India’s Leading Payment Gateway “CCAvenue” Hacked by SQL Injection
digitizor.com
digitizor.com
Indian market is paranoid about online security. This will bring down the number of online sales. Too bad for start-ups depending on CCAvenue.
So you’re saying that the merchant data has not been accessed? > It hasn’t. If you see, apache 2.2.14 – we’ve been live with apache 2.2.17 for last five months.
You’re also saying that merchant account passwords have not been stored as plain text? > They are encrypted, and not stored as plain text.
Have you ever been told that there is a security hole of some sort? > We are looking into this, and this is the intial report. From time to time what we get, I am sharing with you. As more information comes out as we investigate, we will share it.
More updates posted here... http://www.medianama.com/2011/05/223-ccavenue-hacked/
They also claim to have PCI DSS 2.0 certified. In light of all the discussions happening repeatedly about need to regenerate passwords & not to store plain text passwords if they have it this way, this is so stupid.
If I were a customer of CCAvenue I would close my account and move to someone like DirecPay from Times Of Money.
May be this is an opportunity for these kind of payment service providers to come out clean & prove it out to the world (at least in forums like HN) as to how paranoid they are about security?
This is bad, very bad in fact. Its amazing things like this happen from time to time, even things like storing passwords in plain text. This goes on to show only two things, either utter negligence and lack of seriousness on the part of designers or just that they are not aware of even the very basics of computer security.
Engineers passing out of colleges with just degrees and some out side memorized bookish knowledge. Copy pasting snippets of code from the internet when they are asked to write code. Just doing minimal feature compliance tests. Lack of idea of seriousness of jobs they are doing. Failure to understand the overall architecture. And hopping jobs when this sort of things happen.
A ideal approach to computer science security is to have professionals obtain licenses. All people working on security must obtain a license. And failing on things like this must attract penalties and punishments.
Certification doesn't mean anything. In reality, whatever it takes to protect data, companies should do that; Even if it means doing things, which is not written in books.
@kamaal, I agree with you. CCAvenue must have had these since it's first version, they were fortunate no one ever tried sql-injection attacks on them.
It looks like either CEO is not technical or he is misinformed or engineers who implemented have no idea about hashing, encryption and other terms. I bet, most freshers or even experienced engineers here in India, would not know about sql-injection and storing passwords as hashes.
Having said that, there are brilliant guys here as well, hence all those R&D centers of Y!, Google, et al.
Gist of what I find in wikipedia is this:
PCI DSS Requirements: Build and Maintain a Secure Network 1. Install and maintain a firewall configuration to protect cardholder data 2. Do not use vendor-supplied defaults for system passwords and other security parameters
Protect Cardholder Data 3. Protect stored cardholder data 4. Encrypt transmission of cardholder data across open, public networks
Maintain a Vulnerability Management Program 5. Use and regularly update anti-virus software on all systems commonly affected by malware 6. Develop and maintain secure systems and applications
Implement Strong Access Control Measures 7. Restrict access to cardholder data by business need-to-know 8. Assign a unique ID to each person with computer access 9. Restrict physical access to cardholder data
Regularly Monitor and Test Networks 10. Track and monitor all access to network resources and cardholder data 11. Regularly test security systems and processes
Maintain an Information Security Policy 12. Maintain a policy that addresses information security
Well the problem is simple. Some things break or get messed up. Now a root cause analysis is done and its found if a particular thing had been taken care of, the problem would have been avoided.
So now what is the step taken? The solution to the root cause analysis is put as a 'checklist' and now applied to everything or when something is done. And this is put in as a process. Do this, do that... every time you deploy or code something.
Now here comes the problem, the people who write the checklist understand that its only a guidance rather than a compliance document. People who come later or those who don't think take the both the process and checklist as some sort of document which if you adhere to, your job is done. And anything and everything else can be done without proper testing or thinking.
This goes on until something breaks again, root cause is now found and it goes into that checklist.
Its this sort of approach to technology and programming that is creating all the problems in software today. No certification can fix this problem.