Feeds

Alldas defaced!

Occupational Hazard

  • alert
  • submit to reddit

Choosing a cloud hosting partner with confidence

Alldas.de, the defacement archive, was... defaced yesterday.

"Around 15:44 the database for the News section had a new topic, simply stating that "Alldas.de got cracked". After ~1 min. the database was cleaned and nothing else on the page was affected. How could this have happened?," The site said on its news page.

Alldas figured out what the intruder had done by poring over the log files - its analysis was confirmed by the cracker, who emailed: "I had no intention to clear your database or to root your server. No attempt
to do this has been made." Alldas says its log files show different.

The cracker suckered Alldas' scripts to mirror another Web site. This site "was used to execute commands on the server (as an unprivileged user)".

No higher access levels were reached - the cracker was unable to read mail or to download or install bindshells.

"The actual penetration wasn't really big, though it is kinda embarrassing to get 'defaced' as a defacement mirror," Fredrik of Alldas said on the site. "We regret it that the attacker didn't inform us about the bug and choose to deface the site with all the consequences that go hand in hand with it." ®

Choosing a cloud hosting partner with confidence

More from The Register

next story
Facebook pays INFINITELY MORE UK corp tax than in 2012
Thanks for the £3k, Zuck. Doh! you're IN CREDIT. Guess not
Facebook, Apple: LADIES! Why not FREEZE your EGGS? It's on the company!
No biological clockwatching when you work in Silicon Valley
Yes, yes, Steve Jobs. Look what I'VE done for you lately – Tim Cook
New iPhone biz baron points to Apple's (his) greatest successes
Happiness economics is bollocks. Oh, UK.gov just adopted it? Er ...
Opportunity doesn't knock; it costs us instead
Ex-US Navy fighter pilot MIT prof: Drones beat humans - I should know
'Missy' Cummings on UAVs, smartcars and dying from boredom
Sysadmin with EBOLA? Gartner's issued advice to debug your biz
Start hoarding cleaning supplies, analyst firm says, and assume your team will scatter
Edward who? GCHQ boss dodges Snowden topic during last speech
UK spies would rather 'walk' than do 'mass surveillance'
prev story

Whitepapers

Cloud and hybrid-cloud data protection for VMware
Learn how quick and easy it is to configure backups and perform restores for VMware environments.
A strategic approach to identity relationship management
ForgeRock commissioned Forrester to evaluate companies’ IAM practices and requirements when it comes to customer-facing scenarios versus employee-facing ones.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Three 1TB solid state scorchers up for grabs
Big SSDs can be expensive but think big and think free because you could be the lucky winner of one of three 1TB Samsung SSD 840 EVO drives that we’re giving away worth over £300 apiece.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.