009&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Defacement&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Not all defacement are created equal. I have a second grader who has just started to use her school's web site so this defacement of 20 primary school web sites with porn hit me deep inside. We do so much to screen our young ones from the sleazy world outside, and getting it in the school's web site is just unimaginable. Just thinking about the questions I would be asked if my daughter would get such pages.&lt;/p&gt;&lt;br&gt;&lt;p&gt;The &lt;a href=&quot;http://www.theregister.co.uk/2009/02/04/school_website_defacement/&quot;&gt;incident &lt;/a&gt;also highlights the total breakup of cyber security. The incident is blamed on an unpatched version of Moodle, an open source on-line education software. The naive way ot thinking would be that schools don't have the budgets to protect their applications or even to upgrade them. However, as this incident shows, proper security is fundamental and a substantial part of the budget should be allocated to it, even it means we spend less on the application features. We need to move slower but ensure security. After all, what is the value of an educational system that shows porn?&lt;/p&gt;&lt;br&gt;&lt;p&gt;Another insight is that real time controls for protecting web applications are essential. You need a WAF. While the specific vulnerability exploited is unknown, Installing &lt;a href=&quot;/modsecurity&quot;&gt;ModSecurity&lt;/a&gt; would have probably prevented the exploit.&lt;/p&gt;&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Education&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;UK&lt;br&gt;&lt;b&gt;Attacked System Technology: &lt;/b&gt;Moodle</description>      <pubDate>Wed, 16 Jun 2010 14:23:05 -0400</pubDate>      <ddb:attackedentityfield>Education</ddb:attackedentityfield>      <ddb:attackedentitygeography>UK</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology>Moodle</ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>January 30, 2009</ddb:dateoccured>      <ddb:entrytitle>WHID 2009-16: Primary schools hit by smut hack</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Not all defacement are created equal. I have a second grader who has just started to use her school's web site so this defacement of 20 primary school web sites with porn hit me deep inside. We do so much to screen our young ones from the sleazy world outside, and getting it in the school's web site is just unimaginable. Just thinking about the questions I would be asked if my daughter would get such pages.&lt;/p&gt;&#13;&#10;&lt;p&gt;The &lt;a href=&quot;http://www.theregister.co.uk/2009/02/04/school_website_defacement/&quot;&gt;incident &lt;/a&gt;also highlights the total breakup of cyber security. The incident is blamed on an unpatched version of Moodle, an open source on-line education software. The naive way ot thinking would be that schools don't have the budgets to protect their applications or even to upgrade them. However, as this incident shows, proper security is fundamental and a substantial part of the budget should be allocated to it, even it means we spend less on the application features. We need to move slower but ensure security. After all, what is the value of an educational system that shows porn?&lt;/p&gt;&#13;&#10;&lt;p&gt;Another insight is that real time controls for protecting web applications are essential. You need a WAF. While the specific vulnerability exploited is unknown, Installing &lt;a href=&quot;/modsecurity&quot;&gt;ModSecurity&lt;/a&gt; would have probably prevented the exploit.&lt;/p></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Defacement</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2009-16</ddb:whidid>    </item>    <item>      <title>WHID 2008-29: Sunwear hacks metasploit.com?</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34889</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2008-29: Sunwear hacks metasploit.com?&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2008-29&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;September 20, 2008&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Defacement&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;someone hacked a machine on the same subnet and was ARP spoofing the gateway. The metasploit.com machines were not compromised, but all HTTP requests coming into the ISP network were passed through a MITM defacer that inserted that HTML. Once I as able to set a static ARP entry and notify the ISP, the problem was resolved. So, to make things clear, the metasploit.com servers were not hacked, the ISP&lt;/p&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Internet</description>      <pubDate>Wed, 16 Jun 2010 15:02:19 -0400</pubDate>      <ddb:attackedentityfield>Internet</ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>September 20, 2008</ddb:dateoccured>      <ddb:entrytitle>WHID 2008-29: Sunwear hacks metasploit.com?</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;someone hacked a machine on the same subnet and was ARP spoofing the gateway. The metasploit.com machines were not compromised, but all HTTP requests coming into the ISP network were passed through a MITM defacer that inserted that HTML. Once I as able to set a static ARP entry and notify the ISP, the problem was resolved. So, to make things clear, the metasploit.com servers were not hacked, the ISP&lt;/p></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Defacement</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2008-29</ddb:whidid>    </item>    <item>      <title>WHID 2008-30: Security breach hits DivShare, unauthorized access to its database</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34894</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2008-30: Security breach hits DivShare, unauthorized access to its database&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2008-30&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;September 20, 2008&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;The popular document and media sharing service DivShare, suffered a security breach that allowed a malicious user to access their database, which included user e-mail addresses and other basic profile information.&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;Dancho Danchev&quot;&gt;Security breach hits DivShare, unauthorized access to its database&lt;/a&gt; [Zdnet, Jun 19 2008]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Information Services</description>      <pubDate>Wed, 16 Jun 2010 15:02:19 -0400</pubDate>      <ddb:attackedentityfield>Information Services</ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>September 20, 2008</ddb:dateoccured>      <ddb:entrytitle>WHID 2008-30: Security breach hits DivShare, unauthorized access to its database</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;The popular document and media sharing service DivShare, suffered a security breach that allowed a malicious user to access their database, which included user e-mail addresses and other basic profile information.&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;Dancho Danchev&quot;&gt;Security breach hits DivShare, unauthorized access to its database&lt;/a&gt; [Zdnet, Jun 19 2008]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2008-30</ddb:whidid>    </item>    <item>      <title>WHID 2006-13: Hackers Tap Banks&amp;#039; Web Sites In Unique Phishing Attack</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34090</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2006-13: Hackers Tap Banks&amp;#039; Web Sites In Unique Phishing Attack&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2006-13&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;April 4, 2006&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Phishing&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;In this very interesting attack a hacker broke into the informational web sites of several smaller banks in Florida. He than changed the link on the informational pages that points to the outsourced transactional web site to point to his own phishing site.&lt;br /&gt;While the vulnerability that enabled the hacker to penetrate the informational sites is not known, this is a very interesting example of a targeted web attack. It highlights the importance of protecting every web site and not just the core business logic.&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.techweb.com/wire/security/184401079&quot;&gt;Hackers Tap Banks' Web Sites In Unique Phishing Attack&lt;/a&gt; [TechWeb, Mar 29 2006]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.tallahassee.com/apps/pbcs.dll/article?AID=/20060317/BUSINESS/603170343/1003&quot;&gt;Banks pull plug on Web sites&lt;/a&gt; [Tallahassee Democrat, Mar 17 2006]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.tallahassee.com/apps/pbcs.dll/article?AID=/20060318/BUSINESS/603180310/1003&quot;&gt;Hackers create a new scam&lt;/a&gt; [Tallahassee Democrat, Mar 18 2006]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://riskman.typepad.com/perilocity/2006/03/a_new_phishing_.html&quot;&gt;A New Phishing Variation&lt;/a&gt; [John S. Quarterman, Mar 24 2006]&lt;/li&gt;&lt;br&gt;&lt;/ul></description>      <pubDate>Wed, 16 Jun 2010 18:38:09 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>April 4, 2006</ddb:dateoccured>      <ddb:entrytitle>WHID 2006-13: Hackers Tap Banks&amp;#039; Web Sites In Unique Phishing Attack</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;In this very interesting attack a hacker broke into the informational web sites of several smaller banks in Florida. He than changed the link on the informational pages that points to the outsourced transactional web site to point to his own phishing site.&lt;br /&gt;While the vulnerability that enabled the hacker to penetrate the informational sites is not known, this is a very interesting example of a targeted web attack. It highlights the importance of protecting every web site and not just the core business logic.&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.techweb.com/wire/security/184401079&quot;&gt;Hackers Tap Banks' Web Sites In Unique Phishing Attack&lt;/a&gt; [TechWeb, Mar 29 2006]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.tallahassee.com/apps/pbcs.dll/article?AID=/20060317/BUSINESS/603170343/1003&quot;&gt;Banks pull plug on Web sites&lt;/a&gt; [Tallahassee Democrat, Mar 17 2006]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.tallahassee.com/apps/pbcs.dll/article?AID=/20060318/BUSINESS/603180310/1003&quot;&gt;Hackers create a new scam&lt;/a&gt; [Tallahassee Democrat, Mar 18 2006]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://riskman.typepad.com/perilocity/2006/03/a_new_phishing_.html&quot;&gt;A New Phishing Variation&lt;/a&gt; [John S. Quarterman, Mar 24 2006]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Phishing</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2006-13</ddb:whidid>    </item>    <item>      <title>WHID 2005-47: SEC Vs. The Estonian Spiders</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=33745</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2005-47: SEC Vs. The Estonian Spiders&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2005-47&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;November 8, 2005&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Business wire allowed access to non published press releases.&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.webpronews.com/topnews/topnews/wpn-60-20051102SECVsTheEstonianSpiders.html&quot;&gt;SEC Vs. The Estonian Spiders&lt;/a&gt; [Web Pro News, Nov 2 2005]&lt;/li&gt;&lt;br&gt;&lt;/ul></description>      <pubDate>Wed, 16 Jun 2010 19:10:44 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>November 8, 2005</ddb:dateoccured>      <ddb:entrytitle>WHID 2005-47: SEC Vs. The Estonian Spiders</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Business wire allowed access to non published press releases.&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.webpronews.com/topnews/topnews/wpn-60-20051102SECVsTheEstonianSpiders.html&quot;&gt;SEC Vs. The Estonian Spiders&lt;/a&gt; [Web Pro News, Nov 2 2005]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2005-47</ddb:whidid>    </item>    <item>      <title>WHID 2000-2: IKEA exposes customer information on catalog site</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=33739</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2000-2: IKEA exposes customer information on catalog site&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2000-2&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;Error message revealed a database file location, which could be downloaded.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Retail&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://news.com.com/2100-1017-245372.html?legacy=cnet&quot;&gt;http://news.com.com/2100-1017-245372.html?legacy=cnet&lt;/a></description>      <pubDate>Thu, 17 Jun 2010 18:25:45 -0400</pubDate>      <ddb:attackedentityfield>Retail</ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured></ddb:dateoccured>      <ddb:entrytitle>WHID 2000-2: IKEA exposes customer information on catalog site</ddb:entrytitle>      <ddb:incidentdescription>Error message revealed a database file location, which could be downloaded.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference>http://news.com.com/2100-1017-245372.html?legacy=cnet</ddb:reference>      <ddb:whidid>2000-2</ddb:whidid>    </item>    <item>      <title>WHID 2000-3: Gaffe at Amazon leaves email addresses exposed</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=33735</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2000-3: Gaffe at Amazon leaves email addresses exposed&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2000-3&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;E-mail addresses of other customers displayed by mistake, no hacking was required&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://news.com.com/2100-1017-245387.html?legacy=cnet&quot;&gt;http://news.com.com/2100-1017-245387.html?legacy=cnet&lt;/a></description>      <pubDate>Mon, 24 May 2010 13:54:42 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured></ddb:dateoccured>      <ddb:entrytitle>WHID 2000-3: Gaffe at Amazon leaves email addresses exposed</ddb:entrytitle>      <ddb:incidentdescription>E-mail addresses of other customers displayed by mistake, no hacking was required</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome></ddb:outcome>      <ddb:reference>http://news.com.com/2100-1017-245387.html?legacy=cnet</ddb:reference>      <ddb:whidid>2000-3</ddb:whidid>    </item>    <item>      <title>WHID 2005-44: Xoops web site hacked</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=33750</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2005-44: Xoops web site hacked&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2005-44&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;November 8, 2005&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Configuration mistake left an unprotected unused virtual host. No details on the configuration problems given.&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.xoops.org/modules/news/article.php?storyid=2639&quot;&gt;Xoops web site hacked&lt;/a&gt; [Vendor Web Site, Oct 28 2005]&lt;/li&gt;&lt;br&gt;&lt;/ul></description>      <pubDate>Wed, 16 Jun 2010 19:12:44 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>November 8, 2005</ddb:dateoccured>      <ddb:entrytitle>WHID 2005-44: Xoops web site hacked</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Configuration mistake left an unprotected unused virtual host. No details on the configuration problems given.&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.xoops.org/modules/news/article.php?storyid=2639&quot;&gt;Xoops web site hacked&lt;/a&gt; [Vendor Web Site, Oct 28 2005]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2005-44</ddb:whidid>    </item>    <item>      <title>WHID 2000-5: Eve.com exposes customers order information</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=33730</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2000-5: Eve.com exposes customers order information&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2000-5&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;View other customers orders by changing a sequential number within a URL parameter&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://news.com.com/2100-1017-245700.html?legacy=cnet&quot;&gt;http://news.com.com/2100-1017-245700.html?legacy=cnet&lt;/a></description>      <pubDate>Mon, 24 May 2010 13:54:42 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured></ddb:dateoccured>      <ddb:entrytitle>WHID 2000-5: Eve.com exposes customers order information</ddb:entrytitle>      <ddb:incidentdescription>View other customers orders by changing a sequential number within a URL parameter</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome></ddb:outcome>      <ddb:reference>http://news.com.com/2100-1017-245700.html?legacy=cnet</ddb:reference>      <ddb:whidid>2000-5</ddb:whidid>    </item>    <item>      <title>WHID 2005-11: Samy XSS Worm Hits MySpace</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=33755</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2005-11: Samy XSS Worm Hits MySpace&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2005-11&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;November 8, 2005&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Worm&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;The Samy worm at my space is now a classic, both a sophisticated attack and a well documented one, it became a case study in the web application security field. Recently Robert Hansen (RSnake) wrote a very interesting blog entry about Samy and what happened to him since.&lt;/p&gt;&lt;br&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://ha.ckers.org/blog/20070310/my-lunch-with-samy/&quot;&gt;My Lunch With Samy&lt;/a&gt; [ha.ckers, Mar 10 2007]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://fast.info/myspace/&quot;&gt;MySpace XSS worm writer notes&lt;/a&gt; [bindshell, Apr 10 2005]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.bindshell.net/papers/xssv/myspace/code/&quot;&gt;MySpace XSS worm source&lt;/a&gt; [bindshell, Apr 10 2005]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://namb.la/popular/tech.html&quot;&gt;MySpace XSS virus development&lt;/a&gt; [bindshell, Apr 10 2005]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.betanews.com/article/CrossSite_Scripting_Worm_Hits_MySpace/1129232391&quot;&gt;Cross-Site Scripting Worm Hits MySpace&lt;/a&gt; [Beta News, Apr 10 2005]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Web 2.0</description>      <pubDate>Wed, 16 Jun 2010 19:57:41 -0400</pubDate>      <ddb:attackedentityfield>Web 2.0</ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>November 8, 2005</ddb:dateoccured>      <ddb:entrytitle>WHID 2005-11: Samy XSS Worm Hits MySpace</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;The Samy worm at my space is now a classic, both a sophisticated attack and a well documented one, it became a case study in the web application security field. Recently Robert Hansen (RSnake) wrote a very interesting blog entry about Samy and what happened to him since.&lt;/p&gt;&#13;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://ha.ckers.org/blog/20070310/my-lunch-with-samy/&quot;&gt;My Lunch With Samy&lt;/a&gt; [ha.ckers, Mar 10 2007]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://fast.info/myspace/&quot;&gt;MySpace XSS worm writer notes&lt;/a&gt; [bindshell, Apr 10 2005]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.bindshell.net/papers/xssv/myspace/code/&quot;&gt;MySpace XSS worm source&lt;/a&gt; [bindshell, Apr 10 2005]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://namb.la/popular/tech.html&quot;&gt;MySpace XSS virus development&lt;/a&gt; [bindshell, Apr 10 2005]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.betanews.com/article/CrossSite_Scripting_Worm_Hits_MySpace/1129232391&quot;&gt;Cross-Site Scripting Worm Hits MySpace&lt;/a&gt; [Beta News, Apr 10 2005]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Worm</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2005-11</ddb:whidid>    </item>    <item>      <title>WHID 2001-1: Travelocity exposes customer information</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=33724</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2001-1: Travelocity exposes customer information&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2001-1&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Disclosure Only&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;Sensitive files were left in a publicly accessible directory of a new web server install&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://news.com.com/2100-1017-251344.html?legacy=cnet&quot;&gt;http://news.com.com/2100-1017-251344.html?legacy=cnet&lt;/a></description>      <pubDate>Wed, 16 Jun 2010 20:51:42 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured></ddb:dateoccured>      <ddb:entrytitle>WHID 2001-1: Travelocity exposes customer information</ddb:entrytitle>      <ddb:incidentdescription>Sensitive files were left in a publicly accessible directory of a new web server install</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Disclosure Only</ddb:outcome>      <ddb:reference>http://news.com.com/2100-1017-251344.html?legacy=cnet</ddb:reference>      <ddb:whidid>2001-1</ddb:whidid>    </item>    <item>      <title>WHID 2001-2: Computer E-Retailer Exposes Credit Card Numbers</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=33719</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2001-2: Computer E-Retailer Exposes Credit Card Numbers&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2001-2&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Disclosure Only&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;View other orders by changing a sequential parameter number. Security was provided by client side JavaScript&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://www.extremetech.com/article2/0,3973,103782,00.asp&quot;&gt;http://www.extremetech.com/article2/0,3973,103782,00.asp&lt;/a></description>      <pubDate>Wed, 16 Jun 2010 20:51:17 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured></ddb:dateoccured>      <ddb:entrytitle>WHID 2001-2: Computer E-Retailer Exposes Credit Card Numbers</ddb:entrytitle>      <ddb:incidentdescription>View other orders by changing a sequential parameter number. Security was provided by client side JavaScript</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Disclosure Only</ddb:outcome>      <ddb:reference>http://www.extremetech.com/article2/0,3973,103782,00.asp</ddb:reference>      <ddb:whidid>2001-2</ddb:whidid>    </item>    <item>      <title>WHID 2005-40: Defacement of several Novell websites</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=33762</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2005-40: Defacement of several Novell websites&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2005-40&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;November 8, 2005&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Defacement&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Script upload due to a scoop known vulnerability&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://lists.suse.com/archive/suse-security-announce/2005-Oct/0001.html&quot;&gt;Defacement of several Novell websites&lt;/a&gt; [Mailing list post, Oct 4 2005]&lt;/li&gt;&lt;br&gt;&lt;/ul></description>      <pubDate>Wed, 16 Jun 2010 19:15:46 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>November 8, 2005</ddb:dateoccured>      <ddb:entrytitle>WHID 2005-40: Defacement of several Novell websites</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Script upload due to a scoop known vulnerability&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://lists.suse.com/archive/suse-security-announce/2005-Oct/0001.html&quot;&gt;Defacement of several Novell websites&lt;/a&gt; [Mailing list post, Oct 4 2005]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Defacement</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2005-40</ddb:whidid>    </item>    <item>      <title>WHID 2001-3: Persistent XSS in Hotmail</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=33714</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2001-3: Persistent XSS in Hotmail&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2001-3&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Disclosure Only&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;Persistent XSS HTML Injection inside an HTML email message to hotmail&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://www.usatoday.com/tech/news/2001-08-31-hotmail-security.htm&quot;&gt;http://www.usatoday.com/tech/news/2001-08-31-hotmail-security.htm&lt;/a></description>      <pubDate>Wed, 16 Jun 2010 20:50:43 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured></ddb:dateoccured>      <ddb:entrytitle>WHID 2001-3: Persistent XSS in Hotmail</ddb:entrytitle>      <ddb:incidentdescription>Persistent XSS HTML Injection inside an HTML email message to hotmail</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Disclosure Only</ddb:outcome>      <ddb:reference>http://www.usatoday.com/tech/news/2001-08-31-hotmail-security.htm</ddb:reference>      <ddb:whidid>2001-3</ddb:whidid>    </item>    <item>      <title>WHID 2001-5: Privacy hole found in Verizon Wireless Web site</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=33709</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2001-5: Privacy hole found in Verizon Wireless Web site&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2001-5&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;September 6, 2001&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Disclosure Only&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;The privacy hole affected users who logged on to the Verizon Wireless Web site and used the My Account feature to view or change their cell phone billing and account information. The Web site address for the feature assigns session identifications sequentially as each user logs in which allows for forceful browsing.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://www.computerworld.com/securitytopics/security/privacy/story/0,10801,63587,00.html&quot;&gt;http://www.computerworld.com/securitytopics/security/privacy/story/0,10801,63587,00.html&lt;/a></description>      <pubDate>Wed, 16 Jun 2010 20:49:49 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>September 6, 2001</ddb:dateoccured>      <ddb:entrytitle>WHID 2001-5: Privacy hole found in Verizon Wireless Web site</ddb:entrytitle>      <ddb:incidentdescription>The privacy hole affected users who logged on to the Verizon Wireless Web site and used the My Account feature to view or change their cell phone billing and account information. The Web site address for the feature assigns session identifications sequentially as each user logs in which allows for forceful browsing.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Disclosure Only</ddb:outcome>      <ddb:reference>http://www.computerworld.com/securitytopics/security/privacy/story/0,10801,63587,00.html</ddb:reference>      <ddb:whidid>2001-5</ddb:whidid>    </item>    <item>      <title>WHID 2005-39: Promotional Firefox community site hacked (again)</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=33767</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2005-39: Promotional Firefox community site hacked (again)&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2005-39&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;November 8, 2005&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Exploited unpatched Twiki&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://arstechnica.com/news.ars/post/20051004-5383.html&quot;&gt;Promotional Firefox community site hacked (again)&lt;/a&gt; [ARStechnica, Oct 4 2005]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.net-security.org/article.php?id=836&quot;&gt;SpreadFirefox.com Community Website Hacked Once Again&lt;/a&gt; [ARStechnica, Oct 4 2005]&lt;/li&gt;&lt;br&gt;&lt;/ul></description>      <pubDate>Wed, 16 Jun 2010 19:16:53 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>November 8, 2005</ddb:dateoccured>      <ddb:entrytitle>WHID 2005-39: Promotional Firefox community site hacked (again)</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Exploited unpatched Twiki&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://arstechnica.com/news.ars/post/20051004-5383.html&quot;&gt;Promotional Firefox community site hacked (again)&lt;/a&gt; [ARStechnica, Oct 4 2005]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.net-security.org/article.php?id=836&quot;&gt;SpreadFirefox.com Community Website Hacked Once Again&lt;/a&gt; [ARStechnica, Oct 4 2005]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2005-39</ddb:whidid>    </item>    <item>      <title>WHID 2001-6: XSS at Microsoft Passport</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=33704</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2001-6: XSS at Microsoft Passport&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2001-6&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Disclosure Only&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://www.pcworld.com/news/article/0,aid,69543,00.asp&quot;&gt;http://www.pcworld.com/news/article/0,aid,69543,00.asp&lt;/a></description>      <pubDate>Wed, 16 Jun 2010 20:49:22 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured></ddb:dateoccured>      <ddb:entrytitle>WHID 2001-6: XSS at Microsoft Passport</ddb:entrytitle>      <ddb:incidentdescription></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Disclosure Only</ddb:outcome>      <ddb:reference>http://www.pcworld.com/news/article/0,aid,69543,00.asp</ddb:reference>      <ddb:whidid>2001-6</ddb:whidid>    </item>    <item>      <title>WHID 2005-37: A 12 years old hacked an online game and stole game items</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=33772</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2005-37: A 12 years old hacked an online game and stole game items&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2005-37&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;September 12, 2005&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Information Warfare&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;A 12 years old guess login information of a woman and abused her account, stealing game items from her.&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.buslab.org/index.php/content/view/22317/2/&quot;&gt;Boy, 12, referred to child guidance center for hacking into online game site&lt;/a&gt; [Manchini Daily News, Sep 7 2005]&lt;/li&gt;&lt;br&gt;&lt;/ul></description>      <pubDate>Wed, 16 Jun 2010 19:22:26 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>September 12, 2005</ddb:dateoccured>      <ddb:entrytitle>WHID 2005-37: A 12 years old hacked an online game and stole game items</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;A 12 years old guess login information of a woman and abused her account, stealing game items from her.&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.buslab.org/index.php/content/view/22317/2/&quot;&gt;Boy, 12, referred to child guidance center for hacking into online game site&lt;/a&gt; [Manchini Daily News, Sep 7 2005]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Information Warfare</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2005-37</ddb:whidid>    </item>    <item>      <title>WHID 2002-1: Flawed authentication at BN.com exposes personal information</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=33699</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2002-1: Flawed authentication at BN.com exposes personal information&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2002-1&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Opening an account with a discontinued e-mail address exposes all the information of the discontinues account&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://wired-vig.wired.com/news/ebiz/0,1272,53942,00.html&quot;&gt;BN.com: The Hole Story&lt;/a&gt; [Wired, Jul 19 2002]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.marktaw.com/technology/HackingBarnesAndNoble.com.html&quot;&gt;BarnesAndNoble.com Security Flaw&lt;/a&gt; [Personal Web Page, Jul 9 2002]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://itmanagement.earthweb.com/secu/article.php/3347761&quot;&gt;Barnes &amp;amp; Noble.com Fined for Customer Data Leak&lt;/a&gt; [Datamation, Apr 30 2004]&lt;/li&gt;&lt;br&gt;&lt;/ul></description>      <pubDate>Wed, 16 Jun 2010 20:48:14 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured></ddb:dateoccured>      <ddb:entrytitle>WHID 2002-1: Flawed authentication at BN.com exposes personal information</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Opening an account with a discontinued e-mail address exposes all the information of the discontinues account&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://wired-vig.wired.com/news/ebiz/0,1272,53942,00.html&quot;&gt;BN.com: The Hole Story&lt;/a&gt; [Wired, Jul 19 2002]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.marktaw.com/technology/HackingBarnesAndNoble.com.html&quot;&gt;BarnesAndNoble.com Security Flaw&lt;/a&gt; [Personal Web Page, Jul 9 2002]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://itmanagement.earthweb.com/secu/article.php/3347761&quot;&gt;Barnes &amp;amp; Noble.com Fined for Customer Data Leak&lt;/a&gt; [Datamation, Apr 30 2004]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2002-1</ddb:whidid>    </item>    <item>      <title>WHID 2003-1: FTD.com hole leaks personal information</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=33694</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2003-1: FTD.com hole leaks personal information&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2003-1&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;View other customers information by modifying a cookie&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://news.com.com/2100-1017-984585.html&quot;&gt;FTD.com hole leaks personal information&lt;/a&gt; [CNet, Feb 13 2003]&lt;/li&gt;&lt;br&gt;&lt;/ul></description>      <pubDate>Wed, 16 Jun 2010 20:38:37 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured></ddb:dateoccured>      <ddb:entrytitle>WHID 2003-1: FTD.com hole leaks personal information</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;View other customers information by modifying a cookie&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://news.com.com/2100-1017-984585.html&quot;&gt;FTD.com hole leaks personal information&lt;/a&gt; [CNet, Feb 13 2003]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2003-1</ddb:whidid>    </item>    <item>      <title>WHID 2005-38: Massachusetts Teen Convicted for Hacking into Internet and Telephone Service Providers</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=33777</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2005-38: Massachusetts Teen Convicted for Hacking into Internet and Telephone Service Providers&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2005-38&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;September 12, 2005&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Extortion&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Teen convicted of threatening an ISP with DOS attack, among other computer hacking activities&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.prnewswire.com/cgi-bin/stories.pl?ACCT=104&amp;amp;STORY=/www/story/09-08-2005/0004103380&amp;amp;EDATE=&quot;&gt;Massachusetts Teen Convicted for Hacking into Internet and Telephone Service Providers &lt;/a&gt; [Press Release, Sep 8 2005]&lt;/li&gt;&lt;br&gt;&lt;/ul></description>      <pubDate>Wed, 16 Jun 2010 19:20:10 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>September 12, 2005</ddb:dateoccured>      <ddb:entrytitle>WHID 2005-38: Massachusetts Teen Convicted for Hacking into Internet and Telephone Service Providers</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Teen convicted of threatening an ISP with DOS attack, among other computer hacking activities&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.prnewswire.com/cgi-bin/stories.pl?ACCT=104&amp;amp;STORY=/www/story/09-08-2005/0004103380&amp;amp;EDATE=&quot;&gt;Massachusetts Teen Convicted for Hacking into Internet and Telephone Service Providers &lt;/a&gt; [Press Release, Sep 8 2005]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Extortion</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2005-38</ddb:whidid>    </item>    <item>      <title>WHID 2003-3: User passwords could be stolid in Microsoft&amp;#039;s Passport service</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=33689</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2003-3: User passwords could be stolid in Microsoft&amp;#039;s Passport service&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2003-3&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Disclosure Only&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://news.zdnet.co.uk/business/0,39020645,2134469,00.htm&quot;&gt;Microsoft faces huge fine over security&lt;/a&gt; [Zdnet, May 9 2003]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.atnewyork.com/news/article.php/2203651&quot;&gt;Microsoft Patches .NET Passport Hole&lt;/a&gt; [AnyNetwork, May 8 2003]&lt;/li&gt;&lt;br&gt;&lt;/ul></description>      <pubDate>Wed, 16 Jun 2010 20:36:37 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured></ddb:dateoccured>      <ddb:entrytitle>WHID 2003-3: User passwords could be stolid in Microsoft&amp;#039;s Passport service</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://news.zdnet.co.uk/business/0,39020645,2134469,00.htm&quot;&gt;Microsoft faces huge fine over security&lt;/a&gt; [Zdnet, May 9 2003]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.atnewyork.com/news/article.php/2203651&quot;&gt;Microsoft Patches .NET Passport Hole&lt;/a&gt; [AnyNetwork, May 8 2003]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Disclosure Only</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2003-3</ddb:whidid>    </item>    <item>      <title>WHID 2003-4: SQL injection on Guess site triggers an FTC inquiry</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=33684</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2003-4: SQL injection on Guess site triggers an FTC inquiry&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2003-4&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Disclosure Only&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.ftc.gov/opa/2003/06/guess.htm&quot;&gt;Guess Settles FTC Security Charges&lt;/a&gt; [FTC Web Site, Jun 18 2003]&lt;/li&gt;&lt;br&gt;&lt;/ul></description>      <pubDate>Wed, 16 Jun 2010 20:34:27 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured></ddb:dateoccured>      <ddb:entrytitle>WHID 2003-4: SQL injection on Guess site triggers an FTC inquiry</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.ftc.gov/opa/2003/06/guess.htm&quot;&gt;Guess Settles FTC Security Charges&lt;/a&gt; [FTC Web Site, Jun 18 2003]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Disclosure Only</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2003-4</ddb:whidid>    </item>    <item>      <title>WHID 2003-5: Car shoppers&amp;#039; credit details exposed in bulk</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=33679</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2003-5: Car shoppers&amp;#039; credit details exposed in bulk&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2003-5&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;User submitted information was being stored in a publicly available location. The URL found in the source code of a publicly available web page.&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.securityfocus.com/news/7067&quot;&gt;Car shoppers' credit details exposed in bulk&lt;/a&gt; [Security Focus, Sep 25 2003]&lt;/li&gt;&lt;br&gt;&lt;/ul></description>      <pubDate>Wed, 16 Jun 2010 20:34:04 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured></ddb:dateoccured>      <ddb:entrytitle>WHID 2003-5: Car shoppers&amp;#039; credit details exposed in bulk</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;User submitted information was being stored in a publicly available location. The URL found in the source code of a publicly available web page.&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.securityfocus.com/news/7067&quot;&gt;Car shoppers' credit details exposed in bulk&lt;/a&gt; [Security Focus, Sep 25 2003]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2003-5</ddb:whidid>    </item>    <item>      <title>WHID 2005-36: Predictable delay in an online poker game enabled users to beat the casino</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=33783</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2005-36: Predictable delay in an online poker game enabled users to beat the casino&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2005-36&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;September 4, 2005&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Monetary Loss&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;A player of an online game discovered that considerable delay hinted on the cards the dealer holds.&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://haacked.com/archive/2005/08/29/9748.aspx&quot;&gt;Online Games Are Written By Humans&lt;/a&gt; [Personal , Aug 29 2005]&lt;/li&gt;&lt;br&gt;&lt;/ul></description>      <pubDate>Wed, 16 Jun 2010 19:25:32 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>September 4, 2005</ddb:dateoccured>      <ddb:entrytitle>WHID 2005-36: Predictable delay in an online poker game enabled users to beat the casino</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;A player of an online game discovered that considerable delay hinted on the cards the dealer holds.&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://haacked.com/archive/2005/08/29/9748.aspx&quot;&gt;Online Games Are Written By Humans&lt;/a&gt; [Personal , Aug 29 2005]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Monetary Loss</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2005-36</ddb:whidid>    </item>    <item>      <title>WHID 2003-7: Victoria&amp;#039;s Secret reveals far too much</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=33674</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2003-7: Victoria&amp;#039;s Secret reveals far too much&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2003-7&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Disclosure Only&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;View other customers orders by changing a sequential number within a URL parameter&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.cbsnews.com/stories/2003/10/22/tech/main579547.shtml&quot;&gt;Victoria's Secret Reveals Too Much&lt;/a&gt; [CBS News, Oct 22 2003]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://cooltech.iafrica.com/technews/280300.htm&quot;&gt;Victoria's Secret reveals far too much&lt;/a&gt; [iAfrica, Oct 24 2003]&lt;/li&gt;&lt;br&gt;&lt;/ul></description>      <pubDate>Wed, 16 Jun 2010 20:32:39 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured></ddb:dateoccured>      <ddb:entrytitle>WHID 2003-7: Victoria&amp;#039;s Secret reveals far too much</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;View other customers orders by changing a sequential number within a URL parameter&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.cbsnews.com/stories/2003/10/22/tech/main579547.shtml&quot;&gt;Victoria's Secret Reveals Too Much&lt;/a&gt; [CBS News, Oct 22 2003]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://cooltech.iafrica.com/technews/280300.htm&quot;&gt;Victoria's Secret reveals far too much&lt;/a&gt; [iAfrica, Oct 24 2003]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Disclosure Only</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2003-7</ddb:whidid>    </item>    <item>      <title>WHID 2005-35: Stanford University web sites defaced using XMLRPC bug</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=33788</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2005-35: Stanford University web sites defaced using XMLRPC bug&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2005-35&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;August 23, 2005&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Defacement&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Sites where defaced by utilizing an issue in an XMLRPC library used by PHP&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.zone-h.org/en/news/read/id=205962/&quot;&gt;Brazilian defacers hack hundreds of Stanford University web sites&lt;/a&gt; [Zone-H, Aug 21 2005]&lt;/li&gt;&lt;br&gt;&lt;/ul></description>      <pubDate>Wed, 16 Jun 2010 19:26:15 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>August 23, 2005</ddb:dateoccured>      <ddb:entrytitle>WHID 2005-35: Stanford University web sites defaced using XMLRPC bug</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Sites where defaced by utilizing an issue in an XMLRPC library used by PHP&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.zone-h.org/en/news/read/id=205962/&quot;&gt;Brazilian defacers hack hundreds of Stanford University web sites&lt;/a&gt; [Zone-H, Aug 21 2005]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Defacement</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2005-35</ddb:whidid>    </item>    <item>      <title>WHID 2004-2: Biggest Web Problem Isn&amp;#039;t About Privacy, It&amp;#039;s Sloppy Security - Saks</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=33669</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2004-2: Biggest Web Problem Isn&amp;#039;t About Privacy, It&amp;#039;s Sloppy Security - Saks&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2004-2&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;August 4, 2005&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://snafu.fooworld.org/~fubob/pubs/wsj-gomes1.txt&quot;&gt;Biggest Web Problem Isn't About Privacy, It's Sloppy Security&lt;/a&gt; [Wallstreet Journal (Archive Copy), Jan 26 2004]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://www.cs.umass.edu/~kevinfu/news/wsj-gomes1.txt&quot;&gt;http://www.cs.umass.edu/~kevinfu/news/wsj-gomes1.txt&lt;/a></description>      <pubDate>Wed, 16 Jun 2010 20:29:11 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>August 4, 2005</ddb:dateoccured>      <ddb:entrytitle>WHID 2004-2: Biggest Web Problem Isn&amp;#039;t About Privacy, It&amp;#039;s Sloppy Security - Saks</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Additional information:&lt;/p&gt;&#13;&#10;&lt;ul&gt;&#13;&#10;&lt;li&gt;&lt;a href=&quot;http://snafu.fooworld.org/~fubob/pubs/wsj-gomes1.txt&quot;&gt;Biggest Web Problem Isn't About Privacy, It's Sloppy Security&lt;/a&gt; [Wallstreet Journal (Archive Copy), Jan 26 2004]&lt;/li&gt;&#13;&#10;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference>http://www.cs.umass.edu/~kevinfu/news/wsj-gomes1.txt</ddb:reference>      <ddb:whidid>2004-2</ddb:whidid>    </item>    <item>      <title>WHID 2005-34: Man logs into dabs.com misc customer account</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=33793</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2005-34: Man logs into dabs.com misc customer account&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2005-34&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;August 22, 2005&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.channelregister.co.uk/2005/08/18/dabs_password_misdirected/&quot;&gt;Man logs into dabs.com customer account shocker&lt;/a&gt; [channel register, Aug 18 2005]&lt;/li&gt;&lt;br&gt;&lt;/ul></description>      <pubDate>Wed, 16 Jun 2010 19:28:47 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>August 22, 2005</ddb:dateoccured>      <ddb:entrytitle>WHID 2005-34: Man logs into dabs.com misc customer account</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.channelregister.co.uk/2005/08/18/dabs_password_misdirected/&quot;&gt;Man logs into dabs.com customer account shocker&lt;/a&gt; [channel register, Aug 18 2005]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2005-34</ddb:whidid>    </item>    <item>      <title>WHID 2004-1: Biggest Web Problem Isn&amp;#039;t About Privacy, It&amp;#039;s Sloppy Security - OpenTable</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=33664</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2004-1: Biggest Web Problem Isn&amp;#039;t About Privacy, It&amp;#039;s Sloppy Security - OpenTable&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2004-1&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;August 4, 2005&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://snafu.fooworld.org/~fubob/pubs/wsj-gomes1.txt&quot;&gt;Biggest Web Problem Isn't About Privacy, It's Sloppy Security&lt;/a&gt; [Wallstreet Journal (Archive Copy), Jan 26 2004]&lt;/li&gt;&lt;br&gt;&lt;/ul></description>      <pubDate>Wed, 16 Jun 2010 20:30:11 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>August 4, 2005</ddb:dateoccured>      <ddb:entrytitle>WHID 2004-1: Biggest Web Problem Isn&amp;#039;t About Privacy, It&amp;#039;s Sloppy Security - OpenTable</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://snafu.fooworld.org/~fubob/pubs/wsj-gomes1.txt&quot;&gt;Biggest Web Problem Isn't About Privacy, It's Sloppy Security&lt;/a&gt; [Wallstreet Journal (Archive Copy), Jan 26 2004]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2004-1</ddb:whidid>    </item>    <item>      <title>WHID 2004-7: More Scary Tales Involving Big Holes In Web-Site Security - University Sub Service</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=33659</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2004-7: More Scary Tales Involving Big Holes In Web-Site Security - University Sub Service&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2004-7&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;August 4, 2005&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://snafu.fooworld.org/~fubob/pubs/wsj-gomes2.txt&quot;&gt;More Scary Tales Involving Big Holes In Web-Site Security&lt;/a&gt; [Wallstreet Journal (Archive Copy), Feb 2 2004]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://www.cs.umass.edu/~kevinfu/news/wsj-gomes2.txt&quot;&gt;http://www.cs.umass.edu/~kevinfu/news/wsj-gomes2.txt&lt;/a></description>      <pubDate>Wed, 16 Jun 2010 20:25:47 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>August 4, 2005</ddb:dateoccured>      <ddb:entrytitle>WHID 2004-7: More Scary Tales Involving Big Holes In Web-Site Security - University Sub Service</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Additional information:&lt;/p&gt;&#13;&#10;&lt;ul&gt;&#13;&#10;&lt;li&gt;&lt;a href=&quot;http://snafu.fooworld.org/~fubob/pubs/wsj-gomes2.txt&quot;&gt;More Scary Tales Involving Big Holes In Web-Site Security&lt;/a&gt; [Wallstreet Journal (Archive Copy), Feb 2 2004]&lt;/li&gt;&#13;&#10;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference>http://www.cs.umass.edu/~kevinfu/news/wsj-gomes2.txt</ddb:reference>      <ddb:whidid>2004-7</ddb:whidid>    </item>    <item>      <title>WHID 2004-4: More Scary Tales Involving Big Holes In Web-Site Security - Kohl&amp;#039;s</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=33654</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2004-4: More Scary Tales Involving Big Holes In Web-Site Security - Kohl&amp;#039;s&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2004-4&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;August 4, 2005&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://snafu.fooworld.org/~fubob/pubs/wsj-gomes2.txt&quot;&gt;More Scary Tales Involving Big Holes In Web-Site Security&lt;/a&gt; [Wallstreet Journal (Archive Copy), Feb 2 2004]&lt;/li&gt;&lt;br&gt;&lt;/ul></description>      <pubDate>Wed, 16 Jun 2010 20:26:50 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>August 4, 2005</ddb:dateoccured>      <ddb:entrytitle>WHID 2004-4: More Scary Tales Involving Big Holes In Web-Site Security - Kohl&amp;#039;s</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://snafu.fooworld.org/~fubob/pubs/wsj-gomes2.txt&quot;&gt;More Scary Tales Involving Big Holes In Web-Site Security&lt;/a&gt; [Wallstreet Journal (Archive Copy), Feb 2 2004]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2004-4</ddb:whidid>    </item>    <item>      <title>WHID 2004-3: More Scary Tales Involving Big Holes In Web-Site Security - Iomega</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=33649</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2004-3: More Scary Tales Involving Big Holes In Web-Site Security - Iomega&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2004-3&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;August 4, 2005&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://snafu.fooworld.org/~fubob/pubs/wsj-gomes2.txt&quot;&gt;More Scary Tales Involving Big Holes In Web&lt;/a&gt; [Wallstreet Journal (Archive Copy), Feb 2 2004]&lt;/li&gt;&lt;br&gt;&lt;/ul></description>      <pubDate>Wed, 16 Jun 2010 20:27:18 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>August 4, 2005</ddb:dateoccured>      <ddb:entrytitle>WHID 2004-3: More Scary Tales Involving Big Holes In Web-Site Security - Iomega</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://snafu.fooworld.org/~fubob/pubs/wsj-gomes2.txt&quot;&gt;More Scary Tales Involving Big Holes In Web&lt;/a&gt; [Wallstreet Journal (Archive Copy), Feb 2 2004]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2004-3</ddb:whidid>    </item>    <item>      <title>WHID 2005-27: Phishers hack eBay</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=33798</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2005-27: Phishers hack eBay&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2005-27&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;August 8, 2005&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Phishing&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;A bug in an eBay site allowed Phishers to redirect users to their own servers after feeling details at the genuine eBay site&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.macworld.com/news/2005/08/02/phishers/index.php?lsrc=mwrss&quot;&gt;Phishers hack eBay&lt;/a&gt; [MacWorld, Aug 2 2005]&lt;/li&gt;&lt;br&gt;&lt;/ul></description>      <pubDate>Wed, 16 Jun 2010 19:39:25 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>August 8, 2005</ddb:dateoccured>      <ddb:entrytitle>WHID 2005-27: Phishers hack eBay</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;A bug in an eBay site allowed Phishers to redirect users to their own servers after feeling details at the genuine eBay site&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.macworld.com/news/2005/08/02/phishers/index.php?lsrc=mwrss&quot;&gt;Phishers hack eBay&lt;/a&gt; [MacWorld, Aug 2 2005]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Phishing</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2005-27</ddb:whidid>    </item>    <item>      <title>WHID 2004-5: More Scary Tales Involving Big Holes In Web-Site Security - Gateway</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=33644</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2004-5: More Scary Tales Involving Big Holes In Web-Site Security - Gateway&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2004-5&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;August 4, 2005&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://snafu.fooworld.org/~fubob/pubs/wsj-gomes2.txt&quot;&gt;More Scary Tales Involving Big Holes In Web-Site Security&lt;/a&gt; [Wallstreet Journal (Archive Copy), Feb 2 2004]&lt;/li&gt;&lt;br&gt;&lt;/ul></description>      <pubDate>Wed, 16 Jun 2010 20:24:59 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>August 4, 2005</ddb:dateoccured>      <ddb:entrytitle>WHID 2004-5: More Scary Tales Involving Big Holes In Web-Site Security - Gateway</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://snafu.fooworld.org/~fubob/pubs/wsj-gomes2.txt&quot;&gt;More Scary Tales Involving Big Holes In Web-Site Security&lt;/a&gt; [Wallstreet Journal (Archive Copy), Feb 2 2004]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2004-5</ddb:whidid>    </item>    <item>      <title>WHID 2005-31: Hacker forced new planet discovery out of the closet</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=33803</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2005-31: Hacker forced new planet discovery out of the closet&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2005-31&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;August 4, 2005&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Extortion&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.theinquirer.net/?article=25031&quot;&gt;Hacker forced new planet discovery out of the closet &lt;/a&gt; [The Inquierer, Aug 1 2005]&lt;/li&gt;&lt;br&gt;&lt;/ul></description>      <pubDate>Wed, 16 Jun 2010 19:33:01 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>August 4, 2005</ddb:dateoccured>      <ddb:entrytitle>WHID 2005-31: Hacker forced new planet discovery out of the closet</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.theinquirer.net/?article=25031&quot;&gt;Hacker forced new planet discovery out of the closet &lt;/a&gt; [The Inquierer, Aug 1 2005]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Extortion</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2005-31</ddb:whidid>    </item>    <item>      <title>WHID 2004-6: More Scary Tales Involving Big Holes In Web-Site Security - Tiffany</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=33639</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2004-6: More Scary Tales Involving Big Holes In Web-Site Security - Tiffany&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2004-6&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;August 4, 2005&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://snafu.fooworld.org/~fubob/pubs/wsj-gomes2.txt&quot;&gt;More Scary Tales Involving Big Holes In Web-Site Security&lt;/a&gt; [Wallstreet Journal (Archive Copy), Feb 2 2004]&lt;/li&gt;&lt;br&gt;&lt;/ul></description>      <pubDate>Wed, 16 Jun 2010 20:24:11 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>August 4, 2005</ddb:dateoccured>      <ddb:entrytitle>WHID 2004-6: More Scary Tales Involving Big Holes In Web-Site Security - Tiffany</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://snafu.fooworld.org/~fubob/pubs/wsj-gomes2.txt&quot;&gt;More Scary Tales Involving Big Holes In Web-Site Security&lt;/a&gt; [Wallstreet Journal (Archive Copy), Feb 2 2004]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2004-6</ddb:whidid>    </item>    <item>      <title>WHID 2005-30: Blogger Developers Network Blog Cracked</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=33808</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2005-30: Blogger Developers Network Blog Cracked&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2005-30&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;August 4, 2005&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Defacement&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Official answer from Blogger was that this was not the result of a hack attempt but of a subtle bug that occurred because our Developer's Network blog is a special case [it's got two names, 'code.blogger.com' and 'code.blogspot.com'].&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://google-blog.dirson.com/post.new/0272/&quot;&gt;Blogger Developers Network Blog Cracked&lt;/a&gt; [, Jul 31 2005]&lt;/li&gt;&lt;br&gt;&lt;/ul></description>      <pubDate>Wed, 16 Jun 2010 19:34:49 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>August 4, 2005</ddb:dateoccured>      <ddb:entrytitle>WHID 2005-30: Blogger Developers Network Blog Cracked</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Official answer from Blogger was that this was not the result of a hack attempt but of a subtle bug that occurred because our Developer's Network blog is a special case [it's got two names, 'code.blogger.com' and 'code.blogspot.com'].&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://google-blog.dirson.com/post.new/0272/&quot;&gt;Blogger Developers Network Blog Cracked&lt;/a&gt; [, Jul 31 2005]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Defacement</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2005-30</ddb:whidid>    </item>    <item>      <title>WHID 2005-65: LexisNexis Data Breach</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34783</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2005-65: LexisNexis Data Breach&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2005-65&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;February 17, 2008&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;The LexisNexis data breach is not new, but we have recently decided to &lt;a hre=&quot;http://www.webappsec.org/projects/whid/byid_id_2007-65.shtml&quot;&gt;start tracking&lt;/a&gt; abuse of insufficient automation measures and are adding historical incidents.&lt;/p&gt;&lt;br&gt;&lt;p&gt;In this incident a group of people opened accounts at data broker LexisNexis and used automated tools to extract a large amount of personal information provided by the service.&lt;/p&gt;&lt;br&gt;&lt;p&gt;As usual in such cases there is a question of whether the attack was a criminal activity, violation of the license agreement of the information provider or plainly legal. In this regard it is interesting to note that the group arrested in the incident was also responsible for the hacking to &lt;a href=&quot; http://www.webappsec.org/projects/whid/byid_id_2005-5.shtml&quot;&gt;Paris Hilton Vodafone account&lt;/a&gt;, which was clearly an unlawful act.&lt;br&gt;&lt;/p&gt;&lt;p&gt;Back in 2005 this data breach was one of the first such incidents, generated a lot of media interest, and led to more regulation regarding information aggregators. Interestingly, the excuse given by the company was that the incident was that there was no security failure in the web site, but that the procedures where lacking. We accepted this story at the time, but today we believe that such automation and scraping attacks are among the most dangerous attacks.&lt;/p&gt;&lt;br&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.washingtonpost.com/wp-dyn/content/article/2006/06/30/AR2006063001222.html&quot;&gt;Arrests Made in '05 LexisNexis Data Breach&lt;/a&gt; [Washington Post, Jun 30 2006]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.washingtonpost.com/wp-dyn/articles/A45756-2005Apr12.html&quot;&gt;LexisNexis Data Breach Bigger Than Estimated&lt;/a&gt; [Washington Post, Apr 13 2008]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.nytimes.com/2005/04/13/technology/13theft.html&quot;&gt;Security Breach at LexisNexis Now Appears Larger&lt;/a&gt; [New York Times, Apr 13 2008]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Information Services&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA</description>      <pubDate>Wed, 16 Jun 2010 18:52:35 -0400</pubDate>      <ddb:attackedentityfield>Information Services</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>February 17, 2008</ddb:dateoccured>      <ddb:entrytitle>WHID 2005-65: LexisNexis Data Breach</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;The LexisNexis data breach is not new, but we have recently decided to &lt;a hre=&quot;http://www.webappsec.org/projects/whid/byid_id_2007-65.shtml&quot;&gt;start tracking&lt;/a&gt; abuse of insufficient automation measures and are adding historical incidents.&lt;/p&gt;&#13;&lt;p&gt;In this incident a group of people opened accounts at data broker LexisNexis and used automated tools to extract a large amount of personal information provided by the service.&lt;/p&gt;&#13;&lt;p&gt;As usual in such cases there is a question of whether the attack was a criminal activity, violation of the license agreement of the information provider or plainly legal. In this regard it is interesting to note that the group arrested in the incident was also responsible for the hacking to &lt;a href=&quot; http://www.webappsec.org/projects/whid/byid_id_2005-5.shtml&quot;&gt;Paris Hilton Vodafone account&lt;/a&gt;, which was clearly an unlawful act.&#13;&lt;/p&gt;&lt;p&gt;Back in 2005 this data breach was one of the first such incidents, generated a lot of media interest, and led to more regulation regarding information aggregators. Interestingly, the excuse given by the company was that the incident was that there was no security failure in the web site, but that the procedures where lacking. We accepted this story at the time, but today we believe that such automation and scraping attacks are among the most dangerous attacks.&lt;/p&gt;&#13;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.washingtonpost.com/wp-dyn/content/article/2006/06/30/AR2006063001222.html&quot;&gt;Arrests Made in '05 LexisNexis Data Breach&lt;/a&gt; [Washington Post, Jun 30 2006]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.washingtonpost.com/wp-dyn/articles/A45756-2005Apr12.html&quot;&gt;LexisNexis Data Breach Bigger Than Estimated&lt;/a&gt; [Washington Post, Apr 13 2008]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.nytimes.com/2005/04/13/technology/13theft.html&quot;&gt;Security Breach at LexisNexis Now Appears Larger&lt;/a&gt; [New York Times, Apr 13 2008]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2005-65</ddb:whidid>    </item>    <item>      <title>WHID 2004-9: Billing and personal information leakage due to lack of authentication on a phone company web site</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=33633</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2004-9: Billing and personal information leakage due to lack of authentication on a phone company web site&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2004-9&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;A billing information system required only phone number and zip code to pull up account details&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://searchsecurity.techtarget.com/originalContent/0,289142,sid14_gci969836,00.html&quot;&gt;A security tale: From vulnerability discovery to disaster&lt;/a&gt; [Search Security, Jun 14 2004]&lt;/li&gt;&lt;br&gt;&lt;/ul></description>      <pubDate>Wed, 16 Jun 2010 20:18:54 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured></ddb:dateoccured>      <ddb:entrytitle>WHID 2004-9: Billing and personal information leakage due to lack of authentication on a phone company web site</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;A billing information system required only phone number and zip code to pull up account details&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://searchsecurity.techtarget.com/originalContent/0,289142,sid14_gci969836,00.html&quot;&gt;A security tale: From vulnerability discovery to disaster&lt;/a&gt; [Search Security, Jun 14 2004]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2004-9</ddb:whidid>    </item>    <item>      <title>WHID 2005-25: No Charges Filed Yet Against South Charlotte Computer Hacker</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=33813</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2005-25: No Charges Filed Yet Against South Charlotte Computer Hacker&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2005-25&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;July 31, 2005&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;A man hacked into a competing web site&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.wsoctv.com/news/4773654/detail.html&quot;&gt;No Charges Filed Yet Against South Charlotte Computer Hacker&lt;/a&gt; [WSOC-TV, Jul 26 2005]&lt;/li&gt;&lt;br&gt;&lt;/ul></description>      <pubDate>Wed, 16 Jun 2010 19:41:21 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>July 31, 2005</ddb:dateoccured>      <ddb:entrytitle>WHID 2005-25: No Charges Filed Yet Against South Charlotte Computer Hacker</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;A man hacked into a competing web site&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.wsoctv.com/news/4773654/detail.html&quot;&gt;No Charges Filed Yet Against South Charlotte Computer Hacker&lt;/a&gt; [WSOC-TV, Jul 26 2005]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2005-25</ddb:whidid>    </item>    <item>      <title>WHID 2004-10: SQL Injection and XSS on presidential campaign web sites</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=33627</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2004-10: SQL Injection and XSS on presidential campaign web sites&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2004-10&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Disclosure Only&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;C:UsersOfer ShezafDocuments&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://wired-vig.wired.com/news/infostructure/0,1377,64036,00.html?tw=wn_tophead_3&quot;&gt;Campaign Sites Lack Security&lt;/a&gt; [Wired, Jun 30 2004]&lt;/li&gt;&lt;br&gt;&lt;/ul></description>      <pubDate>Wed, 16 Jun 2010 20:18:15 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured></ddb:dateoccured>      <ddb:entrytitle>WHID 2004-10: SQL Injection and XSS on presidential campaign web sites</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;C:UsersOfer ShezafDocuments&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://wired-vig.wired.com/news/infostructure/0,1377,64036,00.html?tw=wn_tophead_3&quot;&gt;Campaign Sites Lack Security&lt;/a&gt; [Wired, Jun 30 2004]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Disclosure Only</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2004-10</ddb:whidid>    </item>    <item>      <title>WHID 2005-24: Firefox marketing site hacked</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=33818</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2005-24: Firefox marketing site hacked&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2005-24&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;July 15, 2005&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://news.zdnet.com/2100-1009_22-5790030.html&quot;&gt;Firefox marketing site hacked&lt;/a&gt; [Zdnet, Jul 15 2005]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://news.com.com/Firefox+marketing+site+hacked/2100-7349_3-5790030.html?part=rss&amp;amp;tag=5790030&amp;amp;subj=news&quot;&gt;Firefox marketing site hacked&lt;/a&gt; [C-Net, Jul 15 2005]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://arstechnica.com/news.ars/post/20050715-5101.html&quot;&gt;Promotional firefox community site hacked&lt;/a&gt; [ars technica, Jul 15 2005]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.eweek.com/article2/0,1759,1837657,00.asp?kc=EWRSS03119TX1K0000594&quot;&gt;SpreadFirefox Site Hacked, Data Leaked&lt;/a&gt; [eWeek, Jul 15 2005]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.spreadfirefox.com/node/16836&quot;&gt;Spread Firefox Downtime&lt;/a&gt; [Spread Firefox, Jul 15 2005]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.networkworld.com/news/2005/071505-mozilla-hack.html?fsrc=rss-security&quot;&gt;Mozilla marketing site hacked&lt;/a&gt; [Network World, Jul 15 2005]&lt;/li&gt;&lt;br&gt;&lt;/ul></description>      <pubDate>Wed, 16 Jun 2010 19:44:09 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>July 15, 2005</ddb:dateoccured>      <ddb:entrytitle>WHID 2005-24: Firefox marketing site hacked</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://news.zdnet.com/2100-1009_22-5790030.html&quot;&gt;Firefox marketing site hacked&lt;/a&gt; [Zdnet, Jul 15 2005]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://news.com.com/Firefox+marketing+site+hacked/2100-7349_3-5790030.html?part=rss&amp;amp;tag=5790030&amp;amp;subj=news&quot;&gt;Firefox marketing site hacked&lt;/a&gt; [C-Net, Jul 15 2005]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://arstechnica.com/news.ars/post/20050715-5101.html&quot;&gt;Promotional firefox community site hacked&lt;/a&gt; [ars technica, Jul 15 2005]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.eweek.com/article2/0,1759,1837657,00.asp?kc=EWRSS03119TX1K0000594&quot;&gt;SpreadFirefox Site Hacked, Data Leaked&lt;/a&gt; [eWeek, Jul 15 2005]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.spreadfirefox.com/node/16836&quot;&gt;Spread Firefox Downtime&lt;/a&gt; [Spread Firefox, Jul 15 2005]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.networkworld.com/news/2005/071505-mozilla-hack.html?fsrc=rss-security&quot;&gt;Mozilla marketing site hacked&lt;/a&gt; [Network World, Jul 15 2005]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2005-24</ddb:whidid>    </item>    <item>      <title></title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=57969</link>      <description>&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Government&lt;br&gt;&lt;b&gt;Reference: &lt;/b></description>      <pubDate>Mon, 19 Jul 2010 20:35:07 -0400</pubDate>      <ddb:attackedentityfield>Government</ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured></ddb:dateoccured>      <ddb:entrytitle></ddb:entrytitle>      <ddb:incidentdescription></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome></ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid></ddb:whidid>    </item>    <item>      <title>WHID 2004-12: XSS in Gmail</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=33622</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2004-12: XSS in Gmail&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2004-12&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;July 11, 2005&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Disclosure Only&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;An XSS was found in G-Mail&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.theregister.co.uk/2004/10/29/gmail_vuln/&quot;&gt;Gmail accounts 'wide open to exploit' - report&lt;/a&gt; [The Register, Oct 29 2004]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://net.nana.co.il/Article/?ArticleID=155025&amp;amp;sid=10&quot;&gt;NetLife Exclusive: Security hole found in Gmail&lt;/a&gt; [Nana NetLife, Oct 27 2004]&lt;/li&gt;&lt;br&gt;&lt;/ul></description>      <pubDate>Wed, 16 Jun 2010 20:17:13 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>July 11, 2005</ddb:dateoccured>      <ddb:entrytitle>WHID 2004-12: XSS in Gmail</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;An XSS was found in G-Mail&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.theregister.co.uk/2004/10/29/gmail_vuln/&quot;&gt;Gmail accounts 'wide open to exploit' - report&lt;/a&gt; [The Register, Oct 29 2004]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://net.nana.co.il/Article/?ArticleID=155025&amp;amp;sid=10&quot;&gt;NetLife Exclusive: Security hole found in Gmail&lt;/a&gt; [Nana NetLife, Oct 27 2004]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Disclosure Only</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2004-12</ddb:whidid>    </item>    <item>      <title>WHID 2003-8: SQL Injection in PetCo.com leads to FTC investigation</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=33617</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2003-8: SQL Injection in PetCo.com leads to FTC investigation&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2003-8&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Disclosure Only&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.infoworld.com/article/04/11/17/HNpetco_1.html&quot;&gt;Petco settles charge it left customer data exposed&lt;/a&gt; [Infoeworld, Nov 17 2004]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.securityfocus.com/news/9957&quot;&gt;Petco settles with FTC over cyber security gaffe&lt;/a&gt; [Security Focus, Nov 17 2004]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.securityfocus.com/news/7581&quot;&gt;FTC investigates PetCo.com security hole&lt;/a&gt; [Security Focus, Dec 5 2003]&lt;/li&gt;&lt;br&gt;&lt;/ul></description>      <pubDate>Wed, 16 Jun 2010 20:32:07 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured></ddb:dateoccured>      <ddb:entrytitle>WHID 2003-8: SQL Injection in PetCo.com leads to FTC investigation</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.infoworld.com/article/04/11/17/HNpetco_1.html&quot;&gt;Petco settles charge it left customer data exposed&lt;/a&gt; [Infoeworld, Nov 17 2004]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.securityfocus.com/news/9957&quot;&gt;Petco settles with FTC over cyber security gaffe&lt;/a&gt; [Security Focus, Nov 17 2004]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.securityfocus.com/news/7581&quot;&gt;FTC investigates PetCo.com security hole&lt;/a&gt; [Security Focus, Dec 5 2003]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Disclosure Only</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2003-8</ddb:whidid>    </item>    <item>      <title>WHID 2005-23: Chinese hacker held in Web data theft</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=33823</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2005-23: Chinese hacker held in Web data theft&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2005-23&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;July 11, 2005&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;The hacker who penetrated Kakaku.com was arrested after breaking into Club Tourism International Inc. Hacking was done in order to earn money to pay for tuition.&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.contentguarder.com/news/web-content-news-0009.htm&quot;&gt;Chinese hacker held in Web data theft&lt;/a&gt; [Asahi Shimbun, Jul 7 2005]&lt;/li&gt;&lt;br&gt;&lt;/ul></description>      <pubDate>Wed, 16 Jun 2010 19:45:08 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>July 11, 2005</ddb:dateoccured>      <ddb:entrytitle>WHID 2005-23: Chinese hacker held in Web data theft</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;The hacker who penetrated Kakaku.com was arrested after breaking into Club Tourism International Inc. Hacking was done in order to earn money to pay for tuition.&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.contentguarder.com/news/web-content-news-0009.htm&quot;&gt;Chinese hacker held in Web data theft&lt;/a&gt; [Asahi Shimbun, Jul 7 2005]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2005-23</ddb:whidid>    </item>    <item>      <title>WHID 2005-22: MS UK defaced in hacking attack</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=33828</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2005-22: MS UK defaced in hacking attack&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2005-22&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;July 11, 2005&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Defacement&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Microsoft UK site defaced due to server misconfiguration&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.theregister.co.uk/2005/07/06/msuk_hacked/&quot;&gt;MS UK defaced in hacking attack&lt;/a&gt; [The Register, Jul 6 2005]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.zone-h.org/index2.php?option=com_mirrorwrp&amp;amp;Itemid=43&amp;amp;id=2531794&quot;&gt;MS UK Zone-H defacements archive&lt;/a&gt; [Zone-H, Jul 6 2005]&lt;/li&gt;&lt;br&gt;&lt;/ul></description>      <pubDate>Wed, 16 Jun 2010 19:45:50 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>July 11, 2005</ddb:dateoccured>      <ddb:entrytitle>WHID 2005-22: MS UK defaced in hacking attack</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Microsoft UK site defaced due to server misconfiguration&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.theregister.co.uk/2005/07/06/msuk_hacked/&quot;&gt;MS UK defaced in hacking attack&lt;/a&gt; [The Register, Jul 6 2005]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.zone-h.org/index2.php?option=com_mirrorwrp&amp;amp;Itemid=43&amp;amp;id=2531794&quot;&gt;MS UK Zone-H defacements archive&lt;/a&gt; [Zone-H, Jul 6 2005]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Defacement</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2005-22</ddb:whidid>    </item>    <item>      <title>WHID 2004-16: Lycos Free Email XSS</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=33612</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2004-16: Lycos Free Email XSS&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2004-16&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;July 11, 2005&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Disclosure Only&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;An XSS was found in Lycos Web Mail&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.securiteam.com/securitynews/6A00N20C1C.html&quot;&gt;Lycos Free Email Cross-Site Scripting Vulnerability&lt;/a&gt; [SecriTeam, Dec 27 2004]&lt;/li&gt;&lt;br&gt;&lt;/ul></description>      <pubDate>Wed, 16 Jun 2010 20:14:22 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>July 11, 2005</ddb:dateoccured>      <ddb:entrytitle>WHID 2004-16: Lycos Free Email XSS</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;An XSS was found in Lycos Web Mail&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.securiteam.com/securitynews/6A00N20C1C.html&quot;&gt;Lycos Free Email Cross-Site Scripting Vulnerability&lt;/a&gt; [SecriTeam, Dec 27 2004]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Disclosure Only</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2004-16</ddb:whidid>    </item>    <item>      <title>WHID 2005-3: Misconfiguration issues in paid wireless access and billing applications</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=33606</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2005-3: Misconfiguration issues in paid wireless access and billing applications&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2005-3&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Multiple misconfiguration problems such as browsable directories, physical path revealing and default or weak passwords&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.thinkcomputer.com/corporate/news/pressreleases.html?id=17&quot;&gt;Think Discovers Critical Flaws in U.S. Transportation Security&lt;/a&gt; [Vulnerabiliy Publisher's Site, Feb 1 2005]&lt;/li&gt;&lt;br&gt;&lt;/ul></description>      <pubDate>Wed, 16 Jun 2010 20:10:26 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured></ddb:dateoccured>      <ddb:entrytitle>WHID 2005-3: Misconfiguration issues in paid wireless access and billing applications</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Multiple misconfiguration problems such as browsable directories, physical path revealing and default or weak passwords&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.thinkcomputer.com/corporate/news/pressreleases.html?id=17&quot;&gt;Think Discovers Critical Flaws in U.S. Transportation Security&lt;/a&gt; [Vulnerabiliy Publisher's Site, Feb 1 2005]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2005-3</ddb:whidid>    </item>    <item>      <title>WHID 2005-18: Hacker hits Duke system</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=33833</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2005-18: Hacker hits Duke system&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2005-18&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://seclists.org/lists/isn/2005/Jun/0005.html&quot;&gt;Hacker hits Duke system&lt;/a&gt; [The News Observer, Jun 5 2005]&lt;/li&gt;&lt;br&gt;&lt;/ul></description>      <pubDate>Wed, 16 Jun 2010 19:51:29 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured></ddb:dateoccured>      <ddb:entrytitle>WHID 2005-18: Hacker hits Duke system</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://seclists.org/lists/isn/2005/Jun/0005.html&quot;&gt;Hacker hits Duke system&lt;/a&gt; [The News Observer, Jun 5 2005]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2005-18</ddb:whidid>    </item>    <item>      <title>WHID 2005-1: Gmail Bug Exposes E-mails messages of other users</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=33601</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2005-1: Gmail Bug Exposes E-mails messages of other users&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2005-1&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;July 11, 2005&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Disclosure Only&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Parameter tampering enabled exposing sensitive information in G-Mail&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.betanews.com/article/Gmail_Bug_Exposes_Emails_to_Hackers/1105561408&quot;&gt;Gmail Bug Exposes E-mails to Hackers&lt;/a&gt; [Beta News, Jan 12 2005]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://it.slashdot.org/article.pl?sid=05/01/12/1655246&amp;amp;tid=172&amp;amp;tid=215&amp;amp;tid=217&amp;amp;tid=218&quot;&gt;Gmail Messages Are Vulnerable To Interception&lt;/a&gt; [Slash.Dot, Jan 12 2005]&lt;/li&gt;&lt;br&gt;&lt;/ul></description>      <pubDate>Wed, 16 Jun 2010 20:11:36 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>July 11, 2005</ddb:dateoccured>      <ddb:entrytitle>WHID 2005-1: Gmail Bug Exposes E-mails messages of other users</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Parameter tampering enabled exposing sensitive information in G-Mail&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.betanews.com/article/Gmail_Bug_Exposes_Emails_to_Hackers/1105561408&quot;&gt;Gmail Bug Exposes E-mails to Hackers&lt;/a&gt; [Beta News, Jan 12 2005]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://it.slashdot.org/article.pl?sid=05/01/12/1655246&amp;amp;tid=172&amp;amp;tid=215&amp;amp;tid=217&amp;amp;tid=218&quot;&gt;Gmail Messages Are Vulnerable To Interception&lt;/a&gt; [Slash.Dot, Jan 12 2005]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Disclosure Only</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2005-1</ddb:whidid>    </item>    <item>      <title>WHID 2005-2: Froogle XSS</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=33596</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2005-2: Froogle XSS&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2005-2&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;July 11, 2005&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Disclosure Only&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;An XSS was found in Froogle&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.theregister.co.uk/2005/01/17/google_security_bugs/&quot;&gt;Google plugs brace of GMail security flaws&lt;/a&gt; [The Register, Jan 14 2005]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.eweek.com/article2/0,1759,1751689,00.asp&quot;&gt;Google Plugs Cookie-Theft Data Leak&lt;/a&gt; [eWeek, Jan 14 2005]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://packetstormsecurity.nl/0501-exploits/froogleCookie.txt&quot;&gt;Froogle XSS&lt;/a&gt; [Packet Storm, ]&lt;/li&gt;&lt;br&gt;&lt;/ul></description>      <pubDate>Wed, 16 Jun 2010 20:10:53 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>July 11, 2005</ddb:dateoccured>      <ddb:entrytitle>WHID 2005-2: Froogle XSS</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;An XSS was found in Froogle&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.theregister.co.uk/2005/01/17/google_security_bugs/&quot;&gt;Google plugs brace of GMail security flaws&lt;/a&gt; [The Register, Jan 14 2005]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.eweek.com/article2/0,1759,1751689,00.asp&quot;&gt;Google Plugs Cookie-Theft Data Leak&lt;/a&gt; [eWeek, Jan 14 2005]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://packetstormsecurity.nl/0501-exploits/froogleCookie.txt&quot;&gt;Froogle XSS&lt;/a&gt; [Packet Storm, ]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Disclosure Only</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2005-2</ddb:whidid>    </item>    <item>      <title>WHID 2005-16: MSN site hacked in South Korea</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=33838</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2005-16: MSN site hacked in South Korea&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2005-16&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Session Hijacking&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;The web site was modified to include password stealing code&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.usatoday.com/tech/news/2005-06-02-hacked_x.htm&quot;&gt;Microsoft admits MSN site hacked in South Korea&lt;/a&gt; [USA Today, Jun 2 2005]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://abcnews.go.com/Technology/wireStory?id=817338&quot;&gt;MSN Site Hacking Went Undetected for Days&lt;/a&gt; [ABC News, Jun 3 2005]&lt;/li&gt;&lt;br&gt;&lt;/ul></description>      <pubDate>Wed, 16 Jun 2010 19:53:20 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured></ddb:dateoccured>      <ddb:entrytitle>WHID 2005-16: MSN site hacked in South Korea</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;The web site was modified to include password stealing code&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.usatoday.com/tech/news/2005-06-02-hacked_x.htm&quot;&gt;Microsoft admits MSN site hacked in South Korea&lt;/a&gt; [USA Today, Jun 2 2005]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://abcnews.go.com/Technology/wireStory?id=817338&quot;&gt;MSN Site Hacking Went Undetected for Days&lt;/a&gt; [ABC News, Jun 3 2005]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Session Hijacking</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2005-16</ddb:whidid>    </item>    <item>      <title>WHID 2005-6: Tampering with parameters allows access to others account data on PayMaxx Inc. site</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=33591</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2005-6: Tampering with parameters allows access to others account data on PayMaxx Inc. site&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2005-6&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Parameter tampering enabled jumping into someone else's account data on PayMaxx Inc. site&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://news.com.com/Payroll+site+closes+on+security+worries/2100-1029_3-5587859.html?tag=cd.hed&quot;&gt;Payroll site closes on security worries&lt;/a&gt; [CNet, Feb 23 2005]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.thinkcomputer.com/corporate/news/pressreleases.html?id=18&quot;&gt;Think Finds Flaw Revealing Up To 100,000 Social Security Numbers&lt;/a&gt; [Vulnerabiliy Publisher's Site, Feb 23 2005]&lt;/li&gt;&lt;br&gt;&lt;/ul></description>      <pubDate>Wed, 16 Jun 2010 20:06:48 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured></ddb:dateoccured>      <ddb:entrytitle>WHID 2005-6: Tampering with parameters allows access to others account data on PayMaxx Inc. site</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Parameter tampering enabled jumping into someone else's account data on PayMaxx Inc. site&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://news.com.com/Payroll+site+closes+on+security+worries/2100-1029_3-5587859.html?tag=cd.hed&quot;&gt;Payroll site closes on security worries&lt;/a&gt; [CNet, Feb 23 2005]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.thinkcomputer.com/corporate/news/pressreleases.html?id=18&quot;&gt;Think Finds Flaw Revealing Up To 100,000 Social Security Numbers&lt;/a&gt; [Vulnerabiliy Publisher's Site, Feb 23 2005]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2005-6</ddb:whidid>    </item>    <item>      <title>WHID 2005-12: Insufficient authentication on Arbela mutual insurance allowed access to private data</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=33586</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2005-12: Insufficient authentication on Arbela mutual insurance allowed access to private data&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2005-12&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Disclosure Only&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Extranet system accessible to the public&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.boston.com/business/technology/articles/2005/05/05/insurers_website_error_reveals_data_on_drivers/?rss_id=Boston+Globe+&quot;&gt;Insurer's website breach reveals data on drivers&lt;/a&gt; [The Boston Globe, May 5 2005]&lt;/li&gt;&lt;br&gt;&lt;/ul></description>      <pubDate>Wed, 16 Jun 2010 19:56:45 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured></ddb:dateoccured>      <ddb:entrytitle>WHID 2005-12: Insufficient authentication on Arbela mutual insurance allowed access to private data</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Extranet system accessible to the public&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.boston.com/business/technology/articles/2005/05/05/insurers_website_error_reveals_data_on_drivers/?rss_id=Boston+Globe+&quot;&gt;Insurer's website breach reveals data on drivers&lt;/a&gt; [The Boston Globe, May 5 2005]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Disclosure Only</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2005-12</ddb:whidid>    </item>    <item>      <title>WHID 2005-14: XSS on Microsoft Xbox site allowed phishing</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=33581</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2005-14: XSS on Microsoft Xbox site allowed phishing&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2005-14&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;November 8, 2005&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Phishing&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://news.com.com/Microsoft+plugs+phishing+hole+in+Xbox+site/2100-1029_3-5720241.html?tag=nl&quot;&gt;Microsoft plugs phishing hole in Xbox site&lt;/a&gt; [news.com, May 25 2005]&lt;/li&gt;&lt;br&gt;&lt;/ul></description>      <pubDate>Wed, 16 Jun 2010 19:54:13 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>November 8, 2005</ddb:dateoccured>      <ddb:entrytitle>WHID 2005-14: XSS on Microsoft Xbox site allowed phishing</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://news.com.com/Microsoft+plugs+phishing+hole+in+Xbox+site/2100-1029_3-5720241.html?tag=nl&quot;&gt;Microsoft plugs phishing hole in Xbox site&lt;/a&gt; [news.com, May 25 2005]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Phishing</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2005-14</ddb:whidid>    </item>    <item>      <title>WHID 2005-13: Hacker attacked weak point on Kakaku.com&amp;#039;s Web Site</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=33843</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2005-13: Hacker attacked weak point on Kakaku.com&amp;#039;s Web Site&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2005-13&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Downtime&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://seclists.org/lists/isn/2005/May/0041.html&quot;&gt;Web sites get costly lesson in security&lt;/a&gt; [Asahi (Japan), May 18 2005]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.cdrinfo.com/forum/tm.asp?m=110616&amp;amp;mpage=1&amp;#110616&quot;&gt;Hacker attacked weak point on Kakaku.com's Web Site&lt;/a&gt; [Asahi (Japan), May 25 2005]&lt;/li&gt;&lt;br&gt;&lt;/ul></description>      <pubDate>Wed, 16 Jun 2010 19:55:04 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured></ddb:dateoccured>      <ddb:entrytitle>WHID 2005-13: Hacker attacked weak point on Kakaku.com&amp;#039;s Web Site</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://seclists.org/lists/isn/2005/May/0041.html&quot;&gt;Web sites get costly lesson in security&lt;/a&gt; [Asahi (Japan), May 18 2005]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.cdrinfo.com/forum/tm.asp?m=110616&amp;amp;mpage=1&amp;#110616&quot;&gt;Hacker attacked weak point on Kakaku.com's Web Site&lt;/a&gt; [Asahi (Japan), May 25 2005]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Downtime</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2005-13</ddb:whidid>    </item>    <item>      <title>WHID 2005-15: Unprotected information on the University of Chicago web site</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=33576</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2005-15: Unprotected information on the University of Chicago web site&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2005-15&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Files containing sensitive information left unprotected on the web server&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://incidentresponse.uchicago.edu/&quot;&gt;University of Chicago&lt;/a&gt; [Victim's Site, May 30 2005]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://maroon.uchicago.edu/news/articles/2005/05/27/private_records_disc.php&quot;&gt;Private records discovered on server&lt;/a&gt; [Chicago Maroon, May 27 2005]&lt;/li&gt;&lt;br&gt;&lt;/ul></description>      <pubDate>Wed, 16 Jun 2010 19:53:54 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured></ddb:dateoccured>      <ddb:entrytitle>WHID 2005-15: Unprotected information on the University of Chicago web site</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Files containing sensitive information left unprotected on the web server&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://incidentresponse.uchicago.edu/&quot;&gt;University of Chicago&lt;/a&gt; [Victim's Site, May 30 2005]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://maroon.uchicago.edu/news/articles/2005/05/27/private_records_disc.php&quot;&gt;Private records discovered on server&lt;/a&gt; [Chicago Maroon, May 27 2005]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2005-15</ddb:whidid>    </item>    <item>      <title>WHID 2005-10: Indian SATs results leaking</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=33848</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2005-10: Indian SATs results leaking&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2005-10&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;November 8, 2005&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Disclosure Only&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://blogs.law.harvard.edu/philg/comments?u=philg&amp;amp;p=7726&amp;amp;link=http%3A%2F%2Fblogs.law.harvard.edu%2Fphilg%2F2005%2F03%2F08%23a7726#a7777&quot;&gt;Indian SATs results leaking&lt;/a&gt; [Blog talkback, Mar 10 2005]&lt;/li&gt;&lt;br&gt;&lt;/ul></description>      <pubDate>Wed, 16 Jun 2010 19:58:33 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>November 8, 2005</ddb:dateoccured>      <ddb:entrytitle>WHID 2005-10: Indian SATs results leaking</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://blogs.law.harvard.edu/philg/comments?u=philg&amp;amp;p=7726&amp;amp;link=http%3A%2F%2Fblogs.law.harvard.edu%2Fphilg%2F2005%2F03%2F08%23a7726#a7777&quot;&gt;Indian SATs results leaking&lt;/a&gt; [Blog talkback, Mar 10 2005]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Disclosure Only</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2005-10</ddb:whidid>    </item>    <item>      <title>WHID 2005-17: Leakage of information due to XSS in Hotmail</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=33571</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2005-17: Leakage of information due to XSS in Hotmail&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2005-17&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Disclosure Only&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.vnunet.com/vnunet/news/2137707/hotmail-hack-fixed&quot;&gt;Microsoft fixes Hotmail hack&lt;/a&gt; [VUnet, Jun 9 2005]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.theregister.co.uk/2005/06/08/hotmail_hack/&quot;&gt;Hotmail users exposed to cookie snaffling exploit&lt;/a&gt; [The Registrer, Jun 8 2005]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.pcmag.com/article2/0,1759,1825250,00.asp&quot;&gt;MSN Site Flaw Exposes Hotmail Accounts to Prying Eyes&lt;/a&gt; [PC Magazine, Jun 7 2005]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://news.com.com/MSN+flaw+put+Hotmail+accounts+at+risk/2100-1002_3-5734448.html?part=rss&amp;amp;tag=5734448&amp;amp;subj=news&quot;&gt;MSN flaw put Hotmail accounts at risk&lt;/a&gt; [CNet, Jun 6 2005]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.net-force.nl/files/articles/hotmail_xss/&quot;&gt;Hacking hotmail, by Alex de Vries&lt;/a&gt; [Personal Web Page, Jun 4 2005]&lt;/li&gt;&lt;br&gt;&lt;/ul></description>      <pubDate>Wed, 16 Jun 2010 19:52:07 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured></ddb:dateoccured>      <ddb:entrytitle>WHID 2005-17: Leakage of information due to XSS in Hotmail</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.vnunet.com/vnunet/news/2137707/hotmail-hack-fixed&quot;&gt;Microsoft fixes Hotmail hack&lt;/a&gt; [VUnet, Jun 9 2005]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.theregister.co.uk/2005/06/08/hotmail_hack/&quot;&gt;Hotmail users exposed to cookie snaffling exploit&lt;/a&gt; [The Registrer, Jun 8 2005]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.pcmag.com/article2/0,1759,1825250,00.asp&quot;&gt;MSN Site Flaw Exposes Hotmail Accounts to Prying Eyes&lt;/a&gt; [PC Magazine, Jun 7 2005]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://news.com.com/MSN+flaw+put+Hotmail+accounts+at+risk/2100-1002_3-5734448.html?part=rss&amp;amp;tag=5734448&amp;amp;subj=news&quot;&gt;MSN flaw put Hotmail accounts at risk&lt;/a&gt; [CNet, Jun 6 2005]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.net-force.nl/files/articles/hotmail_xss/&quot;&gt;Hacking hotmail, by Alex de Vries&lt;/a&gt; [Personal Web Page, Jun 4 2005]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Disclosure Only</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2005-17</ddb:whidid>    </item>    <item>      <title>WHID 2005-19: Privacy Fears due to insufficient authentication on CVS drugstore chain web site</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=33566</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2005-19: Privacy Fears due to insufficient authentication on CVS drugstore chain web site&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2005-19&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Disclosure Only&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.computerworld.com/securitytopics/security/story/0,10801,102773,00.html&quot;&gt;Privacy Fears Prompt CVS To Turn Off Online Service  &lt;/a&gt; [Computer World, Jun 27 2005]&lt;/li&gt;&lt;br&gt;&lt;/ul></description>      <pubDate>Wed, 16 Jun 2010 19:50:17 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured></ddb:dateoccured>      <ddb:entrytitle>WHID 2005-19: Privacy Fears due to insufficient authentication on CVS drugstore chain web site</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.computerworld.com/securitytopics/security/story/0,10801,102773,00.html&quot;&gt;Privacy Fears Prompt CVS To Turn Off Online Service  &lt;/a&gt; [Computer World, Jun 27 2005]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Disclosure Only</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2005-19</ddb:whidid>    </item>    <item>      <title>WHID 2005-7: Hacker Tips Off B-School Applicants</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=33853</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2005-7: Hacker Tips Off B-School Applicants&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2005-7&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Parameter tampering to jump into someone else's account data&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.thecrimson.com/article.aspx?ref=506140&quot;&gt;Hacker Tips Off B-School Applicants&lt;/a&gt; [The Crimson, Mar 3 2005]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://poweryogi.blogspot.com/2005/03/hbsapplyyourself-admit-status-snafu.html&quot;&gt;HBS/ApplyYourself Admit Status snafu&lt;/a&gt; [Personal Blog, Mar 2 2005]&lt;/li&gt;&lt;br&gt;&lt;/ul></description>      <pubDate>Wed, 16 Jun 2010 20:05:26 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured></ddb:dateoccured>      <ddb:entrytitle>WHID 2005-7: Hacker Tips Off B-School Applicants</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Parameter tampering to jump into someone else's account data&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.thecrimson.com/article.aspx?ref=506140&quot;&gt;Hacker Tips Off B-School Applicants&lt;/a&gt; [The Crimson, Mar 3 2005]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://poweryogi.blogspot.com/2005/03/hbsapplyyourself-admit-status-snafu.html&quot;&gt;HBS/ApplyYourself Admit Status snafu&lt;/a&gt; [Personal Blog, Mar 2 2005]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2005-7</ddb:whidid>    </item>    <item>      <title>WHID 2005-21: Insufficient authentication on USC admissions site allowed access to applicants data</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=33559</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2005-21: Insufficient authentication on USC admissions site allowed access to applicants data&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2005-21&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Disclosure Only&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;A person who discovered an SQL injection vulnerability in a USC system and informed security focus about the flaw was criminally charged with breaking into the system.&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.securityfocus.com/brief/191&quot;&gt;Man charged with accessing USC student data&lt;/a&gt; [Security Focus, Apr 20 2006]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.securityfocus.com/news/11239&quot;&gt;Flawed USC admissions site allowed access to applicant data&lt;/a&gt; [Security Focus, Jul 5 2005]&lt;/li&gt;&lt;br&gt;&lt;/ul></description>      <pubDate>Wed, 16 Jun 2010 19:47:50 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured></ddb:dateoccured>      <ddb:entrytitle>WHID 2005-21: Insufficient authentication on USC admissions site allowed access to applicants data</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;A person who discovered an SQL injection vulnerability in a USC system and informed security focus about the flaw was criminally charged with breaking into the system.&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.securityfocus.com/brief/191&quot;&gt;Man charged with accessing USC student data&lt;/a&gt; [Security Focus, Apr 20 2006]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.securityfocus.com/news/11239&quot;&gt;Flawed USC admissions site allowed access to applicant data&lt;/a&gt; [Security Focus, Jul 5 2005]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Disclosure Only</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2005-21</ddb:whidid>    </item>    <item>      <title>WHID 2005-26: NISCC reveals SAP R/3 security flaw</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=33554</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2005-26: NISCC reveals SAP R/3 security flaw&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2005-26&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;July 31, 2005&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Disclosure Only&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.computerweekly.com/Home/Articles/2005/07/28/211124/NISCCrevealsSAPR3securityflaw.htm&quot;&gt;NISCC reveals SAP R/3 security flaw&lt;/a&gt; [Computer Weekly, Jul 28 2005]&lt;/li&gt;&lt;br&gt;&lt;/ul></description>      <pubDate>Wed, 16 Jun 2010 19:40:00 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>July 31, 2005</ddb:dateoccured>      <ddb:entrytitle>WHID 2005-26: NISCC reveals SAP R/3 security flaw</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.computerweekly.com/Home/Articles/2005/07/28/211124/NISCCrevealsSAPR3securityflaw.htm&quot;&gt;NISCC reveals SAP R/3 security flaw&lt;/a&gt; [Computer Weekly, Jul 28 2005]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Disclosure Only</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2005-26</ddb:whidid>    </item>    <item>      <title>WHID 2005-29: Security issues in interactive hotel TVs</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=33548</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2005-29: Security issues in interactive hotel TVs&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2005-29&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;July 31, 2005&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Disclosure Only&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;While not strictly web security, this discussion of hotel rooms TV application security is a very good example of the dangers of our networked society&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.wired.com/news/privacy/0,1848,68370,00.html&quot;&gt;A Hacker Games the Hotel &lt;/a&gt; [Wired, Jul 30 2005]&lt;/li&gt;&lt;br&gt;&lt;/ul></description>      <pubDate>Wed, 16 Jun 2010 19:36:22 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>July 31, 2005</ddb:dateoccured>      <ddb:entrytitle>WHID 2005-29: Security issues in interactive hotel TVs</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;While not strictly web security, this discussion of hotel rooms TV application security is a very good example of the dangers of our networked society&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.wired.com/news/privacy/0,1848,68370,00.html&quot;&gt;A Hacker Games the Hotel &lt;/a&gt; [Wired, Jul 30 2005]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Disclosure Only</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2005-29</ddb:whidid>    </item>    <item>      <title>WHID 2005-8: eBay Redirect Becomes Phishing Tool</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=33858</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2005-8: eBay Redirect Becomes Phishing Tool&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2005-8&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Phishing&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.betanews.com/article/eBay_Redirect_Becomes_Phishing_Tool/1109886753&quot;&gt;eBay Redirect Becomes Phishing Tool&lt;/a&gt; [Beta News, Mar 3 2005]&lt;/li&gt;&lt;br&gt;&lt;/ul></description>      <pubDate>Wed, 16 Jun 2010 20:02:08 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured></ddb:dateoccured>      <ddb:entrytitle>WHID 2005-8: eBay Redirect Becomes Phishing Tool</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.betanews.com/article/eBay_Redirect_Becomes_Phishing_Tool/1109886753&quot;&gt;eBay Redirect Becomes Phishing Tool&lt;/a&gt; [Beta News, Mar 3 2005]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Phishing</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2005-8</ddb:whidid>    </item>    <item>      <title>WHID 2005-32: Weak password recovery on Citrix&amp;#039;s site</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=33543</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2005-32: Weak password recovery on Citrix&amp;#039;s site&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2005-32&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;August 8, 2005&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Disclosure Only&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Weak password recovery procedure at Citrix&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.securityfocus.com/archive/107/407243/30/0/threaded&quot;&gt;Example of the worst passwd recovery interface&lt;/a&gt; [WebAppSec mailing list, Aug 3 2005]&lt;/li&gt;&lt;br&gt;&lt;/ul></description>      <pubDate>Wed, 16 Jun 2010 19:31:21 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>August 8, 2005</ddb:dateoccured>      <ddb:entrytitle>WHID 2005-32: Weak password recovery on Citrix&amp;#039;s site</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Weak password recovery procedure at Citrix&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.securityfocus.com/archive/107/407243/30/0/threaded&quot;&gt;Example of the worst passwd recovery interface&lt;/a&gt; [WebAppSec mailing list, Aug 3 2005]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Disclosure Only</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2005-32</ddb:whidid>    </item>    <item>      <title>WHID 2005-9: Undisclosed application security issue on Cisco&amp;#039;s site forces global passwords reset</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=33538</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2005-9: Undisclosed application security issue on Cisco&amp;#039;s site forces global passwords reset&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2005-9&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;April 8, 2005&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Disclosure Only&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;An undisclosed application security issue on Cisco web site required resetting passwords for all registered users.&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.computerworld.com/developmenttopics/websitemgmt/story/0,10801,103661,00.html?source=NLT_PM&amp;amp;nid=103661&quot;&gt;Cisco.com passwords reset after Web site exposure&lt;/a&gt; [Computer World, Mar 8 2005]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.betanews.com/article/Cisco_Web_Site_Breached_by_Hackers/1123086248&quot;&gt;Cisco Web Site Breached by Hackers&lt;/a&gt; [Beta News, Mar 8 2005]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://news.com.com/Customers+warned+that+Cisco.com+was+breached/2100-7349_3-5816809.html?part=rss&amp;amp;tag=5816809&amp;amp;subj=news&quot;&gt;Cisco warns customers of site breach&lt;/a&gt; [Cnet, Mar 8 2005]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://taosecurity.blogspot.com/2005/08/cisco-connection-online-compromised.html&quot;&gt;Cisco Connection Online Compromised? &lt;/a&gt; [TaoSecurity Blog, Mar 8 2005]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.eweek.com/article2/0,1895,1843451,00.asp&quot;&gt;Cisco Web Portal Password Security Compromised&lt;/a&gt; [eWeek, Mar 8 2005]&lt;/li&gt;&lt;br&gt;&lt;/ul></description>      <pubDate>Wed, 16 Jun 2010 20:01:40 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>April 8, 2005</ddb:dateoccured>      <ddb:entrytitle>WHID 2005-9: Undisclosed application security issue on Cisco&amp;#039;s site forces global passwords reset</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;An undisclosed application security issue on Cisco web site required resetting passwords for all registered users.&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.computerworld.com/developmenttopics/websitemgmt/story/0,10801,103661,00.html?source=NLT_PM&amp;amp;nid=103661&quot;&gt;Cisco.com passwords reset after Web site exposure&lt;/a&gt; [Computer World, Mar 8 2005]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.betanews.com/article/Cisco_Web_Site_Breached_by_Hackers/1123086248&quot;&gt;Cisco Web Site Breached by Hackers&lt;/a&gt; [Beta News, Mar 8 2005]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://news.com.com/Customers+warned+that+Cisco.com+was+breached/2100-7349_3-5816809.html?part=rss&amp;amp;tag=5816809&amp;amp;subj=news&quot;&gt;Cisco warns customers of site breach&lt;/a&gt; [Cnet, Mar 8 2005]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://taosecurity.blogspot.com/2005/08/cisco-connection-online-compromised.html&quot;&gt;Cisco Connection Online Compromised? &lt;/a&gt; [TaoSecurity Blog, Mar 8 2005]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.eweek.com/article2/0,1895,1843451,00.asp&quot;&gt;Cisco Web Portal Password Security Compromised&lt;/a&gt; [eWeek, Mar 8 2005]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Disclosure Only</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2005-9</ddb:whidid>    </item>    <item>      <title>WHID 2005-33: Insufficient authorization on Verizon&amp;#039;s MyAccount feature</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=33532</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2005-33: Insufficient authorization on Verizon&amp;#039;s MyAccount feature&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2005-33&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;August 22, 2005&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Disclosure Only&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;A web site flaw could have allowed a user to view another subscriber's balance of remaining airtime minutes and the number of minutes that customer had used in the current billing cycle&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.washingtonpost.com/wp-dyn/content/article/2005/08/11/AR2005081102122.html&quot;&gt;Glitch on Verizon Wireless Web Site Left Data at Risk&lt;/a&gt; [Washington Post, Aug 12 2005]&lt;/li&gt;&lt;br&gt;&lt;/ul></description>      <pubDate>Wed, 16 Jun 2010 19:29:28 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>August 22, 2005</ddb:dateoccured>      <ddb:entrytitle>WHID 2005-33: Insufficient authorization on Verizon&amp;#039;s MyAccount feature</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;A web site flaw could have allowed a user to view another subscriber's balance of remaining airtime minutes and the number of minutes that customer had used in the current billing cycle&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.washingtonpost.com/wp-dyn/content/article/2005/08/11/AR2005081102122.html&quot;&gt;Glitch on Verizon Wireless Web Site Left Data at Risk&lt;/a&gt; [Washington Post, Aug 12 2005]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Disclosure Only</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2005-33</ddb:whidid>    </item>    <item>      <title>WHID 2005-5: Paris Hilton&amp;#039;s T-Mobile online account hacked</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=33864</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2005-5: Paris Hilton&amp;#039;s T-Mobile online account hacked&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2005-5&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;July 11, 2005&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Details remain sketchy, but news reports include social engineering, a guessable secret question for password recovery, and a known vulnerability is BEA WebLogic&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.washingtonpost.com/wp-dyn/content/article/2005/05/19/AR2005051900711.html&quot;&gt;Paris Hilton Hack Started With Old-Fashioned Con&lt;/a&gt; [Washington Post, May 19 2005]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.pcworld.com/news/article/0,aid,119851,00.asp&quot;&gt;Paris Hilton: Victim of T-Mobile's Web Flaws?&lt;/a&gt; [PCWorld, Mar 1 2005]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.wired.com/news/privacy/0,1848,66735,00.html&quot;&gt;Known Hole Aided T-Mobile Breach&lt;/a&gt; [Wired.com, Feb 28 2005]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.macdevcenter.com/pub/a/mac/2005/01/01/paris.html&quot;&gt;How Paris Got Hacked?&lt;/a&gt; [O'Reilly Network, Feb 22 2005]&lt;/li&gt;&lt;br&gt;&lt;/ul></description>      <pubDate>Wed, 16 Jun 2010 20:08:19 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>July 11, 2005</ddb:dateoccured>      <ddb:entrytitle>WHID 2005-5: Paris Hilton&amp;#039;s T-Mobile online account hacked</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Details remain sketchy, but news reports include social engineering, a guessable secret question for password recovery, and a known vulnerability is BEA WebLogic&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.washingtonpost.com/wp-dyn/content/article/2005/05/19/AR2005051900711.html&quot;&gt;Paris Hilton Hack Started With Old-Fashioned Con&lt;/a&gt; [Washington Post, May 19 2005]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.pcworld.com/news/article/0,aid,119851,00.asp&quot;&gt;Paris Hilton: Victim of T-Mobile's Web Flaws?&lt;/a&gt; [PCWorld, Mar 1 2005]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.wired.com/news/privacy/0,1848,66735,00.html&quot;&gt;Known Hole Aided T-Mobile Breach&lt;/a&gt; [Wired.com, Feb 28 2005]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.macdevcenter.com/pub/a/mac/2005/01/01/paris.html&quot;&gt;How Paris Got Hacked?&lt;/a&gt; [O'Reilly Network, Feb 22 2005]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2005-5</ddb:whidid>    </item>    <item>      <title>WHID 2005-41: XSS on Google&amp;#039;s AdWords enables phishing</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=33527</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2005-41: XSS on Google&amp;#039;s AdWords enables phishing&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2005-41&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;November 10, 2005&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Disclosure Only&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://news.com.com/Google+fixes+Web+site+security+bug/2100-1002_3-5892525.html?part=rss&amp;amp;tag=5892525&amp;amp;subj=news&quot;&gt;Google fixes Web site security bug&lt;/a&gt; [News.com, Oct 10 2005]&lt;/li&gt;&lt;br&gt;&lt;/ul></description>      <pubDate>Wed, 16 Jun 2010 19:14:26 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>November 10, 2005</ddb:dateoccured>      <ddb:entrytitle>WHID 2005-41: XSS on Google&amp;#039;s AdWords enables phishing</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://news.com.com/Google+fixes+Web+site+security+bug/2100-1002_3-5892525.html?part=rss&amp;amp;tag=5892525&amp;amp;subj=news&quot;&gt;Google fixes Web site security bug&lt;/a&gt; [News.com, Oct 10 2005]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Disclosure Only</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2005-41</ddb:whidid>    </item>    <item>      <title>WHID 2005-42: Default password in a common application used by schools</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=33522</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2005-42: Default password in a common application used by schools&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2005-42&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;November 10, 2005&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;The software has a default password for teachers, enabling anyone to access the system with teachers privileges.&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://sfgate.com/cgi-bin/article.cgi?f=/c/a/2005/10/21/SNAFU.TMP&quot;&gt; Software glitch reveals private data for thousands of state's students&lt;br /&gt;&lt;br&gt;S.F. administrators close program to update passwords&lt;/a&gt; [Sfgate, Oct 21 2005]&lt;/li&gt;&lt;br&gt;&lt;/ul></description>      <pubDate>Wed, 16 Jun 2010 19:13:55 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>November 10, 2005</ddb:dateoccured>      <ddb:entrytitle>WHID 2005-42: Default password in a common application used by schools</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;The software has a default password for teachers, enabling anyone to access the system with teachers privileges.&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://sfgate.com/cgi-bin/article.cgi?f=/c/a/2005/10/21/SNAFU.TMP&quot;&gt; Software glitch reveals private data for thousands of state's students&lt;br /&gt;&#13;S.F. administrators close program to update passwords&lt;/a&gt; [Sfgate, Oct 21 2005]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2005-42</ddb:whidid>    </item>    <item>      <title>WHID 2004-15: New Variant of Santy Worm Spreads</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=33871</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2004-15: New Variant of Santy Worm Spreads&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2004-15&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;December 25, 2004&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Worm&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;phpBB worm&lt;/p&gt;&lt;br&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.frsirt.com/exploits/20041225.PhpIncludeWorm.php&quot;&gt;PHP Scripts Automated Arbitrary File Inclusion&lt;/a&gt; [Vulnerabiliy Publisher's Site, Dec 25 2004]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.pcworld.com/news/article/0,aid,119051,pg,1,RSS,RSS,00.asp&quot;&gt;New Variant of Santy Worm Spreads&lt;/a&gt; [PC World, Dec 27 2004]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.computerworld.com/securitytopics/security/holes/story/0,10801,98553,00.html&quot;&gt;Santy.E worm poses threat to sites badly coded in PHP &lt;/a&gt; [Computer World, Dec 27 2004]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Various&lt;br&gt;&lt;b&gt;Attacked System Technology: &lt;/b&gt;phpBB</description>      <pubDate>Wed, 16 Jun 2010 20:15:07 -0400</pubDate>      <ddb:attackedentityfield>Various</ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology>phpBB</ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>December 25, 2004</ddb:dateoccured>      <ddb:entrytitle>WHID 2004-15: New Variant of Santy Worm Spreads</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;phpBB worm&lt;/p&gt;&#13;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.frsirt.com/exploits/20041225.PhpIncludeWorm.php&quot;&gt;PHP Scripts Automated Arbitrary File Inclusion&lt;/a&gt; [Vulnerabiliy Publisher's Site, Dec 25 2004]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.pcworld.com/news/article/0,aid,119051,pg,1,RSS,RSS,00.asp&quot;&gt;New Variant of Santy Worm Spreads&lt;/a&gt; [PC World, Dec 27 2004]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.computerworld.com/securitytopics/security/holes/story/0,10801,98553,00.html&quot;&gt;Santy.E worm poses threat to sites badly coded in PHP &lt;/a&gt; [Computer World, Dec 27 2004]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Worm</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2004-15</ddb:whidid>    </item>    <item>      <title>WHID 2005-43: XSS in Yahoo&amp;#039;s  Web mail enables phishing</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=33517</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2005-43: XSS in Yahoo&amp;#039;s  Web mail enables phishing&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2005-43&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;November 10, 2005&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Disclosure Only&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;XSS in Yahoo mail, Allows phishing&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://news.com.com/Yahoo+fixes+Web+mail+security+flaw/2100-1002_3-5907383.html&quot;&gt;Yahoo fixes Web mail security flaw&lt;/a&gt; [News.com, Oct 21 2005]&lt;/li&gt;&lt;br&gt;&lt;/ul></description>      <pubDate>Wed, 16 Jun 2010 19:13:09 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>November 10, 2005</ddb:dateoccured>      <ddb:entrytitle>WHID 2005-43: XSS in Yahoo&amp;#039;s  Web mail enables phishing</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;XSS in Yahoo mail, Allows phishing&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://news.com.com/Yahoo+fixes+Web+mail+security+flaw/2100-1002_3-5907383.html&quot;&gt;Yahoo fixes Web mail security flaw&lt;/a&gt; [News.com, Oct 21 2005]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Disclosure Only</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2005-43</ddb:whidid>    </item>    <item>      <title>WHID 2004-14: Santy worm defaces websites using PHP bug</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=33877</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2004-14: Santy worm defaces websites using PHP bug&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2004-14&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;December 22, 2004&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Worm&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Worm used Google to locate sites vulnerable to OS&lt;/p&gt;&lt;br&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://news.bbc.co.uk/1/hi/technology/4117711.stm&quot;&gt;Santy worm makes unwelcome visit&lt;/a&gt; [BBC, Dec 22 2004]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://isc.sans.org/diary.php?date=2004-12-21&quot;&gt;Santy worm defaces websites using php bug&lt;/a&gt; [Sans Storm Center, Dec 21 2004]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;Various&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Various&lt;br&gt;&lt;b&gt;Attacked System Technology: &lt;/b&gt;phpBB</description>      <pubDate>Wed, 16 Jun 2010 20:16:04 -0400</pubDate>      <ddb:attackedentityfield>Various</ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology>phpBB</ddb:attackedsystemtechnology>      <ddb:attacksourcegeography>Various</ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>December 22, 2004</ddb:dateoccured>      <ddb:entrytitle>WHID 2004-14: Santy worm defaces websites using PHP bug</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Worm used Google to locate sites vulnerable to OS&lt;/p&gt;&#13;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://news.bbc.co.uk/1/hi/technology/4117711.stm&quot;&gt;Santy worm makes unwelcome visit&lt;/a&gt; [BBC, Dec 22 2004]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://isc.sans.org/diary.php?date=2004-12-21&quot;&gt;Santy worm defaces websites using php bug&lt;/a&gt; [Sans Storm Center, Dec 21 2004]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Worm</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2004-14</ddb:whidid>    </item>    <item>      <title>WHID 2005-48: Insufficient authorization on Papa John&amp;#039;s Pizza chain web site</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=33512</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2005-48: Insufficient authorization on Papa John&amp;#039;s Pizza chain web site&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2005-48&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;November 10, 2005&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://archives.neohapsis.com/archives/fulldisclosure/2005-11/0156.html&quot;&gt;Zero Day Pizza Party - Yo Noid Advisory #00001&lt;/a&gt; [&quot;Full Disclosure&quot; Mailing List, Nov 7 2005]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://news.com.com/Pizza+chain+caught+without+fully+baked+security/2100-7349_3-5938572.html&quot;&gt;Pizza chain caught without fully baked security&lt;/a&gt; [Cnet, Nov 7 2005]&lt;/li&gt;&lt;br&gt;&lt;/ul></description>      <pubDate>Wed, 16 Jun 2010 19:08:37 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>November 10, 2005</ddb:dateoccured>      <ddb:entrytitle>WHID 2005-48: Insufficient authorization on Papa John&amp;#039;s Pizza chain web site</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://archives.neohapsis.com/archives/fulldisclosure/2005-11/0156.html&quot;&gt;Zero Day Pizza Party - Yo Noid Advisory #00001&lt;/a&gt; [&quot;Full Disclosure&quot; Mailing List, Nov 7 2005]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://news.com.com/Pizza+chain+caught+without+fully+baked+security/2100-7349_3-5938572.html&quot;&gt;Pizza chain caught without fully baked security&lt;/a&gt; [Cnet, Nov 7 2005]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2005-48</ddb:whidid>    </item>    <item>      <title>WHID 2004-13: SunTrust site XSS vulnerability exploited by for phishing</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=33883</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2004-13: SunTrust site XSS vulnerability exploited by for phishing&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2004-13&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;November 8, 2005&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Phishing&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Phishing based on XSS (Same vulnerability but a different attack that the similar September 2004 attack)&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.fool.com/News/mft/2004/mft04120810.htm&quot;&gt;Do Online Banks Facilitate Fraud?&lt;/a&gt; [The Motley Fool, Dec 8 2004]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://news.netcraft.com/archives/2004/12/06/suntrust_site_exploited_by_fraudsters.html&quot;&gt;SunTrust site exploited by fraudsters&lt;/a&gt; [NetCraft, Dec 6 2004]&lt;/li&gt;&lt;br&gt;&lt;/ul></description>      <pubDate>Wed, 16 Jun 2010 20:16:40 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>November 8, 2005</ddb:dateoccured>      <ddb:entrytitle>WHID 2004-13: SunTrust site XSS vulnerability exploited by for phishing</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Phishing based on XSS (Same vulnerability but a different attack that the similar September 2004 attack)&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.fool.com/News/mft/2004/mft04120810.htm&quot;&gt;Do Online Banks Facilitate Fraud?&lt;/a&gt; [The Motley Fool, Dec 8 2004]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://news.netcraft.com/archives/2004/12/06/suntrust_site_exploited_by_fraudsters.html&quot;&gt;SunTrust site exploited by fraudsters&lt;/a&gt; [NetCraft, Dec 6 2004]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Phishing</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2004-13</ddb:whidid>    </item>    <item>      <title>WHID 2005-64: Woman scammed QVC for $400,000+ in Internet glitch</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34574</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2005-64: Woman scammed QVC for $400,000+ in Internet glitch&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2005-64&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;November 20, 2007&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Monetary Loss&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;A woman exploited a bug in QVC shopping network web site to get, without paying, more than 1800 items worth $412,000 items from the March to November 2005. The glitch enabled her to cancel orders she placed at a specific time and still get the product.&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.tgdaily.com/content/view/34608/113/&quot;&gt;Woman scammed QVC for $400,000+ in Internet glitch&lt;/a&gt; [TG Daily, Oct 30 2007]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.philly.com/dailynews/local/20071026_N_C__woman_admits_400G_scam_of_QVC.html&quot;&gt;N.C. woman admits 400G scam of QVC&lt;/a&gt; [Phily.com, Oct 26 2007]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA</description>      <pubDate>Wed, 16 Jun 2010 18:53:39 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>November 20, 2007</ddb:dateoccured>      <ddb:entrytitle>WHID 2005-64: Woman scammed QVC for $400,000+ in Internet glitch</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;A woman exploited a bug in QVC shopping network web site to get, without paying, more than 1800 items worth $412,000 items from the March to November 2005. The glitch enabled her to cancel orders she placed at a specific time and still get the product.&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.tgdaily.com/content/view/34608/113/&quot;&gt;Woman scammed QVC for $400,000+ in Internet glitch&lt;/a&gt; [TG Daily, Oct 30 2007]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.philly.com/dailynews/local/20071026_N_C__woman_admits_400G_scam_of_QVC.html&quot;&gt;N.C. woman admits 400G scam of QVC&lt;/a&gt; [Phily.com, Oct 26 2007]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Monetary Loss</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2005-64</ddb:whidid>    </item>    <item>      <title>WHID 2004-11: Phishers Manipulate SunTrust Site to Steal Data</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=33889</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2004-11: Phishers Manipulate SunTrust Site to Steal Data&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2004-11&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Phishing&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Phishing based on XSS&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://news.netcraft.com/archives/2004/09/28/phishers_manipulate_suntrust_site_to_steal_data.html&quot;&gt;Phishers Manipulate SunTrust Site to Steal Data&lt;/a&gt; [NetCraft, Sep 28 2004]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Finance&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA</description>      <pubDate>Wed, 16 Jun 2010 20:17:37 -0400</pubDate>      <ddb:attackedentityfield>Finance</ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured></ddb:dateoccured>      <ddb:entrytitle>WHID 2004-11: Phishers Manipulate SunTrust Site to Steal Data</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Phishing based on XSS&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://news.netcraft.com/archives/2004/09/28/phishers_manipulate_suntrust_site_to_steal_data.html&quot;&gt;Phishers Manipulate SunTrust Site to Steal Data&lt;/a&gt; [NetCraft, Sep 28 2004]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Phishing</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2004-11</ddb:whidid>    </item>    <item>      <title>WHID 2004-18: Security flaw exposed in Cahoot bank accounts</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34522</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2004-18: Security flaw exposed in Cahoot bank accounts&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2004-18&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;October 25, 2007&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Disclosure Only&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Following a software upgrade, Cahoot, a UK based Internet only bank allowed accessing user accounts by guessing their user names. At least on one page allowed accessing an account by only specifying the user name in the URL. The bug was open for 12 days before being discovered.&lt;br&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;The site was taken off line for 10 hours to fix the issue. It is a significant incident, as it is one of those rare occasions where vulnerability was serious enough to force the organization to just take the site off line until it is fixed.&lt;br&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;We somehow missed this story so it finds its way to WHID only now in late 2007.&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://software.silicon.com/security/0,39024655,39125639,00.htm&quot;&gt;Security flaw exposed in Cahoot bank accounts&lt;/a&gt; [Silicon.com, Oct 5 2004]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://software.silicon.com/security/0,39024655,39125665,00.htm&quot;&gt;Leader: Not another security scare&lt;/a&gt; [Silicon.com, Oct 5 2004]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://news.bbc.co.uk/2/hi/business/3984845.stm&quot;&gt;Cahoot hit by web security scare&lt;/a&gt; [BBC, Oct 5 2004]&lt;/li&gt;&lt;br&gt;&lt;/ul></description>      <pubDate>Wed, 16 Jun 2010 20:13:01 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>October 25, 2007</ddb:dateoccured>      <ddb:entrytitle>WHID 2004-18: Security flaw exposed in Cahoot bank accounts</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Following a software upgrade, Cahoot, a UK based Internet only bank allowed accessing user accounts by guessing their user names. At least on one page allowed accessing an account by only specifying the user name in the URL. The bug was open for 12 days before being discovered.&#13;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;The site was taken off line for 10 hours to fix the issue. It is a significant incident, as it is one of those rare occasions where vulnerability was serious enough to force the organization to just take the site off line until it is fixed.&#13;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;We somehow missed this story so it finds its way to WHID only now in late 2007.&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://software.silicon.com/security/0,39024655,39125639,00.htm&quot;&gt;Security flaw exposed in Cahoot bank accounts&lt;/a&gt; [Silicon.com, Oct 5 2004]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://software.silicon.com/security/0,39024655,39125665,00.htm&quot;&gt;Leader: Not another security scare&lt;/a&gt; [Silicon.com, Oct 5 2004]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://news.bbc.co.uk/2/hi/business/3984845.stm&quot;&gt;Cahoot hit by web security scare&lt;/a&gt; [BBC, Oct 5 2004]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Disclosure Only</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2004-18</ddb:whidid>    </item>    <item>      <title>WHID 2005-63: Web designer sentenced for hacking competitor&amp;#039;s site</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34455</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2005-63: Web designer sentenced for hacking competitor&amp;#039;s site&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2005-63&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;August 14, 2007&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;While lacking in technical details, this story is certainly juicy. It demonstrates well the business use of web site hacking. The downside is that the hacker got only a minimal punishment, which unless the incident itself is overrated in the media, is a very bad sign on how courts view computer crime.&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://news.cnet.co.uk/software/0,39029694,49292191,00.htm&quot;&gt;Web designer sentenced for hacking competitor's site&lt;/a&gt; [CNet, Aug 14 2007]&lt;/li&gt;&lt;br&gt;&lt;/ul></description>      <pubDate>Wed, 16 Jun 2010 18:55:30 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>August 14, 2007</ddb:dateoccured>      <ddb:entrytitle>WHID 2005-63: Web designer sentenced for hacking competitor&amp;#039;s site</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;While lacking in technical details, this story is certainly juicy. It demonstrates well the business use of web site hacking. The downside is that the hacker got only a minimal punishment, which unless the incident itself is overrated in the media, is a very bad sign on how courts view computer crime.&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://news.cnet.co.uk/software/0,39029694,49292191,00.htm&quot;&gt;Web designer sentenced for hacking competitor's site&lt;/a&gt; [CNet, Aug 14 2007]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2005-63</ddb:whidid>    </item>    <item>      <title>WHID 2004-8: Broadcast TV announcements changed by hacking the stations web site</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=33894</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2004-8: Broadcast TV announcements changed by hacking the stations web site&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2004-8&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Disinformation&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Previously moderated weather announcements could be changed by the user&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.securityfocus.com/news/8191&quot;&gt;Pranksters bedevil TV weather announcment system&lt;/a&gt; [Security Focus, Mar 4 2004]&lt;/li&gt;&lt;br&gt;&lt;/ul></description>      <pubDate>Wed, 16 Jun 2010 20:20:34 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured></ddb:dateoccured>      <ddb:entrytitle>WHID 2004-8: Broadcast TV announcements changed by hacking the stations web site</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Previously moderated weather announcements could be changed by the user&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.securityfocus.com/news/8191&quot;&gt;Pranksters bedevil TV weather announcment system&lt;/a&gt; [Security Focus, Mar 4 2004]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Disinformation</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2004-8</ddb:whidid>    </item>    <item>      <title>WHID 2005-62: Guidance Software</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34337</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2005-62: Guidance Software&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2005-62&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;April 18, 2007&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;3,800 customer credit-card numbers were stolen in the attack on Guidance Software web site. This incident is made more severe since Guidance software is a provider of software for investigating security breaches and many of its clients are security and law enforcement agencies, some of them known to be affected.&lt;br&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;As usual in such cases the actual way in which the information was stolen was not disclosed. A federal trade commission report on the incident, published only in 2007, revealed that the incident was a result on an SQL injection attack on Guidance servers. In a settlement with the FTC, Guidance agreed to implement a comprehensive information security program, including independent, third-party audits every other year for the next ten years.&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.ftc.gov/os/caselist/0623057/0623057%20-Guidance%20complaint.pdf&quot;&gt;United States Of America Federal Trade Commission In The Matter Of Guidance Software, Inc.&lt;/a&gt; [Federal Trade Commission, Apr 1 2007]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.internetnews.com/security/article.php/3572386&quot;&gt;Guidance Software Investigating Stolen Data&lt;/a&gt; [Internet News, Dec 20 2005]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.internetnews.com/security/article.php/3669561&quot;&gt;FTC Approves Final Guidance Settlement&lt;/a&gt; [Internet News, Apr 3 2007]&lt;/li&gt;&lt;br&gt;&lt;/ul></description>      <pubDate>Wed, 16 Jun 2010 18:56:09 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>April 18, 2007</ddb:dateoccured>      <ddb:entrytitle>WHID 2005-62: Guidance Software</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;3,800 customer credit-card numbers were stolen in the attack on Guidance Software web site. This incident is made more severe since Guidance software is a provider of software for investigating security breaches and many of its clients are security and law enforcement agencies, some of them known to be affected.&#13;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;As usual in such cases the actual way in which the information was stolen was not disclosed. A federal trade commission report on the incident, published only in 2007, revealed that the incident was a result on an SQL injection attack on Guidance servers. In a settlement with the FTC, Guidance agreed to implement a comprehensive information security program, including independent, third-party audits every other year for the next ten years.&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.ftc.gov/os/caselist/0623057/0623057%20-Guidance%20complaint.pdf&quot;&gt;United States Of America Federal Trade Commission In The Matter Of Guidance Software, Inc.&lt;/a&gt; [Federal Trade Commission, Apr 1 2007]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.internetnews.com/security/article.php/3572386&quot;&gt;Guidance Software Investigating Stolen Data&lt;/a&gt; [Internet News, Dec 20 2005]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.internetnews.com/security/article.php/3669561&quot;&gt;FTC Approves Final Guidance Settlement&lt;/a&gt; [Internet News, Apr 3 2007]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2005-62</ddb:whidid>    </item>    <item>      <title>WHID 2003-9: Defenses lacking at social network sites</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=33899</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2003-9: Defenses lacking at social network sites&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2003-9&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Disclosure Only&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.securityfocus.com/news/7739&quot;&gt;Defenses lacking at social network sites&lt;/a&gt; [Security Focus, Dec 31 2003]&lt;/li&gt;&lt;br&gt;&lt;/ul></description>      <pubDate>Wed, 16 Jun 2010 20:31:33 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured></ddb:dateoccured>      <ddb:entrytitle>WHID 2003-9: Defenses lacking at social network sites</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.securityfocus.com/news/7739&quot;&gt;Defenses lacking at social network sites&lt;/a&gt; [Security Focus, Dec 31 2003]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Disclosure Only</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2003-9</ddb:whidid>    </item>    <item>      <title>WHID 2004-17: The CardSystems breach was an SQL Injection hack (Updated)</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34170</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2004-17: The CardSystems breach was an SQL Injection hack (Updated)&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2004-17&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;April 20, 2006&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Credit Card Leakage&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;&lt;em&gt;&lt;strong&gt;Update (May 27th 2009)&lt;/strong&gt;&lt;/em&gt; - The CardSystems incident is refusing to die. Merrick Back is now &lt;a href=&quot;http://www.courthousenews.com/2009/05/26/Merrick.pdf&quot;&gt;suing Savvis&lt;/a&gt; for certifying CardSystems as CISP compliant while it systems where wide open. CISP is a VISA program for certifying credit card processing systems which existed prior to PCI DSS.&lt;/p&gt;&lt;br&gt;&lt;p&gt;The actual damage to an organization of an attack is rarely disclosed, and coverage focuses on the Number_of_Records stolen. In the court documents Merrick reveals that its own damage from the CardSystems incident was $16,000,000! The money was paid to card holders to compensate for losses and for legal fees and fines.&lt;/p&gt;&lt;br&gt;&lt;p&gt;The case is also interesting as it put to test the liability of the certifying entity (in this case Savvis) resulting from assessing. The results may have profound influence on the PCI QSA market and therefore PCI itself. David Navetta posts an &lt;a href=&quot;http://infoseccompliance.com/2009/06/03/merrick-bank-v-savvis-analysis-of-the-merrick-bank-complaint/&quot;&gt;excellent legal analysis&lt;/a&gt; of the potential implications of the lawsuit.&lt;/p&gt;&lt;br&gt;&lt;hr /&gt;&lt;br&gt;&lt;p&gt;This entry is a very important one. Most are already familiar with the infamous CardSystems incident where hackers stole 263,000 credit card numbers, exposed 40 million more and several million dollars fraudulent credit and debit card purchases had been made with these counterfeit cards. As a result of the breach CardSystems nearly went out of business and was eventually purchased by PayByTouch. CardSystems is considered by many the most severe publicized information security breach ever and it caused company share holders, financial institutes and card holders damage of millions of dollars.&lt;/p&gt;&lt;br&gt;&lt;p&gt;But since the publication of the incident a year ago the way in which the breach occurred remained a mystery.&lt;/p&gt;&lt;br&gt;&lt;p&gt;Recently new articles about the case (listed below) revealed that SQL injection was used by the attackers to install malicious script on the CardSystems web application database which where scheduled to run every four days, extract records, zip them and export them to an FTP site.&lt;/p&gt;&lt;br&gt;&lt;p&gt;This is one of the most stunning examples where a web application security hole was used to launch a targeted attack in order to steal money.&lt;/p&gt;&lt;br&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://searchsecurity.techtarget.com/originalContent/0,289142,sid14_gci1180411,00.html&quot;&gt;Cleaning up after a hack job: CardSystems' Christensen&lt;/a&gt; [Information Security (mirror), Apr 14 2006]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.ftc.gov/os/caselist/0523148/0523148complaint.pdf&quot;&gt;FTC complain In the Matter of CardSystems Solutions&lt;/a&gt; [FTC, ]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://wiki.midrange.com/index.php/CardSystems&quot;&gt;Midrange CardSystems Wiki&lt;/a&gt; [Midrange, ]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.webappsec.org/lists/websecurity/archive/2006-04/msg00051.html&quot;&gt;CardSystems was a Web Application Hack&lt;/a&gt; [Cesar Cerrudo, &lt;a href=&quot;http://www.argeniss.com&quot;&gt;Argeniss&lt;/a&gt;, Apr 18 2006]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.schneier.com/blog/archives/2005/06/cardsystems_exp.html&quot;&gt;CardSystems Exposes 40 Million Identities&lt;/a&gt; [Bruce Schneier, Jun 23 2005]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Field: &lt;/b&gt;Finance&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Items Leaked: &lt;/b&gt;Credit Card Number&lt;br&gt;&lt;b&gt;Number of Records: &lt;/b&gt;40,000,000</description>      <pubDate>Wed, 16 Jun 2010 20:13:27 -0400</pubDate>      <ddb:attackedentityfield>Finance</ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>April 20, 2006</ddb:dateoccured>      <ddb:entrytitle>WHID 2004-17: The CardSystems breach was an SQL Injection hack (Updated)</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;&lt;em&gt;&lt;strong&gt;Update (May 27th 2009)&lt;/strong&gt;&lt;/em&gt; - The CardSystems incident is refusing to die. Merrick Back is now &lt;a href=&quot;http://www.courthousenews.com/2009/05/26/Merrick.pdf&quot;&gt;suing Savvis&lt;/a&gt; for certifying CardSystems as CISP compliant while it systems where wide open. CISP is a VISA program for certifying credit card processing systems which existed prior to PCI DSS.&lt;/p&gt;&#13;&lt;p&gt;The actual damage to an organization of an attack is rarely disclosed, and coverage focuses on the Number_of_Records stolen. In the court documents Merrick reveals that its own damage from the CardSystems incident was $16,000,000! The money was paid to card holders to compensate for losses and for legal fees and fines.&lt;/p&gt;&#13;&lt;p&gt;The case is also interesting as it put to test the liability of the certifying entity (in this case Savvis) resulting from assessing. The results may have profound influence on the PCI QSA market and therefore PCI itself. David Navetta posts an &lt;a href=&quot;http://infoseccompliance.com/2009/06/03/merrick-bank-v-savvis-analysis-of-the-merrick-bank-complaint/&quot;&gt;excellent legal analysis&lt;/a&gt; of the potential implications of the lawsuit.&lt;/p&gt;&#13;&lt;hr /&gt;&#13;&lt;p&gt;This entry is a very important one. Most are already familiar with the infamous CardSystems incident where hackers stole 263,000 credit card numbers, exposed 40 million more and several million dollars fraudulent credit and debit card purchases had been made with these counterfeit cards. As a result of the breach CardSystems nearly went out of business and was eventually purchased by PayByTouch. CardSystems is considered by many the most severe publicized information security breach ever and it caused company share holders, financial institutes and card holders damage of millions of dollars.&lt;/p&gt;&#13;&lt;p&gt;But since the publication of the incident a year ago the way in which the breach occurred remained a mystery.&lt;/p&gt;&#13;&lt;p&gt;Recently new articles about the case (listed below) revealed that SQL injection was used by the attackers to install malicious script on the CardSystems web application database which where scheduled to run every four days, extract records, zip them and export them to an FTP site.&lt;/p&gt;&#13;&lt;p&gt;This is one of the most stunning examples where a web application security hole was used to launch a targeted attack in order to steal money.&lt;/p&gt;&#13;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://searchsecurity.techtarget.com/originalContent/0,289142,sid14_gci1180411,00.html&quot;&gt;Cleaning up after a hack job: CardSystems' Christensen&lt;/a&gt; [Information Security (mirror), Apr 14 2006]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.ftc.gov/os/caselist/0523148/0523148complaint.pdf&quot;&gt;FTC complain In the Matter of CardSystems Solutions&lt;/a&gt; [FTC, ]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://wiki.midrange.com/index.php/CardSystems&quot;&gt;Midrange CardSystems Wiki&lt;/a&gt; [Midrange, ]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.webappsec.org/lists/websecurity/archive/2006-04/msg00051.html&quot;&gt;CardSystems was a Web Application Hack&lt;/a&gt; [Cesar Cerrudo, &lt;a href=&quot;http://www.argeniss.com&quot;&gt;Argeniss&lt;/a&gt;, Apr 18 2006]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.schneier.com/blog/archives/2005/06/cardsystems_exp.html&quot;&gt;CardSystems Exposes 40 Million Identities&lt;/a&gt; [Bruce Schneier, Jun 23 2005]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked>Credit Card Number</ddb:itemsleaked>      <ddb:numberofrecords>40,000,000</ddb:numberofrecords>      <ddb:outcome>Credit Card Leakage</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2004-17</ddb:whidid>    </item>    <item>      <title>WHID 2002-4: Tower Records settles charges over hack attacks</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=33905</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2002-4: Tower Records settles charges over hack attacks&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2002-4&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;View other customers orders by changing a guessable number within a URL parameter&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.securityfocus.com/news/8508&quot;&gt;Tower Records settles charges over hack attacks&lt;/a&gt; [Security Focus, Apr 21 2004]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://news.com.com/2100-1017-976271.html&quot;&gt;Tower Records site exposes data&lt;/a&gt; [CNet, Dec 5 2002]&lt;/li&gt;&lt;br&gt;&lt;/ul></description>      <pubDate>Wed, 16 Jun 2010 20:39:46 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured></ddb:dateoccured>      <ddb:entrytitle>WHID 2002-4: Tower Records settles charges over hack attacks</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;View other customers orders by changing a guessable number within a URL parameter&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.securityfocus.com/news/8508&quot;&gt;Tower Records settles charges over hack attacks&lt;/a&gt; [Security Focus, Apr 21 2004]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://news.com.com/2100-1017-976271.html&quot;&gt;Tower Records site exposes data&lt;/a&gt; [CNet, Dec 5 2002]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2002-4</ddb:whidid>    </item>    <item>      <title>WHID 2005-61: Gmail session management bug</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34155</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2005-61: Gmail session management bug&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2005-61&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;April 12, 2006&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Disclosure Only&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;A bug in Gmail's authentication and session management allows direct login to anybodies account without requiring any involvement of the victim.&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.elhacker.net/gmailbug/english_version.htm&quot;&gt;Gmail bug&lt;/a&gt; [elhacker.net, Oct 18 2005]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.eweek.com/article2/0,1759,1889050,00.asp&quot;&gt;Google Downplays Gmail Security Fix&lt;/a&gt; [eWeek, Oct 18 2005]&lt;/li&gt;&lt;br&gt;&lt;/ul></description>      <pubDate>Wed, 16 Jun 2010 18:56:54 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>April 12, 2006</ddb:dateoccured>      <ddb:entrytitle>WHID 2005-61: Gmail session management bug</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;A bug in Gmail's authentication and session management allows direct login to anybodies account without requiring any involvement of the victim.&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.elhacker.net/gmailbug/english_version.htm&quot;&gt;Gmail bug&lt;/a&gt; [elhacker.net, Oct 18 2005]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.eweek.com/article2/0,1759,1889050,00.asp&quot;&gt;Google Downplays Gmail Security Fix&lt;/a&gt; [eWeek, Oct 18 2005]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Disclosure Only</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2005-61</ddb:whidid>    </item>    <item>      <title>WHID 1999-1: eBay downplays security hole</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34101</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 1999-1: eBay downplays security hole&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;1999-1&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;April 4, 2006&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;A very early XSS issue at eBay. Interesting historically as it seems that at the time the term XSS was not yet in use.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://packetstormsecurity.org/9904-exploits/ebayla.txt&quot;&gt;http://packetstormsecurity.org/9904-exploits/ebayla.txt&lt;/a></description>      <pubDate>Mon, 24 May 2010 13:29:40 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>April 4, 2006</ddb:dateoccured>      <ddb:entrytitle>WHID 1999-1: eBay downplays security hole</ddb:entrytitle>      <ddb:incidentdescription>A very early XSS issue at eBay. Interesting historically as it seems that at the time the term XSS was not yet in use.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome></ddb:outcome>      <ddb:reference>http://packetstormsecurity.org/9904-exploits/ebayla.txt</ddb:reference>      <ddb:whidid>1999-1</ddb:whidid>    </item>    <item>      <title>WHID 2002-2: Advogato XSS virus account</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=33910</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2002-2: Advogato XSS virus account&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2002-2&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;July 11, 2005&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Worm&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.bindshell.net/papers/xssv/advogato/&quot;&gt;Advogato xss virus account&lt;/a&gt; [Bindshell, Sep 21 2002]&lt;/li&gt;&lt;br&gt;&lt;/ul></description>      <pubDate>Wed, 16 Jun 2010 20:41:57 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>July 11, 2005</ddb:dateoccured>      <ddb:entrytitle>WHID 2002-2: Advogato XSS virus account</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.bindshell.net/papers/xssv/advogato/&quot;&gt;Advogato xss virus account&lt;/a&gt; [Bindshell, Sep 21 2002]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Worm</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2002-2</ddb:whidid>    </item>    <item>      <title>WHID 2003-2: UT Austin hack yields personal info on thousands</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34085</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2003-2: UT Austin hack yields personal info on thousands&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2003-2&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;April 4, 2006&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;While an old incident, further research into it suggest that it was a web hack. While the initial reports talk about a database break in, a report in the Register identify the database as txClass, which is a web based system.&lt;br /&gt;55,200 social security numbers where stolen, though the hacker claimed that he did not perform the act for profit. He was caught and sentenced to 5 years probation.&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;https://www.utexas.edu/datatheft/&quot;&gt;Data Theft Incident Response&lt;/a&gt; [UofT, Sep 7 2005]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.theregister.co.uk/2003/03/18/student_owns_up_to_texas/&quot;&gt;Student owns up to Texas Uni cyber-heist&lt;/a&gt; [The Register, Mar 18 2003]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.computerworld.com/securitytopics/security/holes/story/0,10801,79102,00.html&quot;&gt;UT Austin hack yields personal info on thousands&lt;/a&gt; [Computer World, Mar 6 2003]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.securityfocus.com/news/2935&quot;&gt;Hackers steal names, Social Security numbers from University of Texas database&lt;/a&gt; [Security Focus, Mar 6 2006]&lt;/li&gt;&lt;br&gt;&lt;/ul></description>      <pubDate>Wed, 16 Jun 2010 20:38:09 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>April 4, 2006</ddb:dateoccured>      <ddb:entrytitle>WHID 2003-2: UT Austin hack yields personal info on thousands</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;While an old incident, further research into it suggest that it was a web hack. While the initial reports talk about a database break in, a report in the Register identify the database as txClass, which is a web based system.&lt;br /&gt;55,200 social security numbers where stolen, though the hacker claimed that he did not perform the act for profit. He was caught and sentenced to 5 years probation.&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;https://www.utexas.edu/datatheft/&quot;&gt;Data Theft Incident Response&lt;/a&gt; [UofT, Sep 7 2005]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.theregister.co.uk/2003/03/18/student_owns_up_to_texas/&quot;&gt;Student owns up to Texas Uni cyber-heist&lt;/a&gt; [The Register, Mar 18 2003]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.computerworld.com/securitytopics/security/holes/story/0,10801,79102,00.html&quot;&gt;UT Austin hack yields personal info on thousands&lt;/a&gt; [Computer World, Mar 6 2003]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.securityfocus.com/news/2935&quot;&gt;Hackers steal names, Social Security numbers from University of Texas database&lt;/a&gt; [Security Focus, Mar 6 2006]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2003-2</ddb:whidid>    </item>    <item>      <title>WHID 2006-5: Hotmail XSS (1)</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34075</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2006-5: Hotmail XSS (1)&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2006-5&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;March 29, 2006&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Disclosure Only&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Hotmail's filtering engine insufficiently filters JavaScript scripts. It is possible to write JavaScript in the BGCOLOR attribute of the BODY tag, using CSS. This leads to execution when the email is viewed. JavaScript must be Unicode encoded in order to fool the filter. This encoding is recognized with IE &gt;= 6&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://seclists.org/lists/bugtraq/2006/Mar/0509.html&quot;&gt;Microsoft MSN Hotmail : Cross-Site Scripting Vulnerability&lt;/a&gt; [Bugtraq Archives, Mar 23 2006]&lt;/li&gt;&lt;br&gt;&lt;/ul></description>      <pubDate>Wed, 16 Jun 2010 18:45:43 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>March 29, 2006</ddb:dateoccured>      <ddb:entrytitle>WHID 2006-5: Hotmail XSS (1)</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Hotmail's filtering engine insufficiently filters JavaScript scripts. It is possible to write JavaScript in the BGCOLOR attribute of the BODY tag, using CSS. This leads to execution when the email is viewed. JavaScript must be Unicode encoded in order to fool the filter. This encoding is recognized with IE &gt;= 6&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://seclists.org/lists/bugtraq/2006/Mar/0509.html&quot;&gt;Microsoft MSN Hotmail : Cross-Site Scripting Vulnerability&lt;/a&gt; [Bugtraq Archives, Mar 23 2006]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Disclosure Only</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2006-5</ddb:whidid>    </item>    <item>      <title>WHID 2006-12: Music Web Site: Breach Exposed Accounts</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34070</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2006-12: Music Web Site: Breach Exposed Accounts&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2006-12&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;March 22, 2006&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;A musical instrument and sound gear Web site that advertises its relationship with artists such as Dave Matthews, Carlos Santana and Mary J. Blige was breached and notified some customers that their credit card information may have been stolen.&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://news.yahoo.com/s/ap/20060317/ap_on_hi_te/web_site_breach&quot;&gt;Music Web Site: Breach Exposed Accounts&lt;/a&gt; [AP, Mar 16 2006]&lt;/li&gt;&lt;br&gt;&lt;/ul></description>      <pubDate>Wed, 16 Jun 2010 18:38:59 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>March 22, 2006</ddb:dateoccured>      <ddb:entrytitle>WHID 2006-12: Music Web Site: Breach Exposed Accounts</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;A musical instrument and sound gear Web site that advertises its relationship with artists such as Dave Matthews, Carlos Santana and Mary J. Blige was breached and notified some customers that their credit card information may have been stolen.&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://news.yahoo.com/s/ap/20060317/ap_on_hi_te/web_site_breach&quot;&gt;Music Web Site: Breach Exposed Accounts&lt;/a&gt; [AP, Mar 16 2006]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2006-12</ddb:whidid>    </item>    <item>      <title>WHID 2006-6: Hacker breaks into Buffalo sports site</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34065</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2006-6: Hacker breaks into Buffalo sports site&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2006-6&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;March 22, 2006&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;A site of a minor league baseball team was hacked and personal details of fans was stolen.&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.wstm.com/Global/story.asp?S=4633614&amp;amp;nav=2aKD&quot;&gt;Hacker breaks into Buffalo sports site&lt;/a&gt; [NBC, Mar 15 2006]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.buffalonews.com/editorial/20060314/1033934.asp&quot;&gt;Hacker gains access to Bisons fans' Web data&lt;/a&gt; [The Buffalow News, Mar 14 2006]&lt;/li&gt;&lt;br&gt;&lt;/ul></description>      <pubDate>Wed, 16 Jun 2010 18:45:22 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>March 22, 2006</ddb:dateoccured>      <ddb:entrytitle>WHID 2006-6: Hacker breaks into Buffalo sports site</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;A site of a minor league baseball team was hacked and personal details of fans was stolen.&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.wstm.com/Global/story.asp?S=4633614&amp;amp;nav=2aKD&quot;&gt;Hacker breaks into Buffalo sports site&lt;/a&gt; [NBC, Mar 15 2006]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.buffalonews.com/editorial/20060314/1033934.asp&quot;&gt;Hacker gains access to Bisons fans' Web data&lt;/a&gt; [The Buffalow News, Mar 14 2006]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2006-6</ddb:whidid>    </item>    <item>      <title>WHID 2001-4: Hacked Web site damaged PCs in Japan</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=33916</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2001-4: Hacked Web site damaged PCs in Japan&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2001-4&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Planting of Malware&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;Users who visited the Price Lotto site using Microsoft's IE (Internet Explorer) 4.x and 5.x, automatically downloaded malicious JavaScript that was programmed to alter the software configuration of their PCs.&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://www.infoworld.com/articles/hn/xml/01/08/21/010821hnjapmal.html?&amp;amp;_ref=1024727153&quot;&gt;http://www.infoworld.com/articles/hn/xml/01/08/21/010821hnjapmal.html?&amp;amp;_ref=1024727153&lt;/a></description>      <pubDate>Wed, 16 Jun 2010 20:50:25 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured></ddb:dateoccured>      <ddb:entrytitle>WHID 2001-4: Hacked Web site damaged PCs in Japan</ddb:entrytitle>      <ddb:incidentdescription>Users who visited the Price Lotto site using Microsoft's IE (Internet Explorer) 4.x and 5.x, automatically downloaded malicious JavaScript that was programmed to alter the software configuration of their PCs.</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Planting of Malware</ddb:outcome>      <ddb:reference>http://www.infoworld.com/articles/hn/xml/01/08/21/010821hnjapmal.html?&amp;amp;_ref=1024727153</ddb:reference>      <ddb:whidid>2001-4</ddb:whidid>    </item>    <item>      <title>WHID 2006-7: Google Reader &amp;quot;preview&amp;quot; and &amp;quot;lens&amp;quot; script improper feed validation</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34060</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2006-7: Google Reader &amp;quot;preview&amp;quot; and &amp;quot;lens&amp;quot; script improper feed validation&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2006-7&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;March 5, 2006&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Disclosure Only&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Google reader allows redirection so sites can fool users to subscribe to malicious content.&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://lists.grok.org.uk/pipermail/full-disclosure/2006-February/042439.html&quot;&gt;Google Reader &quot;preview&quot; and &quot;lens&quot; script improper feed validation&lt;/a&gt; [Full Disclosure, Feb 22 2006]&lt;/li&gt;&lt;br&gt;&lt;/ul></description>      <pubDate>Wed, 16 Jun 2010 18:44:26 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>March 5, 2006</ddb:dateoccured>      <ddb:entrytitle>WHID 2006-7: Google Reader &amp;quot;preview&amp;quot; and &amp;quot;lens&amp;quot; script improper feed validation</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Google reader allows redirection so sites can fool users to subscribe to malicious content.&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://lists.grok.org.uk/pipermail/full-disclosure/2006-February/042439.html&quot;&gt;Google Reader &quot;preview&quot; and &quot;lens&quot; script improper feed validation&lt;/a&gt; [Full Disclosure, Feb 22 2006]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Disclosure Only</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2006-7</ddb:whidid>    </item>    <item>      <title>WHID 2006-10: NUJP website defacement seen not related to political crisis</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34055</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2006-10: NUJP website defacement seen not related to political crisis&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2006-10&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;March 5, 2006&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Defacement&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;A mass defacement of a Philippine hosting service was carried our using SQL injection. It accidentally also defaced the site of the National Union of Journalists of the Philippines, which led some to believe that it was a targeted political attack.&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://news.inq7.net/infotech/index.php?index=1&amp;amp;story_id=68097&quot;&gt;NUJP website defacement seen not related to political crisis&lt;/a&gt; [inq7, Mar 2 2006]&lt;/li&gt;&lt;br&gt;&lt;/ul></description>      <pubDate>Wed, 16 Jun 2010 18:39:58 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>March 5, 2006</ddb:dateoccured>      <ddb:entrytitle>WHID 2006-10: NUJP website defacement seen not related to political crisis</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;A mass defacement of a Philippine hosting service was carried our using SQL injection. It accidentally also defaced the site of the National Union of Journalists of the Philippines, which led some to believe that it was a targeted political attack.&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://news.inq7.net/infotech/index.php?index=1&amp;amp;story_id=68097&quot;&gt;NUJP website defacement seen not related to political crisis&lt;/a&gt; [inq7, Mar 2 2006]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Defacement</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2006-10</ddb:whidid>    </item>    <item>      <title>WHID 2000-6: Inforeading.com defacement using command injection</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=33922</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2000-6: Inforeading.com defacement using command injection&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2000-6&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;Executing local commands using URL parameters&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://www.inforeading.com/library/infoarticles/InfoReading/logs/deface/02.txt&quot;&gt;http://www.inforeading.com/library/infoarticles/InfoReading/logs/deface/02.txt&lt;/a></description>      <pubDate>Mon, 24 May 2010 13:29:40 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured></ddb:dateoccured>      <ddb:entrytitle>WHID 2000-6: Inforeading.com defacement using command injection</ddb:entrytitle>      <ddb:incidentdescription>Executing local commands using URL parameters</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome></ddb:outcome>      <ddb:reference>http://www.inforeading.com/library/infoarticles/InfoReading/logs/deface/02.txt</ddb:reference>      <ddb:whidid>2000-6</ddb:whidid>    </item>    <item>      <title>WHID 2006-11: Teenager claims to find code flaw in Gmail</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34050</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2006-11: Teenager claims to find code flaw in Gmail&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2006-11&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;March 5, 2006&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Disclosure Only&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;A 14 years old claims to have discovered an XSS flaw in Google's Gmail. Comments have been mixed, and Google did not comment, so either the flaw was fixed pretty fast, or did not exits.&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.networkworld.com/news/2006/030206-teen-flaw-gmail.html&quot;&gt;Teenager claims to find code flaw in Gmail&lt;/a&gt; [Network World, Feb 3 2006]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://ph3rny.blogspot.com/2006/03/vulnerability-in-gmail.html&quot;&gt; Vulnerability in Gmail&lt;/a&gt; [Ph3rny's Blog, ]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://news.zdnet.com/2100-1009_22-6045416.html&quot;&gt;Google fixes 'minor' Gmail flaw&lt;/a&gt; [ZDnet, Feb 2 2006]&lt;/li&gt;&lt;br&gt;&lt;/ul></description>      <pubDate>Wed, 16 Jun 2010 18:39:35 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>March 5, 2006</ddb:dateoccured>      <ddb:entrytitle>WHID 2006-11: Teenager claims to find code flaw in Gmail</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;A 14 years old claims to have discovered an XSS flaw in Google's Gmail. Comments have been mixed, and Google did not comment, so either the flaw was fixed pretty fast, or did not exits.&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.networkworld.com/news/2006/030206-teen-flaw-gmail.html&quot;&gt;Teenager claims to find code flaw in Gmail&lt;/a&gt; [Network World, Feb 3 2006]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://ph3rny.blogspot.com/2006/03/vulnerability-in-gmail.html&quot;&gt; Vulnerability in Gmail&lt;/a&gt; [Ph3rny's Blog, ]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://news.zdnet.com/2100-1009_22-6045416.html&quot;&gt;Google fixes 'minor' Gmail flaw&lt;/a&gt; [ZDnet, Feb 2 2006]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Disclosure Only</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2006-11</ddb:whidid>    </item>    <item>      <title>WHID 2006-8: ICQmail.com - Mail2World.com XSS vulnerability</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34045</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2006-8: ICQmail.com - Mail2World.com XSS vulnerability&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2006-8&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;March 5, 2006&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Disclosure Only&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Links sent to a user as part of the mail content are not properly sanitized, so a user receiving such mail and activating a link would be affected.&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.nukedx.com/?viewdoc=15&quot;&gt;Advisory: ICQmail.com &amp;amp; Mail2World.com (ms_inbox.asp Current_folder) XSS vulnerability&lt;/a&gt; [NukedX, Feb 25 2006]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b></description>      <pubDate>Wed, 16 Jun 2010 18:43:28 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>March 5, 2006</ddb:dateoccured>      <ddb:entrytitle>WHID 2006-8: ICQmail.com - Mail2World.com XSS vulnerability</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Links sent to a user as part of the mail content are not properly sanitized, so a user receiving such mail and activating a link would be affected.&#13;&#10;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&#10;&lt;ul&gt;&#13;&#10;&lt;li&gt;&lt;a href=&quot;http://www.nukedx.com/?viewdoc=15&quot;&gt;Advisory: ICQmail.com &amp;amp; Mail2World.com (ms_inbox.asp Current_folder) XSS vulnerability&lt;/a&gt; [NukedX, Feb 25 2006]&lt;/li&gt;&#13;&#10;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Disclosure Only</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2006-8</ddb:whidid>    </item>    <item>      <title>WHID 2000-4: Sensitive files left unprotected on Western Union&amp;#039;s Web</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=33926</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2000-4: Sensitive files left unprotected on Western Union&amp;#039;s Web&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2000-4&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;Sensitive files were left in a publicly accessible directory during a maintenance window&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b&gt;USA&lt;br&gt;&lt;b&gt;Reference: &lt;/b&gt;&lt;a href=&quot;http://news.com.com/2100-1023-245525.html?legacy=cnet&quot;&gt;http://news.com.com/2100-1023-245525.html?legacy=cnet&lt;/a></description>      <pubDate>Mon, 24 May 2010 13:54:42 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography>USA</ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured></ddb:dateoccured>      <ddb:entrytitle>WHID 2000-4: Sensitive files left unprotected on Western Union&amp;#039;s Web</ddb:entrytitle>      <ddb:incidentdescription>Sensitive files were left in a publicly accessible directory during a maintenance window</ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome></ddb:outcome>      <ddb:reference>http://news.com.com/2100-1023-245525.html?legacy=cnet</ddb:reference>      <ddb:whidid>2000-4</ddb:whidid>    </item>    <item>      <title>WHID 2006-9: EBay XSS</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34040</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2006-9: EBay XSS&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2006-9&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;March 3, 2006&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Disinformation&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Unlike other XSS cases, this was discovered due to actual abuse on a specific auction at EBay.&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://archives.neohapsis.com/archives/fulldisclosure/2006-02/0730.html&quot;&gt;Ebay XSS&lt;/a&gt; [Full Disclosure, Feb 28 2006]&lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;&lt;b&gt;Attack Source Geography: &lt;/b&gt;&lt;br&gt;&lt;b&gt;Attacked Entity Geography: &lt;/b></description>      <pubDate>Wed, 16 Jun 2010 18:44:42 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>March 3, 2006</ddb:dateoccured>      <ddb:entrytitle>WHID 2006-9: EBay XSS</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Unlike other XSS cases, this was discovered due to actual abuse on a specific auction at EBay.&#13;&#10;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&#10;&lt;ul&gt;&#13;&#10;&lt;li&gt;&lt;a href=&quot;http://archives.neohapsis.com/archives/fulldisclosure/2006-02/0730.html&quot;&gt;Ebay XSS&lt;/a&gt; [Full Disclosure, Feb 28 2006]&lt;/li&gt;&#13;&#10;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Disinformation</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2006-9</ddb:whidid>    </item>    <item>      <title></title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=58188</link>      <description>&lt;b&gt;Date Occured: &lt;/b&gt;January 1, 2009 - August 23, 2010&lt;br&gt;&lt;b&gt;Reference: &lt;/b></description>      <pubDate>Mon, 23 Aug 2010 13:08:55 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>January 1, 2009 - August 23, 2010</ddb:dateoccured>      <ddb:entrytitle></ddb:entrytitle>      <ddb:incidentdescription></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome></ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid></ddb:whidid>    </item>    <item>      <title>WHID 2005-28: Phishers Steal Trust from eBay Sign In Pages</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=33932</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2005-28: Phishers Steal Trust from eBay Sign In Pages&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2005-28&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Phishing&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://news.netcraft.com/archives/2005/07/29/phishers_steal_trust_from_ebay_sign_in_pages.html&quot;&gt;Phishers Steal Trust from eBay Sign In Pages&lt;/a&gt; [Netcraft, Jul 29 2005]&lt;/li&gt;&lt;br&gt;&lt;/ul></description>      <pubDate>Wed, 16 Jun 2010 19:37:41 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured></ddb:dateoccured>      <ddb:entrytitle>WHID 2005-28: Phishers Steal Trust from eBay Sign In Pages</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://news.netcraft.com/archives/2005/07/29/phishers_steal_trust_from_ebay_sign_in_pages.html&quot;&gt;Phishers Steal Trust from eBay Sign In Pages&lt;/a&gt; [Netcraft, Jul 29 2005]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Phishing</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2005-28</ddb:whidid>    </item>    <item>      <title></title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=58187</link>      <description>&lt;b&gt;Reference: &lt;/b></description>      <pubDate>Mon, 23 Aug 2010 13:08:04 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured></ddb:dateoccured>      <ddb:entrytitle></ddb:entrytitle>      <ddb:incidentdescription></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome></ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid></ddb:whidid>    </item>    <item>      <title>WHID 2002-3: Reuters accused of hacking</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=33937</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2002-3: Reuters accused of hacking&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2002-3&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Leakage of Information&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;A company put its earnings report on site before its official release, but did not linked to it. Reuters found the document and published it.&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://news.com.com/2100-1023-963658.html&quot;&gt;Reuters accused of hacking&lt;/a&gt; [Cnet, Nov 29 2002]&lt;/li&gt;&lt;br&gt;&lt;/ul></description>      <pubDate>Wed, 16 Jun 2010 20:40:29 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured></ddb:dateoccured>      <ddb:entrytitle>WHID 2002-3: Reuters accused of hacking</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;A company put its earnings report on site before its official release, but did not linked to it. Reuters found the document and published it.&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://news.com.com/2100-1023-963658.html&quot;&gt;Reuters accused of hacking&lt;/a&gt; [Cnet, Nov 29 2002]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Leakage of Information</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2002-3</ddb:whidid>    </item>    <item>      <title>WHID 2005-4: An Israeli debate site vulnerable to XSS</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=33942</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2005-4: An Israeli debate site vulnerable to XSS&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2005-4&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Disclosure Only&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;An Israeli public debates site called Hyde Park has an XSS vulnerability that exposes session cookies.&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.nrg.co.il/online/10/ART1/049/017.html&quot;&gt;Identity theft in Hyde Park&lt;/a&gt; [nrg.co.il, Feb 16 2005]&lt;/li&gt;&lt;br&gt;&lt;/ul></description>      <pubDate>Wed, 16 Jun 2010 20:09:00 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured></ddb:dateoccured>      <ddb:entrytitle>WHID 2005-4: An Israeli debate site vulnerable to XSS</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;An Israeli public debates site called Hyde Park has an XSS vulnerability that exposes session cookies.&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.nrg.co.il/online/10/ART1/049/017.html&quot;&gt;Identity theft in Hyde Park&lt;/a&gt; [nrg.co.il, Feb 16 2005]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Disclosure Only</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2005-4</ddb:whidid>    </item>    <item>      <title>WHID 2005-49: Google Base launched with security hole</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34035</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2005-49: Google Base launched with security hole&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2005-49&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;February 28, 2006&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Disclosure Only&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;XSS in Google Base search function&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://www.pcworld.idg.com.au/index.php/id;751088708;fp;2;fpid;1&quot;&gt;Google Base launched with security hole&lt;/a&gt; [PC World, Nov 21 2005]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://jibbering.com/blog/?p=189&quot;&gt;More Google security failures&lt;/a&gt; [Jibbering.com, Nov 16 2005]&lt;/li&gt;&lt;br&gt;&lt;/ul></description>      <pubDate>Wed, 16 Jun 2010 19:06:41 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>February 28, 2006</ddb:dateoccured>      <ddb:entrytitle>WHID 2005-49: Google Base launched with security hole</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;XSS in Google Base search function&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://www.pcworld.idg.com.au/index.php/id;751088708;fp;2;fpid;1&quot;&gt;Google Base launched with security hole&lt;/a&gt; [PC World, Nov 21 2005]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://jibbering.com/blog/?p=189&quot;&gt;More Google security failures&lt;/a&gt; [Jibbering.com, Nov 16 2005]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Disclosure Only</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2005-49</ddb:whidid>    </item>    <item>      <title>WHID 2005-50: XSS on Yahoo Mail</title>      <link>http://wasc-whid.dabbledb.com/dabble/wasc-whid?view=36954&amp;entry=34030</link>      <description>&lt;b&gt;Entry Title: &lt;/b&gt;WHID 2005-50: XSS on Yahoo Mail&lt;br&gt;&lt;b&gt;WHID ID: &lt;/b&gt;2005-50&lt;br&gt;&lt;b&gt;Date Occured: &lt;/b&gt;February 28, 2006&lt;br&gt;&lt;b&gt;Outcome: &lt;/b&gt;Disclosure Only&lt;br&gt;&lt;b&gt;Incident Description: &lt;/b&gt;&lt;p&gt;Inserting code in an HTML attachments enables changing the user interface of Yahoo mail, which may enable fraud.&lt;br&gt;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://archives.neohapsis.com/archives/bugtraq/2005-11/0289.html&quot;&gt;XSS on Yahoo Mail&lt;/a&gt; [Bugtraq, Nov 23 2005]&lt;/li&gt;&lt;br&gt;&lt;li&gt;&lt;a href=&quot;http://richard.computeiro.com/yahoo_bug.jpg&quot;&gt;XSS on Yahoo Mail&lt;/a&gt; [Bugtraq, Nov 23 2005]&lt;/li&gt;&lt;br&gt;&lt;/ul></description>      <pubDate>Wed, 16 Jun 2010 19:05:49 -0400</pubDate>      <ddb:attackedentityfield></ddb:attackedentityfield>      <ddb:attackedentitygeography></ddb:attackedentitygeography>      <ddb:attackedsystemtechnology></ddb:attackedsystemtechnology>      <ddb:attacksourcegeography></ddb:attacksourcegeography>      <ddb:cost></ddb:cost>      <ddb:dateoccured>February 28, 2006</ddb:dateoccured>      <ddb:entrytitle>WHID 2005-50: XSS on Yahoo Mail</ddb:entrytitle>      <ddb:incidentdescription>&lt;p&gt;Inserting code in an HTML attachments enables changing the user interface of Yahoo mail, which may enable fraud.&#13;&lt;/p&gt;&lt;p&gt;Additional information:&lt;/p&gt;&#13;&lt;ul&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://archives.neohapsis.com/archives/bugtraq/2005-11/0289.html&quot;&gt;XSS on Yahoo Mail&lt;/a&gt; [Bugtraq, Nov 23 2005]&lt;/li&gt;&#13;&lt;li&gt;&lt;a href=&quot;http://richard.computeiro.com/yahoo_bug.jpg&quot;&gt;XSS on Yahoo Mail&lt;/a&gt; [Bugtraq, Nov 23 2005]&lt;/li&gt;&#13;&lt;/ul></ddb:incidentdescription>      <ddb:itemsleaked></ddb:itemsleaked>      <ddb:numberofrecords></ddb:numberofrecords>      <ddb:outcome>Disclosure Only</ddb:outcome>      <ddb:reference></ddb:reference>      <ddb:whidid>2005-50</ddb:whidid>    </item>  </channel></rss>