BitDefender Antivirus
BitDefender PressCenter / In regards to BitDefender’s partner’s website vulnerability
February 2009

In regards to BitDefender’s partner’s website vulnerability


we have the following update:


· The vulnerability was found by BitDefender’s blog monitoring activities

· We immediately notified our partner and the site was shutdown very shortly after.

· Working with our partner, we corrected the vulnerability and the site reopened at 6pm WET (GMT) time, February 9th.

· Our current review indicates that no customer data was stolen.

· During investigation, it appears that the attack was not intended to steal information, but simply to show vulnerability.

· It is important to highlight that BitDefender does not store customer credit card information on any of our sites, to protect customer privacy and ensure that this type of information is not accessible to attack.

· The website vulnerability exploited seems common. SQL injection and XSS (cross site scripting)

· All BitDefender owned sites execute routine protection processes to ensure that these severely limit vulnerability to these types of attacks. While we can’t control how our partners manage their sites, we do work with them to foster best practices in protection.

· As a result of this attack, BitDefender worked with our partners, reevaluated their Web defense strategies and where necessary took corrective action to avoid this type of attack, ensuring they have the support and resources necessary for adequate web defense.



Digg this story    del.ici.us

* * *

About BitDefender®
BitDefender is the creator of one of the industry's fastest and most effective lines of internationally certified security software. Since its inception in 2001, BitDefender has continued to raise the bar and set new standards in proactive threat prevention. Every day, BitDefender protects tens of millions of home and corporate users across the globe - giving them the peace of mind of knowing that their digital experiences will be secure. BitDefender solutions are distributed by a global network of value-added distribution and reseller partners in more than 100 countries worldwide. More information about BitDefender and its products are available at the company’s security solutions press room. Additionally, BitDefender’s www.malwarecity.com provides background and the latest updates on security threats helping users stay informed in the everyday battle against malware.