CCAvenue denies hacking attack

Advertisement
By NDTV Correspondent | Updated: 5 June 2012 02:09 IST
Highlights
  • Hackers claim to have hacked CCAvenue, an online commerce service provider in India, by exploiting “SQL injection vulnerability”.
Online commerce service provider, CCAvenue, has denied that its portal has been hacked.
 
Vishwas Patel, CEO,  CCAvenue told NDTVGadgets, "I confirm that the image posted by a hacker is a spoofed, self-created one and not that of our database and it has been created just to create panic and defame our company. We are in the process of filing a criminal complaint against the unknown hacker for the slander and malicious campaign run against our company."
 
Earlier today, we reported that a hacker claimed to have broken into CCAvenue by exploiting "SQL injection vulnerability".  The hacker, identifying himself as d3hydr8, submitted what he called a full disclosure of his attack on HackerRegiment.com. The "report" included what the hacker said were all the admin usernames and passwords of the CCAvenue portal.
 
In what was his first reaction on this,  Vishwas Patel said, "First and most [we] would like to say that this a slanderous campaign that is targeting CCAvenue. Based on our initial investigations by our security officials, we confirm that no hack has happened of our servers at 1515 hours on 04th May 2011 by the following person, as claimed in his article. We also confirm that  that the screenshot is not of our live database as the Apache version on live server is 2.2.17 (Updated more than 5 months ago) and not 2.2.14 (as claimed by the hacker). We also confirm that all the passwords of our merchants and all login credentials in our live database are encrypted and stored in our database and not in text format as claimed by the hacker."
 
He also assured that, "We don't store credit card details or Netbanking account details on our servers."
 
HackerRegiment has published the details submitted by the hacker but has maintained discretion by blurring the "passwords". The information published includes a list of databases, some information on tables within the databases, and screenshots of the administrator usernames and passwords.
 
HackerRegiment.com also claims to have reported the issue to CERT (Computer Emergency Response Team) India to help CCAvenue take corrective action before any information is released through any other media.

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement
Popular Mobile Brands
  1. Google Pixel 10 Users Can Now Play Steam Games Offline via GameNative
  2. Infinix GT 50 Pro Design, Cooling, Gaming Features Leaked Again
  3. Euphoria Is Streaming Online: Know Where to Watch Sara Arjun's Social Thriller
  1. Euphoria Is Streaming Online: Know Where to Watch Sara Arjun's Social Thriller
  2. Valathu Vashathe Kallan Is Now Streaming: Know All About Jeethu Joseph's Crime Thriller
  3. Band Melam OTT Release: Know Where to Watch the Telugu Romantic Musical Film
  4. Microsoft Releases New AI Models That Can Generate Images, Audio and Transcribe Text
  5. Redmi K Pad 2, New Redmi Laptops Tipped to Launch Alongside Redmi K90 Ultra
  6. Google Pixel 10 Users Can Now Play Steam Games Offline via GameNative 0.9.0
  7. Circle Unveils cirBTC Token to Expand Bitcoin’s Role in DeFi Ecosystem
  8. Honor 600 Series Could Launch Soon as Company Starts Teasing Debut of a New Phone
  9. Microsoft AI Chief Wants to Deliver State-of-the-Art AI Models by 2027: Report
  10. Infinix GT 50 Pro Leak Shows Design, Cooling, Gaming Features Ahead of Anticipated Launch
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.