Feeds

Microsoft hacked again

Known security hole gives access to download software

  • alert
  • submit to reddit

Secure remote control for conventional and virtual desktops

Just one week after Microsoft admitted to a major breach of its security, another hacker by the name of Dimitri claims to have gained access to several of its Web servers.

Using a known security hole in M$' Internet Information Server software - which should have been fixed with its own patch - Dimitri hacked into the servers and uploaded a text file called Hack the Planet. He claims to have been able to alter files on Microsoft's download site and, if he so wished, add Trojan horses to software. The implications are obvious.

On top of this, Dimitri claimed to have possession of an encrypted file containing administrative user names and passwords. He could decode it, he said, but wouldn't. Other interesting info: Microsoft's server domain is called Houston (and now it has a problem) and all the Web servers are set up in the same way. Tut tut.

Microsoft has admitted that at least one server has been compromised and that access was gained through a known security hole. The patch hadn't been applied to the server and now it is rushing around checking all the others. However, the Redmond giant claimed, this was not an important server and was being used only to redirect traffic to more up-to-date content.

Dimitri used the Unicode bug to get access into the systems. Microsoft's first patch for the hole was produced in August and was made public last month. The failure of M$ to install its own patches was described as "extremely sloppy" by the hacker. You're not wrong there. ®

Related Stories

Microsoft Hack: Warned of weakness three months earlier
Microsoft's choice: Law or Order
Register story inspire FBI raid on student
How you hack into Microsoft: A step by step guide
Redmond strives to cram great MS hack back in box
MS hacked! Russian mafia swipes WinME source?

Providing a secure and efficient Helpdesk

More from The Register

next story
Microsoft on the Threshold of a new name for Windows next week
Rebranded OS reportedly set to be flung open by Redmond
Business is back, baby! Hasta la VISTA, Win 8... Oh, yeah, Windows 9
Forget touchscreen millennials, Microsoft goes for mouse crowd
SMASH the Bash bug! Apple and Red Hat scramble for patch batches
'Applying multiple security updates is extremely difficult'
Apple: SO sorry for the iOS 8.0.1 UPDATE BUNGLE HORROR
Apple kills 'upgrade'. Hey, Microsoft. You sure you want to be like these guys?
ARM gives Internet of Things a piece of its mind – the Cortex-M7
32-bit core packs some DSP for VIP IoT CPU LOL
Lotus Notes inventor Ozzie invents app to talk to people on your phone
Imagine that. Startup floats with voice collab app for Win iPhone
prev story

Whitepapers

A strategic approach to identity relationship management
ForgeRock commissioned Forrester to evaluate companies’ IAM practices and requirements when it comes to customer-facing scenarios versus employee-facing ones.
Storage capacity and performance optimization at Mizuno USA
Mizuno USA turn to Tegile storage technology to solve both their SAN and backup issues.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Beginner's guide to SSL certificates
De-mystify the technology involved and give you the information you need to make the best decision when considering your online security options.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.