In association with heise online

22 February 2012, 11:58

Porn portal's user database open and accessible on the net

  • Twitter
  • Facebook
  • submit to slashdot
  • StumbleUpon
  • submit to reddit

Open security icon Apparently, the user database of the videosz.com porn portal was openly available on the internet. The VideosZ site offers adult customers the ability to download any available porn DVD for a fee of about $30. But a security hole allowed several hundred thousand data records of customers and affiliate partners, including such information as addresses, passwords, credit card details and downloaded movies, to be accessed without password authentication.

An anonymous reader of heise Security, The H's associate in Germany, had stumbled across an IP address that gave access to a server with an unprotected phpMyAdmin interface. Such servers are usually protected by a log-in procedure and can normally only be accessed from specific computers.

In addition to customer data, the database also exposed the business data of VideosZ affiliates and information on paid premiums. Heise Security informed the server operators of the problem, and access protection was implemented as a result. However, VideosZ declined to comment further on the issue.

(djwm)

Print Version | Send by email | Permalink: http://h-online.com/-1440233
 


  • July's Community Calendar





The H Open

The H Security

The H Developer

The H Internet Toolkit