Feeds

160+ UK Web sites defaced over petrol tax

Dumb admins using default passwords with SQL

  • alert
  • submit to reddit

Choosing a cloud hosting partner with confidence

A protester identifying himself as 'Herbless' defaced 168 corporate Web sites Friday with a message urging public support for demonstrators standing up against high fuel taxes in the UK.

"Our government has now started to spread FUD (Fear, Uncertainty, Doubt) propaganda through the media in the hope that they can dispel puplic [sic] support for the protest that is taking place all around Britain," Herbless said.

He notes that 72 per cent of the price of petrol in the UK is tax, that production costs are one of the cheapest in Europe, though retail prices are the highest in Europe.

He also takes issue with media reports and government statements painting the protests as obstructive. "Despite the fact that there are no blockades, tankers will not leave the distribution centres. This has led to wide-spread speculation that the policy not to deliver petrol is in fact being handed down from the petrol companies," he said.

The message closes with an appeal for public support of those on the front lines. "If you live near a picket line, go and give your support. Applaud the lorry drivers. Make cups of tea and sandwiches for the picketers. Write to your MP pledging your support," he urged.

The final note, "Admin: Learn how to change passwords. Hint: SQL server doesn't just do SQL," suggests that Herbless probably scanned a large number of sites for installations of the MS SQL server with default passwords in place. Administrators are supposed to change the password before going live, but apparently there are a vast number maintaining commercial sites who can't understand the documentation. Perhaps reading tests ought to become a standard part of the recruitment process.

Herbless easily exploited such sites as specsavers.com, jobs.co.uk, itforhire.co.uk, travelfocus.co.uk, brandimage.co.uk, and many others in this attack. He defaced nine government Web sites last month and the Legoland.co.uk site last week. ®

Security for virtualized datacentres

More from The Register

next story
WHY did Sunday Mirror stoop to slurping selfies for smut sting?
Tabloid splashes, MP resigns - but there's a BIG copyright issue here
Spies, avert eyes! Tim Berners-Lee demands a UK digital bill of rights
Lobbies tetchy MPs 'to end indiscriminate online surveillance'
How the FLAC do I tell MP3s from lossless audio?
Can you hear the difference? Can anyone?
Google hits back at 'Dear Rupert' over search dominance claims
Choc Factory sniffs: 'We're not pirate-lovers - also, you publish The Sun'
While you queued for an iPhone 6, Apple's Cook sold shares worth $35m
Right before the stock took a 3.8% dive amid bent and broken mobe drama
Inequality increasing? BOLLOCKS! You heard me: 'Screw the 1%'
There's morality and then there's economics ...
prev story

Whitepapers

Providing a secure and efficient Helpdesk
A single remote control platform for user support is be key to providing an efficient helpdesk. Retain full control over the way in which screen and keystroke data is transmitted.
Intelligent flash storage arrays
Tegile Intelligent Storage Arrays with IntelliFlash helps IT boost storage utilization and effciency while delivering unmatched storage savings and performance.
Beginner's guide to SSL certificates
De-mystify the technology involved and give you the information you need to make the best decision when considering your online security options.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.
Secure remote control for conventional and virtual desktops
Balancing user privacy and privileged access, in accordance with compliance frameworks and legislation. Evaluating any potential remote control choice.