Feeds

Microsoft Web site hacked in Kiwiland

And Chanel defaced in the name of 'TheRegister'

  • alert
  • submit to reddit

Application security programs and practises

Microsoft's Web site in New Zealand was defaced overnight by hackers who sprayed the site with taunts about the software giants lack of security.

The site was still defaced at lunchtime UK time; instead of information about the software giants' products it was changed to contain a rather different message from the attacker, Prime Suspectz.

He wrote: "Another Micro$oft was hacked? !!Yes!! 'The vulnerability is completely teorical'!! I don't think so!! Security wuz broke'n!"

A copy of the message posted can be seen in full here.

The incident is the latest in a string of embarrassing security gaffes to affect the software giant. Last year, hackers broke into the corporate giant's network and it is believed they were able to see code under development. Further, though less serious attacks against its corporate system followed.

Microsoft's international Web sites, which are often hosted by local firms, also come under attack and the latest incident followed the same pattern as a successful attack in Slovenian last December.

Paul Rogers, a security consultant at MIS Corporate Defence, said: "Hackers defaced the New Zealand site by breaking into an NT using one of a number of holes in IIS. In this case it looks they used the Unicode exploit, which has been behind a flurry of break-ins to sites running IIS web servers that we have seen recently."

Other attacks by Prime Suspectz in the last 24 hours included an attack on www.chryslerjeep.co.uk, which defaced that site with the same message sprayed on Microsoft's New Zealand Web site.

"Chrysler are updating its Web site via SQL Server using remote management tools," said Rogers, who added that this was an insecure method which meant "they could be broken into again".

In a separate attack, Chanel's Web site was defaced by an attacker calling himself 'TheRegister', which we are somewhat concerned may bring our name into repute. After the defacement, a protest about the fur trade which can be seen here, the site was moved from an NT server to a Solaris box running Netscape Enterprise Server.

Whether this remains a temporary move or not is unclear and is obviously not an option for Microsoft New Zealand, which will have to devise other ways to shore up the site's leaky security. ®

Related Stories

MS hacked! Russian mafia swipes WinME source?
Microsoft Hack: Warned of weakness three months earlier
Microsoft hacked in the Balkans
Mass hack takes out govt sites
Hackers, Windows NT and the FBI
How you hack into Microsoft: a step by step guide

The Power of One eBook: Top reasons to choose HP BladeSystem

More from The Register

next story
BBC goes offline in MASSIVE COCKUP: Stephen Fry partly muzzled
Auntie tight-lipped as major outage rolls on
There's NOTHING on TV in Europe – American video DOMINATES
Even France's mega subsidies don't stop US content onslaught
You! Pirate! Stop pirating, or we shall admonish you politely. Repeatedly, if necessary
And we shall go about telling people you smell. No, not really
Airbus promises Wi-Fi – yay – and 3D movies (meh) in new A330
If the person in front reclines their seat, this could get interesting
UK Parliament rubber-stamps EMERGENCY data grab 'n' keep bill
Just 49 MPs oppose Drip's rushed timetable
Want to beat Verizon's slow Netflix? Get a VPN
Exec finds stream speed climbs when smuggled out
Samsung threatens to cut ties with supplier over child labour allegations
Vows to uphold 'zero tolerance' policy on underage workers
Dude, you're getting a Dell – with BITCOIN: IT giant slurps cryptocash
1. Buy PC with Bitcoin. 2. Mine more coins. 3. Goto step 1
prev story

Whitepapers

Reducing security risks from open source software
Follow a few strategies and your organization can gain the full benefits of open source and the cloud without compromising the security of your applications.
Consolidation: The Foundation for IT Business Transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.
Application security programs and practises
Follow a few strategies and your organization can gain the full benefits of open source and the cloud without compromising the security of your applications.
Boost IT visibility and business value
How building a great service catalog relieves pressure points and demonstrates the value of IT service management.
Consolidation: the foundation for IT and business transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.