Multiple Vulnerabilities in BitDefender website

Status
Not open for further replies.

Viking

Level 26
Thread author
Verified
Honorary Member
Top Poster
Well-known
Forum Veteran
Oct 2, 2011
1,556
12,811
2,478
Australia
A Security Researcher from crackhackforum.com, Rynaldo, has discovered multiple Vulnerabilities in one of the Biggest Antivirus company called "BitDefender".

The researcher claimed that he sent several emails to BitDenfender's team, butthey haven't responded nor fixed the vulnerabilities neither.

"The website is having several reflected XXS vulnerabilities and the CSRF
vulnerability. Also I have found a way to cause DOS attack on the local
server to take BitDefender temporarely down." Rynaldo said.

CSRF attack : https://my.bitdefender.com/en_us/my/#page=account.index hacker is able to perform CSRF attack to change the details on the user's profile.CSRF tokens aren't implemented and password isn't required to change information on the profile.

http://www.ehackingnews.com/2013/01/multiple-vulnerabilities-in-bitdefender.html
 
A kick in nuts for people who bought BIS...The company cannot even protect their own site,why would it protect the users which are using it...
 
i uninstalled bitdefender internet security because it was blocking everything so maybe more stuff was hacked into and not just the web site did anyone else had problems yesterday with it
 
Payback said:
A kick in nuts for people who bought BIS...The company cannot even protect their own site,why would it protect the users which are using it...

That came to my mind yesterday as I installed a trial of BitDefender IS 2013. Can even create an account for it..reverted back to a system image without it.
 
Status
Not open for further replies.