Sunday, August 28, 2011

During our ongoing investigation of the incident we have discovered that a database table containing developer forum members' email addresses has been accessed, by exploiting a vulnerability in the bulletin board software that allowed an SQL Injection attack. Initially we believed that only a small number of these forum member records had been accessed, but further investigation has identified that the number is significantly larger.

The database table records includes members’ email addresses and, for fewer than 7% who chose to include them in their public profile, either birth dates, homepage URL or usernames for AIM, ICQ, MSN, Skype or Yahoo. However, they do not contain sensitive information such as passwords or credit card details and so we do not believe the security of forum members’ accounts is at risk. Other Nokia accounts are not affected.
http://wl4.peer360.com/b/6z33Clk5oMzsHbFl36gc/main.asp?hl=110364988&r=BABIDIIH

No comments:

Legal

Anticipate This!™ | Patent and Trademark Law Blog

FOSS Patents

Groklaw

IP Law Blog

OUT-LAW News

Patent Docs

Patent Law Practice Center

Patently-O

Philip Brooks' Patent Infringement Updates

Reexamination Alert™

Steve van Dulken's Patent blog

Tactical IP

Think IP Strategy

Software

OSNews

Slashdot

Mobile Industry

Epic Mobile News

Mobiledia

mocoNews

Android

Apple

Microsoft

International

Asia and Australia

Europe

North and South America