Top Stories
|
Saudi hackers scalp MS UK2 Jul 2007 15:53 Defacement video tutorial pulled after attackSaudi hackers manged to deface a page on Microsoft's UK web site last week, recording the techniques they used in an online video. The software giant's sites are periodically hit by acts of digital graffiti. In this case, however, the defacement gang unusually decided to document its attack. A video illustrating SQL Injection flaws affecting www.microsoft.co.uk, used to insert extra HTML code that formed the basis of the attack, was posted online. Details of how this might be done would be useful fodder for hackers so it shouldn't come as any particular surprise to learn that the video (posted on unbase.com) was pulled over the weekend. The defaced page (www.microsoft.co.uk/events/net/eventdetail.aspx?eventid=8399) is also currently unavailable but defacement archive Zone-h has recorded the attack for posterity here.
According to Zone-h, microsoft.co.uk's externally hosted website remains potentially vulnerable to Cross Site Scripting and SQL injection attacks. It bases this conclusion on debug errors generated by scripts on the site. Microsoft.co.uk is run using IIS6 on a series on Windows 2003 servers, according to Netcraft. ® 12 comments posted — Comment period finished .com runs on 2008Posted: 16:13 2nd July 2007 SurprisePosted: 16:48 2nd July 2007 And they wonder why they can't keep it secure?Posted: 18:22 2nd July 2007 deny by defaultPosted: 19:43 2nd July 2007 Never let facts get in the way of a good MS bashing.Posted: 00:00 3rd July 2007
Track this type of story as a custom Atom/RSS feed or by email. Related storiesScotland Yard careers website defaced (25 February 2008)
|
Breaking Hardware News
Intel has been ordered to hand over secret employee interviews from an internal investigation looking into documents and e-mails that went missing during its antitrust trial with AMD.
Newsletter |