程阳:英国黑客组织声称国家彩票网有安全漏洞
2009-03-04 21:49阅读:
程阳:英国黑客组织声称国家彩票网有安全漏洞
运营商卡米洛特坚持说网站安全可靠
UK Hacker Group Claims Holes in Camelot Security
Camelot dismisses lottery website hack claims; Unu strikes
again
Camelot maintains the National Lottery website it runs is secure,
following the publication of a supposed breach on an underground
hacking
forum.
The same Romanian group that discovered SQL injection problems on
the website of Kaspersky, BitDefender, and other anti-virus vendors
in
recent weeks has posted screen shots of supposed flaws on the
national-lottery.co.uk site.
Unu, a member of the hacker group, claims that 'an unsecured
parameter allows access to the database' behind the website. The
screenshots
appear to illustrate partially redacted listings from a database
table and partial login credentials for an admin account.
However Camelot, the firm that runs the UK's National Lottery
including its online version, said it was confident its systems are
secure.
'Camelot can confirm that the main player site at
www.national-lottery.co.uk
has not been compromised, as outlined on softpedia.com [story
here],' it said in a statement. 'As a result, there is no risk to
company or player information.'
'We do our utmost to continually ensure that our interactive
systems are as secure as possible, and regularly review the
extensive measures
in place to safeguard our players. We have implemented industry
standard technical solutions to protect our systems and to ensure
that player
information is kept secure at all times.'
Despite Camelot's assurance, security watchers think Unu's posting
illustrates cause for concern. Gareth Catterall, a security analyst
at
Sophos said SQL injection attacks are nearly always
significant.
'This is obviously a vulnerability that would need to be cleaned
up. In my personal opinion, with an information-revealing
vulnerability such
as this it can be only a matter of time before full penetration can
occur,' he said.
Source: The Register (London), By John Leyden, 27th February
2009
广西女孩英国中奖2亿元!
程阳:Camelot
2009 Annual
Report
程阳:UK
National
Lottery
Commission
程阳:Freedom
of
Information
Act
2000-Publication
Scheme
程阳:UK Lottery celebrates its
15th birthday
程阳:National Lottery (United
Kingdom)
程阳:UK National
Lottery
History
程阳:英国的国家彩票法令
程阳:发达的英国彩票业
程阳:英国的电视彩票
程阳:The Gaming Industry in the
United Kingdom
程阳:英国探求网上博彩监
程阳:死亡的几率VS大英彩票的几率
程阳:英国黑客组织声称国家彩票网有安全漏洞
亚博科技收购英国游戏开发商Gextech
广西青年交流团启程赴英
程阳:US and CAN lottery sales
in FY08
The Camelot Social
Report 2005
汤宗德:英国、美国、日本信息公开法比较
英国信息自由法(Freedom
of Information Act 2000)
汤德宗:资讯公开与资讯隐私法
从《信息自由法案》看《信息公开条例》的实施
信息民主的保障——政府信息公开制度