Screen Shot 2013-07-22 at 9.34.44 AM

Security researcher Ibrahim Balic is claiming to have reported a Developer Center security hole just hours before the portal went down.

After reviewing the information and speaking with Balic, it seems as if Apple’s website could be breached through a simple unescaped injection attack. We haven’t seen the script ourselves, so this isn’t completely confirmed.

Balic was able to access first and last names, Apple IDs/email addresses, and user IDs. From the information he showed in a YouTube video (update: the video has now been taken down) and what he described to me in an email, the leak does not show any other information.

In an email to me, Balic also states that the exposed Apple IDs belong to developers as well as regular users. His YouTube video description stated he was able glean over 100,000 users’ information, but is planning on deleting all of the information.

He is insistent in stating he did this for security research purposes and does not plan to use the information in any malicious manner.

Leave a Reply

Please log in using one of these methods to post your comment: Logo

You are commenting using your account. Log Out / Change )

Twitter picture

You are commenting using your Twitter account. Log Out / Change )

Facebook photo

You are commenting using your Facebook account. Log Out / Change )

Google+ photo

You are commenting using your Google+ account. Log Out / Change )

Connecting to %s