Forum     

Go Back   Digit Technology Discussion Forum > News > Technology News
Register FAQ Calendar Mark Forums Read

Technology News News from the world of technology that our members stumble across. NOTE: Sources to be mentioned at the beginning of each post.


Closed Thread
 
LinkBack Thread Tools Display Modes
Old 05-05-2011, 04:17 PM   #1 (permalink)
Simply a DIGITian
 
krishnandu.sarkar's Avatar
 
Join Date: Nov 2007
Location: Kolkata
Posts: 2,955
Default CCAvenue Gateway Hacked


Quote:
CCAvenue, one of the largest online Payment gateways of India, has been compromised by a hacker who goes by the name d3hydr8.



According to HackerRegiment, this website was compromised by exploiting a SQL injection vulnerability and all the admin passwords which were apparently stored in Plain Text, have been leaked in a report which includes a list of databases, info on the tables within the databases and screenshots of the admin passwords of the CCAvenue portal.

Furthermore, it added that they have reported the issue to CERT India (Indian Computer Emergency Response Team) and are anticipating corrective action to be taken before the information becomes public through other channels.

Vishas Patel, CEO of Avenues India which runs CCAvenue, initially wasn’t sure of the damage and said he’d respond after they’ve looked into how significant the breach was. Although he added they didn’t store any credit card details or any other payment details.

In a quote to Medianama, he said:

“From our side, we’ll have to look into it. It is not possible, because of the kind of application level firewalls that we have put up. We don’t store credit card numbers or any other kind of payment details because of the Payment Card Industry Data Security Standards, and there is no credit card or payment related info on our servers. There are new standards that have come in, that is PCI DSS 2.0, which are more stringent than the earlier standards, and we have just completed the assessment under that last week.”

“More than 85-90% of our transactions are netbanking and non-credit cards related transactions. Those transactions go through the bank server, where the end customer enters usernames and passwords, and we don’t store those. They are entered on the bank servers. There is no payment related info on our servers. CCAvenue is just a redirector in this case.”

Later, he rebuffed the activity saying this is a mischevious slander against CCAvenue. He said the screenshot that has been leaked is not of their current database since it quotes the server type as Apache/2.2.14 and they have shifted to Apache/2.2.17 since 5 months.

He also said they had stored all the passwords as encrypted and not plain text as before, although users on Twitter are stating a different story.
Source : CCAvenue, India’s Payment Gateway gets hacked. CEO cries foul - TNW India

WTH??? How they can store passwords in plain text and SQL Injection?? They are not even this much secure

Not going to use it anymore...
__________________
  • Read The Forum RULES First.
  • Before PM'ing Or Asking Any Questions To Any Mod Read The FAQ's
  • Before Starting A New Thread Read The STICKY THREADS First
  • Before Participating In Bazaar Section Read The BAZAAR RULES
krishnandu.sarkar is online now  
Advertisements. Register and be a member of the community to get rid of them.
Advertisement

Old 05-05-2011, 05:06 PM   #2 (permalink)
Super Moderator
 
asingh's Avatar
 
Join Date: May 2008
Location: New Delhi
Posts: 5,550
Default Re: CCAvenue Gateway Hacked

I just cannot believe this. SQL Injection and then storage of passwords in plain text. What the heck.

How can you not use it, most gateways go via CC Avenue.
__________________
MSI P45 Platinum(BIOS v1.7B)|Q9550[E0]@3.85Ghz@1.320V[453x8.5]MCH@1.184V|ICH@1.55V|DDR_V_Ref_A_B@1.05V|NH-D14|Corsair TWIN2X4096-8500C5(5-5-5-15)@1089Mhz@2.14V
2xHD4890[Xfire]@1000/900[MEM/GPU]|Corsair 650TX|Seagate180GB+80GB+WD1TB|SONY-DVD-R|CM690|2x120mm Scythe Ultra Kaze|DELL S2409W|APC 1100VA|Scythe Kaze Server
Windows 7 Ultimate RTM - 64BIT|Catalyst 10.5 (8.14.10.0753) forced with RadeonPRO|PS3 160GB|Sony 40EX520|AC Ryan POHD Mini|APC 800VA|APC 800VA|D425KT|CM100 Elite|2TB WD|Acer D255

Test your spoiler tags before submitting
asingh is offline  
Old 05-05-2011, 05:20 PM   #3 (permalink)
Stuck in Time...
 
Vyom's Avatar
 
Join Date: May 2009
Location: Land of Logic
Posts: 2,278
Default Re: CCAvenue Gateway Hacked

The more I hear of such hacks, more I start to believe of the impending doom of 2012!

OMG! That's just not happening dude!!! CCAvenue!

My telephone bill, railway ticket booking... and even the recent digit subcription I did.. was all through the CCAvenue!

I dont want to spread panic... but... We are DOOMED!
__________________
Marty: Hey, Doc, we better back up. We don't have enough road to get up to 88.
Doc Brown: Roads? Where we're going, we don't need, "roads!" :)

──── On the Internet you can be Anything you want. It's Strange that, so many people choose to be Stupid! ────
Vyom is online now  
Old 05-05-2011, 05:41 PM   #4 (permalink)
Alpha Geek
 
baccilus's Avatar
 
Join Date: Feb 2006
Location: Chandigarh
Posts: 949
Default Re: CCAvenue Gateway Hacked

Where did 2012 come into this? Common man. From what I have seen, I have only ever entered passwords in the SBI site. Never in CCavenue site. But I will still keep an eye on my bank account.
__________________
Appreciate me now and avoid the rush!!
i5 2500K || 8GB DDRIII 1600 MHz RAM || Zotac GTX560Ti || Samsung 2233sw || Corsair GS600
baccilus is online now  
Old 05-05-2011, 06:16 PM   #5 (permalink)
ico
.
 
ico's Avatar
 
Join Date: Jun 2007
Location: New Delhi
Posts: 8,935
Default Re: CCAvenue Gateway Hacked

This is ridiculous. Plain text?
__________________
.
ico is offline  
Old 05-05-2011, 06:24 PM   #6 (permalink)
Excessive happiness
 
furious_gamer's Avatar
 
Join Date: Jun 2008
Location: Bangalore
Posts: 2,975
Default Re: CCAvenue Gateway Hacked

CCAvenue is a bunch of fools to store password as plaintext. Even a small company will encrypt the password and store it.

BTW In my prev company we used CCAvenue. Too bad such famous PG provider doomed by simple SQL injection, which a school going kid can do.
__________________
My First Android phone : Samsung Galaxy SL i9003 - Rooted & Gingerbread XXKPQ
Updated : superteekz_V2 ROM for XXKPQ.

PS Request
furious_gamer is offline  
Old 05-05-2011, 06:34 PM   #7 (permalink)
Broken In
 
Pratul_09's Avatar
 
Join Date: Sep 2007
Location: Navi Mumbai
Posts: 181
Default Re: CCAvenue Gateway Hacked

Quote:
Originally Posted by asingh View Post
I just cannot believe this. SQL Injection and then storage of passwords in plain text. What the heck.

How can you not use it, most gateways go via CC Avenue.
thinkdigit also uses the same gateway, this is hightime we look after the security aspect of payment gateways. before making a purchase we must verify the security.

Verisign certified.
Pratul_09 is online now  
Old 05-05-2011, 06:35 PM   #8 (permalink)
Excessive happiness
 
furious_gamer's Avatar
 
Join Date: Jun 2008
Location: Bangalore
Posts: 2,975
Default Re: CCAvenue Gateway Hacked

They are already hacked a few before IIRC.
__________________
My First Android phone : Samsung Galaxy SL i9003 - Rooted & Gingerbread XXKPQ
Updated : superteekz_V2 ROM for XXKPQ.

PS Request
furious_gamer is offline  
Old 05-05-2011, 07:12 PM   #9 (permalink)
Stuck in Time...
 
Vyom's Avatar
 
Join Date: May 2009
Location: Land of Logic
Posts: 2,278
Default Re: CCAvenue Gateway Hacked

So how many options we have other than CCAvenue?
And can anyone clarify what SQL injection actually is? Since supposedly even a school kid can crack?
__________________
Marty: Hey, Doc, we better back up. We don't have enough road to get up to 88.
Doc Brown: Roads? Where we're going, we don't need, "roads!" :)

──── On the Internet you can be Anything you want. It's Strange that, so many people choose to be Stupid! ────
Vyom is online now  
Old 05-05-2011, 07:42 PM   #10 (permalink)
mekalodu
 
iinfi's Avatar
 
Join Date: Oct 2004
Location: Navi Mumbai
Posts: 1,519
Default Re: CCAvenue Gateway Hacked

i dont think this news is true ....
__________________
mekalodu
iinfi is online now  
Old 05-05-2011, 08:31 PM   #11 (permalink)
Simply a DIGITian
 
krishnandu.sarkar's Avatar
 
Join Date: Nov 2007
Location: Kolkata
Posts: 2,955
Default Re: CCAvenue Gateway Hacked

Well, asingh is right, max. vendors use CCAvenue as their payment gateway, no idea what should we do next.

Quote:
Originally Posted by vineet369 View Post
So how many options we have other than CCAvenue?
And can anyone clarify what SQL injection actually is? Since supposedly even a school kid can crack?
SQL injection - Wikipedia, the free encyclopedia

Quote:
Originally Posted by iinfi View Post
i dont think this news is true ....
Dude, read the news, CCAvenue themselves accepted it, and the source is not fake, it's reliable.
__________________
  • Read The Forum RULES First.
  • Before PM'ing Or Asking Any Questions To Any Mod Read The FAQ's
  • Before Starting A New Thread Read The STICKY THREADS First
  • Before Participating In Bazaar Section Read The BAZAAR RULES
krishnandu.sarkar is online now  
Old 05-05-2011, 09:05 PM   #12 (permalink)
Stuck in Time...
 
Vyom's Avatar
 
Join Date: May 2009
Location: Land of Logic
Posts: 2,278
Default Re: CCAvenue Gateway Hacked

Quote:
“More than 85-90% of our transactions are netbanking and non-credit cards related transactions. Those transactions go through the bank server, where the end customer enters usernames and passwords, and we don’t store those. They are entered on the bank servers. There is no payment related info on our servers. CCAvenue is just a redirector in this case.”
Reading the above quote, I am relieved again. Since most of my transactions are through Net Banking
__________________
Marty: Hey, Doc, we better back up. We don't have enough road to get up to 88.
Doc Brown: Roads? Where we're going, we don't need, "roads!" :)

──── On the Internet you can be Anything you want. It's Strange that, so many people choose to be Stupid! ────
Vyom is online now  
Old 05-05-2011, 11:04 PM   #13 (permalink)
Simply a DIGITian
 
krishnandu.sarkar's Avatar
 
Join Date: Nov 2007
Location: Kolkata
Posts: 2,955
Default Re: CCAvenue Gateway Hacked

Yes, that's right, but I think I've used CC few times. Can't remember though.
__________________
  • Read The Forum RULES First.
  • Before PM'ing Or Asking Any Questions To Any Mod Read The FAQ's
  • Before Starting A New Thread Read The STICKY THREADS First
  • Before Participating In Bazaar Section Read The BAZAAR RULES
krishnandu.sarkar is online now  
Old 06-05-2011, 01:24 AM   #14 (permalink)
Uhu, Not Gonna Happen!
 
gagan007's Avatar
 
Join Date: Nov 2005
Location: Bangalore
Posts: 1,160
Default Re: CCAvenue Gateway Hacked

me too..and I have used credit card all the time
__________________
My personal blog - http://gagan.scholarguru.com
gagan007 is offline  
Old 06-05-2011, 02:02 AM   #15 (permalink)
Dev
 
dreatica's Avatar
 
Join Date: Oct 2010
Posts: 629
Default Re: CCAvenue Gateway Hacked

Quote:
Originally Posted by krishnandu.sarkar View Post
Yes, that's right, but I think I've used CC few times. Can't remember though.
Me too ? So after all the hype of PSN, and now ccavenue. The last payment made for digit subscription, 2 weeks back.
dreatica is offline  
Old 06-05-2011, 08:09 AM   #16 (permalink)
Simply a DIGITian
 
krishnandu.sarkar's Avatar
 
Join Date: Nov 2007
Location: Kolkata
Posts: 2,955
Default Re: CCAvenue Gateway Hacked

So what should we do now?? Is there anything that we can do??

I have registered for Mastercard Secure Code at the very beginning after getting the Card, but never got any site which asks for it to verify it.
__________________
  • Read The Forum RULES First.
  • Before PM'ing Or Asking Any Questions To Any Mod Read The FAQ's
  • Before Starting A New Thread Read The STICKY THREADS First
  • Before Participating In Bazaar Section Read The BAZAAR RULES
krishnandu.sarkar is online now  
Old 06-05-2011, 09:02 AM   #17 (permalink)
Dev
 
dreatica's Avatar
 
Join Date: Oct 2010
Posts: 629
Default Re: CCAvenue Gateway Hacked

Quote:
Originally Posted by krishnandu.sarkar View Post
So what should we do now?? Is there anything that we can do??

I have registered for Mastercard Secure Code at the very beginning after getting the Card, but never got any site which asks for it to verify it.
thats what I also want to know ? What to do know ? Call the bank and ask them to cancel my cc ?

Now, I remember I make the electricity, water, phone and god knows what else through ccavenue.

@krishnandu.sarkar I get the master secure code page whenever I make the payments. Why you don't get it ?
dreatica is offline  
Old 06-05-2011, 09:10 AM   #18 (permalink)
Rising Sun!
 
buddyram's Avatar
 
Join Date: Feb 2011
Location: Bengalooor
Posts: 234
Default Re: CCAvenue Gateway Hacked

This January i renewed my digit subscription through the same CCAvenue. I got a message stating that the login details which i entered would be transferred through an unencrypted channel. I was apprehensive about that but still there was no other go, trusting digit i carried on with the payment!
buddyram is online now  
Old 06-05-2011, 09:40 AM   #19 (permalink)
Simply a DIGITian
 
krishnandu.sarkar's Avatar
 
Join Date: Nov 2007
Location: Kolkata
Posts: 2,955
Default Re: CCAvenue Gateway Hacked

^^Yup that's right, whenever I bought anything, after making payment through SBI Net Banking, when it redirects it says it's going to send the data through unencrypted channel, and I used to go with it. And I guess many of us did that too.

@dreatica I've no idea, I registered for Mastercard Secure Code at the very beginning after getting my Card, but never asked for that while making payment. I can't remember particular services I used but it never asked for that password. I guess not all sites are compatible with it, so the sites which are compatible with it, asks for the password, others just make the transaction normally. One I can remember is Vodafone.in which I use for my recharge needs.
__________________
  • Read The Forum RULES First.
  • Before PM'ing Or Asking Any Questions To Any Mod Read The FAQ's
  • Before Starting A New Thread Read The STICKY THREADS First
  • Before Participating In Bazaar Section Read The BAZAAR RULES
krishnandu.sarkar is online now  
Old 06-05-2011, 09:50 AM   #20 (permalink)
Uhu, Not Gonna Happen!
 
gagan007's Avatar
 
Join Date: Nov 2005
Location: Bangalore
Posts: 1,160
Default Re: CCAvenue Gateway Hacked

@dreatica: for some gateways it doesn't ask the password..I am not sure why!
__________________
My personal blog - http://gagan.scholarguru.com
gagan007 is offline  
Old 06-05-2011, 10:16 AM   #21 (permalink)
In The Zone
 
Thor's Avatar
 
Join Date: Jun 2004
Location: Kolkata
Posts: 384
Default Re: CCAvenue Gateway Hacked

Krishnandu , thanks for bringing this to our notice.

This is such a setback now. Just when people of India were getting in the thick of things when it comes to the online shopping , transactions etc , CCAvenue , one of the most used and trusted Payment Gateway craps on our confidence . This is just horrible. Most of the time I have used HDFC Netsafe card which is good for only 1 transaction , looks like thats the way to go from now onwards.

This incident has now made me wonder, how secure really is Online shopping / marketing in Indian sites . If a payment gateways site can be hacked ( because of their earth shattering stupidity, negligence, etc etc ) , can the shopping portals be trusted ?
__________________
Beware of my Wrath Mortals, Thou hast no choice.
Thor is offline  
Old 06-05-2011, 10:36 AM   #22 (permalink)
God of Mistakes...
 
Garbage's Avatar
 
Join Date: Dec 2005
Location: Pune, Maharashtra
Posts: 1,923
Default Re: CCAvenue Gateway Hacked

Updated: CCAvenue CEO Vishwas Patel Denies Authenticity Of Hacking Report; Claims Mischief - MediaNama
__________________
Registered Linux User #468778
----------------------------------
http://twitter.com/_Garbage_
Garbage is offline  
Old 06-05-2011, 10:42 AM   #23 (permalink)
Excessive happiness
 
furious_gamer's Avatar
 
Join Date: Jun 2008
Location: Bangalore
Posts: 2,975
Default Re: CCAvenue Gateway Hacked

^^ looks conflicting. They claim they updated their server 5 months back but reports saying that its done very recently. Shame on CCAvenue
__________________
My First Android phone : Samsung Galaxy SL i9003 - Rooted & Gingerbread XXKPQ
Updated : superteekz_V2 ROM for XXKPQ.

PS Request
furious_gamer is offline  
Old 06-05-2011, 11:17 AM   #24 (permalink)
Super Moderator
 
asingh's Avatar
 
Join Date: May 2008
Location: New Delhi
Posts: 5,550
Default Re: CCAvenue Gateway Hacked

Payment Gateway CCAvenue Hacked [Updated/Open Questions]
__________________
MSI P45 Platinum(BIOS v1.7B)|Q9550[E0]@3.85Ghz@1.320V[453x8.5]MCH@1.184V|ICH@1.55V|DDR_V_Ref_A_B@1.05V|NH-D14|Corsair TWIN2X4096-8500C5(5-5-5-15)@1089Mhz@2.14V
2xHD4890[Xfire]@1000/900[MEM/GPU]|Corsair 650TX|Seagate180GB+80GB+WD1TB|SONY-DVD-R|CM690|2x120mm Scythe Ultra Kaze|DELL S2409W|APC 1100VA|Scythe Kaze Server
Windows 7 Ultimate RTM - 64BIT|Catalyst 10.5 (8.14.10.0753) forced with RadeonPRO|PS3 160GB|Sony 40EX520|AC Ryan POHD Mini|APC 800VA|APC 800VA|D425KT|CM100 Elite|2TB WD|Acer D255

Test your spoiler tags before submitting
asingh is offline  
Old 06-05-2011, 11:45 AM   #25 (permalink)
Simply a DIGITian
 
krishnandu.sarkar's Avatar
 
Join Date: Nov 2007
Location: Kolkata
Posts: 2,955
Default Re: CCAvenue Gateway Hacked

Quote:
Originally Posted by Thor View Post
Krishnandu , thanks for bringing this to our notice.
Welcome, But I didn't find this, I got the news from other forum and thought of sharing here too.
__________________
  • Read The Forum RULES First.
  • Before PM'ing Or Asking Any Questions To Any Mod Read The FAQ's
  • Before Starting A New Thread Read The STICKY THREADS First
  • Before Participating In Bazaar Section Read The BAZAAR RULES
krishnandu.sarkar is online now  
Old 06-05-2011, 03:51 PM   #26 (permalink)
Dev
 
dreatica's Avatar
 
Join Date: Oct 2010
Posts: 629
Default Re: CCAvenue Gateway Hacked

So what are these store passwords ? I never made any userid to use ccavenue ? Is this employee's database ?

http://www.hackerregiment.com/wp-con..._passwords.jpg

and the ccavenue peoples are lying that they updated the apache 5 months back. They have updated yesterday :

Netcraft What's That Site Running Results
dreatica is offline  
Old 06-05-2011, 03:57 PM   #27 (permalink)
Simply a DIGITian
 
krishnandu.sarkar's Avatar
 
Join Date: Nov 2007
Location: Kolkata
Posts: 2,955
Default Re: CCAvenue Gateway Hacked

Yes, they are the admin passwords. Not of users.

I guess their N/W admins are too noob to know that these things can be find out easily
__________________
  • Read The Forum RULES First.
  • Before PM'ing Or Asking Any Questions To Any Mod Read The FAQ's
  • Before Starting A New Thread Read The STICKY THREADS First
  • Before Participating In Bazaar Section Read The BAZAAR RULES
krishnandu.sarkar is online now  
Old 06-05-2011, 04:05 PM   #28 (permalink)
Dev
 
dreatica's Avatar
 
Join Date: Oct 2010
Posts: 629
Default Re: CCAvenue Gateway Hacked

Check this out :

Updated: CCAvenue CEO Vishwas Patel Denies Authenticity Of Hacking Report; Claims Mischief - MediaNama

The credit card numbers are not stored anywhere in our database, as per PCI norms. Only the first six and last 4 card numbers of the last 15 days are stored. And those are also BSI encrypted, for which there is a key, and to open that there is a master key, and those keys are not stored online anywhere. It is there with our head of security, who is the only person with access to it. The encryption has been in place on our servers for the last four years.

I made the last payment from ccavenue to digit on 18th, If the last 15 days is true, my A@@ is saved coz I just bump it for 16 day as the database was hacked on 4th may.
dreatica is offline  
Old 09-05-2011, 08:55 PM   #29 (permalink)
Mozilla Rep
 
sygeek's Avatar
 
Join Date: Apr 2011
Location: Lucknow
Posts: 1,471
Default Re: CCAvenue Gateway Hacked

CCAvenue hacked by SQL Injection...I mean WTF? Never realised CCAvenue would be this insecure, and to add to the stupidity, all the database of admin's login information was stored in plain text
sygeek is offline  
Old 09-05-2011, 11:39 PM   #30 (permalink)
Mmmph!!!
 
doomgiver's Avatar
 
Join Date: Nov 2010
Location: Mmmphhmph Mmphph
Posts: 1,408
Default Re: CCAvenue Gateway Hacked

lol, even script kiddies can do a sql inject.

are these the people to whom we trust our money?
__________________
Mmmphh-mphhhh-mmphh mhh!!!

Steam : doomgiver
doomgiver is offline  
Closed Thread

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


 
Latest Threads
- by Tenida
- by Who
- by clmlbx
- by Charan
- by abhidev

Advertisement




All times are GMT +5.5. The time now is 08:14 PM.


Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2012, vBulletin Solutions, Inc.

Search Engine Optimization by vBSEO 3.3.2