funsec mailing list archives

[privacy] U.S. Pro Soccer's Online Shoppers Get Kicked By Security Breach


From: "Paul Ferguson" <fergdawg () netzero net>
Date: Sat, 9 Feb 2008 02:20:16 GMT

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Via ComputerWorld.

[snip]

A series of SQL injection attacks on servers hosted by a third-party
service provider has compromised the personal data of an unspecified number
of individuals who had shopped on Major League Soccer's MLSgear.com Web
site.

The compromised information included names, addresses, credit and debit
card data, and MLSgear.com passwords, MLS President Mark Abbott said in a
letter sent to affected individuals on Feb. 1. MLSgear.com is the soccer
league's official online store.

The incident was first reported by PogoWasRight.org, a blog that tracks
data breaches. The blog site also posted a link to a notice that was sent
by MLSgear.com to the office of New Hampshire's attorney general, informing
the AG of the breach and saying that it affected 169 New Hampshire
residents.

[snip]

More:
http://computerworld.com/action/article.do?command=viewArticleBasic&taxonom
yName=security&articleId=9061858

Pogo Was Right:
http://www.pogowasright.org/article.php?story=20080208084547770

- - ferg


-----BEGIN PGP SIGNATURE-----
Version: PGP Desktop 9.6.3 (Build 3017)

wj8DBQFHrQ3dq1pz9mNUZTMRAuEmAKCuaaUPJL9Xzk4IgJbCR6F6DY+GegCg1DfB
l3sLuKOK53G5O1rNmKOAE44=
=TXmN
-----END PGP SIGNATURE-----

--
"Fergie", a.k.a. Paul Ferguson
 Engineering Architecture for the Internet
 fergdawg(at)netzero.net
 ferg's tech blog: http://fergdawg.blogspot.com/

_______________________________________________
privacy mailing list
privacy () whitestar linuxbox org
http://www.whitestar.linuxbox.org/mailman/listinfo/privacy


Current thread: