Posted by : Cyber Freak
Tuesday, 30 August 2011
Hackers have accessed user details from Nokia's online forum for software developers, prompting the mobile phone giant to temporarily shut down the "Community" section of its main developers' site. Nokia also admitted that the number of users affected was larger than thought.
The company, which has yet to reveal the exact scale of the attack, said that a database table with forum members' email addresses had been accessed. "Initially, we believed that only a small number of these forum member records had been accessed, but further investigation has identified that the number is significantly larger," it said in an official statement. Nokia added that no credit card details were accessed, although about 7% of the compromised records included data for other web accounts like Skype.
The hackers exploited a vulnerability in Nokia's bulletin board software using an SQL Injection attack. There has been a surge of cyber attacks on companies this year using SQL Injection, a relatively straightforward method that involves inputting programming code, which a server or site cannot handle. Supporters of the subversive online identity Anonymous are known to have used the method, as did a splinter group of hackers this summer called LulzSec.
The attackers left a deface page mentioning "AntiSec." LulzSec revived the so-called AntiSec or AntiSecurity movement earlier this summer calling on web activists and cyber insurgents to attack governments and corporations to expose corruption and protect individual privacy. This meanwhile represents another hurdle for software developers who work with Nokia. In recent months they faced the prospect of a forced change in focus, after Nokia said it would stop using the Symbian operating system on forthcoming smartphones in favor of Windows Phone.