Feeds

Microsoft Web site hacked in Kiwiland

And Chanel defaced in the name of 'TheRegister'

  • alert
  • submit to reddit

Choosing a cloud hosting partner with confidence

Microsoft's Web site in New Zealand was defaced overnight by hackers who sprayed the site with taunts about the software giants lack of security.

The site was still defaced at lunchtime UK time; instead of information about the software giants' products it was changed to contain a rather different message from the attacker, Prime Suspectz.

He wrote: "Another Micro$oft was hacked? !!Yes!! 'The vulnerability is completely teorical'!! I don't think so!! Security wuz broke'n!"

A copy of the message posted can be seen in full here.

The incident is the latest in a string of embarrassing security gaffes to affect the software giant. Last year, hackers broke into the corporate giant's network and it is believed they were able to see code under development. Further, though less serious attacks against its corporate system followed.

Microsoft's international Web sites, which are often hosted by local firms, also come under attack and the latest incident followed the same pattern as a successful attack in Slovenian last December.

Paul Rogers, a security consultant at MIS Corporate Defence, said: "Hackers defaced the New Zealand site by breaking into an NT using one of a number of holes in IIS. In this case it looks they used the Unicode exploit, which has been behind a flurry of break-ins to sites running IIS web servers that we have seen recently."

Other attacks by Prime Suspectz in the last 24 hours included an attack on www.chryslerjeep.co.uk, which defaced that site with the same message sprayed on Microsoft's New Zealand Web site.

"Chrysler are updating its Web site via SQL Server using remote management tools," said Rogers, who added that this was an insecure method which meant "they could be broken into again".

In a separate attack, Chanel's Web site was defaced by an attacker calling himself 'TheRegister', which we are somewhat concerned may bring our name into repute. After the defacement, a protest about the fur trade which can be seen here, the site was moved from an NT server to a Solaris box running Netscape Enterprise Server.

Whether this remains a temporary move or not is unclear and is obviously not an option for Microsoft New Zealand, which will have to devise other ways to shore up the site's leaky security. ®

Related Stories

MS hacked! Russian mafia swipes WinME source?
Microsoft Hack: Warned of weakness three months earlier
Microsoft hacked in the Balkans
Mass hack takes out govt sites
Hackers, Windows NT and the FBI
How you hack into Microsoft: a step by step guide

Top 5 reasons to deploy VMware with Tegile

Whitepapers

Why and how to choose the right cloud vendor
The benefits of cloud-based storage in your processes. Eliminate onsite, disk-based backup and archiving in favor of cloud-based data protection.
Getting started with customer-focused identity management
Learn why identity is a fundamental requirement to digital growth, and how without it there is no way to identify and engage customers in a meaningful way.
Go beyond APM with real-time IT operations analytics
How IT operations teams can harness the wealth of wire data already flowing through their environment for real-time operational intelligence.
Why CIOs should rethink endpoint data protection in the age of mobility
Assessing trends in data protection, specifically with respect to mobile devices, BYOD, and remote employees.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.