Feeds

Symantec finally secures HackIsWack

It's such a bungle, sometimes, it makes you wonder...

Beginner's guide to SSL certificates

Symantec has belatedly secured its laughable HackIsWack competition website.

The site - a collaboration between the security software firm and rapper Snoop Dogg - is designed to raise awareness about malware and identity theft by providing a forum for a user-generated cybercrime-themed rap competition. The site had a slow start, and currently boasts an underwhelming 22 videos.

Reg commentards have described the campaign as the most comically inept since the Don't Copy that Floppy anti-piracy screed of the 1990s, an earlier rap music meets security multi-purpose fail.

Even more embarrassingly the security giant went live with a branded site that was riddled with security holes, including a cross-site scripting flaw that amusingly lent itself to a rickrolling attack. In a statement issued over the weekend, Symantec acknowledged the problems, which it said were now resolved.

Symantec was made aware of reported vulnerabilities to the Norton Hack is Wack microsite, and we quickly took the necessary steps to enhance security on the site. We have found no evidence to date that any intrusion into the site or other areas of Symantec’s network or website have occurred.

To date, Symantec can confirm that no company or customer data has been compromised or exposed.  Symantec takes the security of our website and microsites very seriously, and we have taken the necessary steps to resolve this issue.

The statement fails to explain why Symantec went live with an apparently untested and seriously flawed site, which one wag suggested might have been coded by Snoop Dogg rather than an experienced security-aware web developer.

The rickrolling XSS was only the most publicised of the site's many flaws. Security blogger Mike Bailey did a good job last week in compiling a list of numerous flaws present on the site at the time, which included the caching of potentially sensitive data and upload security problems, among others.

Hack is Wack site is chock full of holes. For example, there's the publicly available, indexed cache directory with all that SQL, JSON and other data. There's the XSS vulns (HTML5 only, though it should be simple enough to rewrite), CSRF holes, and the Flash upload issues in the video upload script (a Joomla module that appears to have been used without any quality control or review despite the fact that it's currently in Alpha)

The original XSS rickrolling exploit has been blocked and, we take on trust but have not confirmed, Symantec has also mopped up the other flaws on the site. ®

Protecting users from Firesheep and other Sidejacking attacks with SSL

More from The Register

next story
Spies would need SUPER POWERS to tap undersea cables
Why mess with armoured 10kV cables when land-based, and legal, snoop tools are easier?
Early result from Scots indyref vote? NAW, Jimmy - it's a SCAM
Anyone claiming to know before tomorrow is telling porkies
Jihadi terrorists DIDN'T encrypt their comms 'cos of Snowden leaks
Intel bods' analysis concludes 'no significant change' after whistle was blown
TOR users become FBI's No.1 hacking target after legal power grab
Be afeared, me hearties, these scoundrels be spying our signals
Home Depot: 56 million bank cards pwned by malware in our tills
That's about 50 per cent bigger than the Target tills mega-hack
Hackers pop Brazil newspaper to root home routers
Step One: try default passwords. Step Two: Repeat Step One until success
China hacked US Army transport orgs TWENTY TIMES in ONE YEAR
FBI et al knew of nine hacks - but didn't tell TRANSCOM
Microsoft to patch ASP.NET mess even if you don't
We know what's good for you, because we made the mess says Redmond
NORKS ban Wi-Fi and satellite internet at embassies
Crackdown on tardy diplomatic sysadmins providing accidental unfiltered internet access
prev story

Whitepapers

Providing a secure and efficient Helpdesk
A single remote control platform for user support is be key to providing an efficient helpdesk. Retain full control over the way in which screen and keystroke data is transmitted.
WIN a very cool portable ZX Spectrum
Win a one-off portable Spectrum built by legendary hardware hacker Ben Heck
Saudi Petroleum chooses Tegile storage solution
A storage solution that addresses company growth and performance for business-critical applications of caseware archive and search along with other key operational systems.
Protecting users from Firesheep and other Sidejacking attacks with SSL
Discussing the vulnerabilities inherent in Wi-Fi networks, and how using TLS/SSL for your entire site will assure security.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.