Feeds

Microsoft India web store 'hacked by Chinese group'

Evil Shadow Team pounces, claims it uncovered passwords

Combat fraud and increase customer satisfaction

Microsoft appears to have had its Indian web store broken into and user login credentials stolen by Chinese hackers.

Tech site WP Sauce reported on Sunday that the group, which goes by the name Evil Shadow Team, managed to deface the web site, posting an image of a V for Vendetta mask and the message: “Unsafe system will be baptized.”

At the time of writing the site had been taken offline, presumably while Quasar Media, the third-party digital media firm Microsoft employed to run it, figures out what went wrong.

“The Microsoft Store India is currently unavailable. Microsoft is working to restore access as quickly as possible. We apologise for any inconvenience this may have caused,” the holding page message reads.

According to multiple reports, punters' logins and passwords were also stolen by the hackers, a situation made significantly worse because Quasar apparently made the schoolboy error of storing them in plain text.

Not much is known about Evil Shadow Team, although a link posted on the defaced Microsoft Store page on Sunday takes the user to the group’s blog, written in Chinese and titled “7z1’s blog”.

Users of Microsoft Store in India have been advised to change their passwords on the site as soon as it comes back online, and to change their credentials on any other sites if they used the same ones across multiple online accounts.

Microsoft has yet to respond to a request for comment. ®

SANS - Survey on application security programs

Whitepapers

Mobile application security study
Download this report to see the alarming realities regarding the sheer number of applications vulnerable to attack, as well as the most common and easily addressable vulnerability errors.
3 Big data security analytics techniques
Applying these Big Data security analytics techniques can help you make your business safer by detecting attacks early, before significant damage is done.
The benefits of software based PBX
Why you should break free from your proprietary PBX and how to leverage your existing server hardware.
Securing web applications made simple and scalable
In this whitepaper learn how automated security testing can provide a simple and scalable way to protect your web applications.
Combat fraud and increase customer satisfaction
Based on their experience using HP ArcSight Enterprise Security Manager for IT security operations, Finansbank moved to HP ArcSight ESM for fraud management.