<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: mlsgear]]></title>
    <link>http://securityratty.com/tag/mlsgear</link>
    <description></description>
    <pubDate>Thu, 07 Feb 2008 21:00:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[SQL injection compromises MLSgear.com customer information]]></title>
      <link>http://securityratty.com/article/5193b99d7531d1457fbe8530678288f7</link>
      <guid>http://securityratty.com/article/5193b99d7531d1457fbe8530678288f7</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
2/1/08

Organization
Major League Soccer, L.L.C

Contractor/Consultant/Branch
MLSgear.com
Unnamed hosting provider

Victims
MLSgear.com customers

Number...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/mlsgear.jpg" align="right" height="22" width="198"><font size="2"><span style="font-weight: bold;">Date Reported: </span><br>2/1/08<br><br><span style="font-weight: bold;">Organization: </span><br><a href="http://web.mlsnet.com/index.jsp" target="_blank"> Major League Soccer, L.L.C.</a> <br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br><a href="http://www.mlsgear.com/home/index.jsp?clickid=topnav_home_txt" target="_blank"> MLSgear.com</a> <br>Unnamed hosting provider<br><br><span style="font-weight: bold;">Victims:</span><br>MLSgear.com customers<br><br><span style="font-weight: bold;">Number Affected:</span><br>Unknown*<br><br><font size="1">*MLSgear.com informed the New Hampshire Attorney General that there are 169 affected persons in her state</font><br><br><span style="font-weight: bold;">Types of Data:</span><br>Names, addresses, credit and debit card information, and MLSGear.com passwords<br><br><span style="font-weight: bold;">Breach Description:</span><br>An unauthorized third-party attempted to obtain access to, and may have accessed personal information belonging to MLSgear.com customers through the use of SQL injection attacks carried out on the MLSgear.com web site between January and August, 2007.<br><br><span style="font-weight: bold;">Reference URL:</span><br><a href="http://doj.nh.gov/consumer/pdf/MLSgear.pdf" target="_blank"> The New Hampshire State Attorney General breach notification</a> <br><a href="http://computerworld.com/action/article.do?command=viewArticleBasic&amp;taxonomyName=security&amp;articleId=9061858&amp;taxonomyId=17&amp;intsrc=kc_top" target="_blank"> Computerworld online story</a> <br><a href="http://www.pogowasright.org/article.php?story=20080208084547770" target="_blank"> PogoWasRight.org report</a> <br><br><span style="font-weight: bold;">Report Credit:</span><br>The New Hampshire State Attorney General<br><br><span style="font-weight: bold;">Response:</span><br>From the online sources cited above:<br><br>It has recently come to our attention that an unauthorized third party has attempted to obtain access to, and may have accessed the personal information of customers of the MLSGear.com website<br><br>Based upon the forensic audit we commissioned upon the request of Visa and MasterCard, our current understanding of this situation is that these third parties used SQL Injection attacks between January and August 2007, and may have obtained names, addresses, credit and debit card information, and MLSGear.com passwords, that had been stored on computer servers operated by a third party service provider.<br><i>[Evan] SQL Injection attacks have been around ever since there was SQL (a long time!).&nbsp; SecuriTeam has a pretty good <a href="http://www.securiteam.com/securityreviews/5DP0N1P76E.html" target="_blank"> explanation</a> of how it works, or a pretty good demo on <a href="http://www.youtube.com/watch?v=MJNJjh4jORY" target="_blank"> YouTube</a>.</i><br><br><a style="border-width: 0px; margin: 0px; padding: 0px; outline-offset: -1px; display: inline;" title="&lt;OBJECT&gt;, shockwave-flash@http://www.youtube.com/v/MJNJjh4jORY&amp;rel=1" class="__noscriptPlaceholder__" href="http://www.youtube.com/v/MJNJjh4jORY&amp;rel=1" id=""><div style="border: 0px none rgb(0, 0, 0); margin: 0px; padding: 0px; overflow: visible; background-attachment: scroll; background-color: transparent; background-image: none; background-repeat: repeat; border-collapse: separate; border-spacing: 0px; bottom: auto; caption-side: top; clear: none; clip: rect(auto, auto, auto, auto); color: rgb(0, 0, 0); counter-increment: none; counter-reset: none; cursor: default; direction: ltr; display: block; empty-cells: -moz-show-background; float: none; font-family: Verdana; font-size: 13px; font-size-adjust: none; font-style: normal; font-variant: normal; font-weight: 400; height: 355px; left: auto; letter-spacing: normal; line-height: normal; list-style-image: none; list-style-position: outside; list-style-type: disc; max-height: none; max-width: none; min-height: 32px; min-width: 32px; outline-color: rgb(0, 0, 0); outline-style: none; outline-width: 0px; outline-offset: 0px; position: static; right: auto; table-layout: auto; text-align: left; text-decoration: none; text-indent: 0px; text-transform: none; top: auto; unicode-bidi: normal; vertical-align: 0px; visibility: visible; white-space: normal; width: 425px; word-spacing: normal; z-index: auto; -moz-appearance: none; -moz-background-clip: border; -moz-background-inline-policy: continuous; -moz-background-origin: padding; -moz-binding: none; -moz-border-bottom-colors: none; -moz-border-left-colors: none; -moz-border-right-colors: none; -moz-border-top-colors: none; -moz-border-radius-bottomleft: 0px; -moz-border-radius-bottomright: 0px; -moz-border-radius-topleft: 0px; -moz-border-radius-topright: 0px; -moz-box-align: stretch; -moz-box-direction: normal; -moz-box-flex: 0; -moz-box-ordinal-group: 1; -moz-box-orient: horizontal; -moz-box-pack: start; -moz-box-sizing: content-box; -moz-column-count: auto; -moz-column-width: auto; -moz-column-gap: 0px; -moz-float-edge: content-box; -moz-image-region: rect(auto, auto, auto, auto); opacity: 1; -moz-outline-radius-bottomleft: 0px; -moz-outline-radius-bottomright: 0px; -moz-outline-radius-topleft: 0px; -moz-outline-radius-topright: 0px; -moz-user-focus: none; -moz-user-input: auto; -moz-user-modify: read-only;"></div></a><br>We have a zero tolerance policy when it comes to protection of our customers' personal information and consequently, we are terminating our relationship with that e-commerce provider.<br><i>[Evan] I don't know who MLSgear.com was hosted with before, but they appear to be hosted by GSI Commerce at the time I am writing this.&nbsp; GSI Commerce also hosts Liz Claiborne, Dicks Sporting Goods, Polo, Major League Baseball, Radioshack, NASCAR, among others.</i><br><br>We have also taken immediate steps to further strengthen our already stringent security measures to safeguard the privacy of customer personal and credit information, including purging all passwords<br><br>We are notifying on approximately February 1, 2008, all customers whose information was potentially affected by the above-described activity.<br><br>we have arranged for and are offering to all affected customers one year of credit monitoring services and, if necessary credit restoration with Kroll Background America, Inc., free to the customer<br><i>[Evan] Affected customers are not signed-up automatically, they will need to follow the instructions received in their letter.</i><br><br>We have also contacted federal law enforcement and are currently working with the Federal Bureau of Investigation. Further, we are working with VISA, Mastercard and Chase Paymentech our credit card payment processor on this issue<br><br>Please be assured that MLSGear.com remains committed to ensuring the safety and security of our customers' sensitive personal information. We appreciate your support and sincerely apologize for this incident.<br><br><b>Commentary:</b><br>There were 169 affected individuals in New Hampshire alone.&nbsp; I imagine that the total number globally could be much larger.&nbsp; Victims aren't as much at risk of identity theft as they are of credit card fraud.&nbsp; If an affected customer knows which card they used for purchases on MLSgear.com, they should cancel the card and get a new one (with a new number).<br><br>SQL injection attacks should have been detected through the quarterly online security scans that are required as part of VISA compliance. <br><br><b>Past Breaches:</b><br>Unknown</font><br><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/02/11/mlsgear.aspx" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
      <pubDate>Mon, 11 Feb 2008 06:27:06 +0000</pubDate>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/sensitive personal information">sensitive personal information</category>
      <category domain="http://securityratty.com/tag/personal information">personal information</category>
      <category domain="http://securityratty.com/tag/mlsgear">mlsgear</category>
      <category domain="http://securityratty.com/tag/sql">sql</category>
      <category domain="http://securityratty.com/tag/debit card information">debit card information</category>
      <category domain="http://securityratty.com/tag/report credit">report credit</category>
      <category domain="http://securityratty.com/tag/credit">credit</category>
      <category domain="http://securityratty.com/tag/credit card fraud">credit card fraud</category>
      <source url="http://breachblog.com/2008/02/11/mlsgear.aspx">SQL injection compromises MLSgear.com customer information</source>
    </item>
    <item>
      <title><![CDATA[Soccer league's online shoppers get hit by security breach]]></title>
      <link>http://securityratty.com/article/b15fe65698d15e4351bc43028f25533a</link>
      <guid>http://securityratty.com/article/b15fe65698d15e4351bc43028f25533a</guid>
      <description><![CDATA[A series of SQL injection attacks on servers hosted by a third-party service provider has compromised the personal data of an unspecified number of individuals who had shopped on Major League Soccer's...]]></description>
      <content:encoded><![CDATA[A series of SQL injection attacks on servers hosted by a third-party service provider has compromised the personal data of an unspecified number of individuals who had shopped on Major League Soccer's MLSgear.com Web site.<p><NOLAYER>
<IFRAME id="rss" src="http://ad.doubleclick.net/adi/idg.us.nwf.rss/security;sz=468x60;ord=89352?" width="468" height="60" frameborder="no" border="0" marginwidth="0" marginheight="0" scrolling="no">
<A href="http://ad.doubleclick.net/jump/idg.us.nwf.rss/security;sz=468x60;ord=89352?">
<IMG src="http://ad.doubleclick.net/ad/idg.us.nwf.rss/security;sz=468x60;ord=89352?" border="0" width="468" height="60"></A>
</IFRAME>
</NOLAYER></p>]]></content:encoded>
      <pubDate>Thu, 07 Feb 2008 21:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/major league soccer">major league soccer</category>
      <category domain="http://securityratty.com/tag/sql injection attacks">sql injection attacks</category>
      <category domain="http://securityratty.com/tag/third-party service provider">third-party service provider</category>
      <category domain="http://securityratty.com/tag/personal data">personal data</category>
      <category domain="http://securityratty.com/tag/web site">web site</category>
      <category domain="http://securityratty.com/tag/mlsgear">mlsgear</category>
      <category domain="http://securityratty.com/tag/individuals">individuals</category>
      <category domain="http://securityratty.com/tag/series">series</category>
      <category domain="http://securityratty.com/tag/servers">servers</category>
      <source url="http://www.networkworld.com/news/2008/020808-soccer-leagues-online-shoppers-get.html?fsrc=rss-security">Soccer league's online shoppers get hit by security breach</source>
    </item>
  </channel>
</rss>
