Feeds

MailOnline pulls recipe site after innocent young cookbook DEFILED

Hackers terrorise readers with, er, mildly annoying song. They're foreign, you know

SANS - Survey on application security programs

The Mail Online has pulled its recipes website after it was vandalised by Libyan cyber-hijackers.

The UK mid-market tabloid's content partner MyDish was defaced by "The Great Team" hacking crew on Monday in a hack recorded by defacement archive Zone-h here (warning: link auto plays mildly annoying music). The defacement is also recorded by the Wayback Machine at archive.org here.

The compromised site might easily have been used as a platform to serve up malicious code but it appears the hackers involved confined themselves to bragging about their conquest. The defacement message omits any political message and is characterised by a screen-cap of the benign Professor Dumbledore from the Harry Potter movies with the caption "I own this shit". The Great Team are a prolific defacement crew who have claimed the scalps of more than 2,100 websites over the last two years.

The MailOnline responded by updating the DNS so that recipes.dailymail.co.uk pointed to its own server rather than that of MyDish, through use of a server that handles redirects. The papers also removed the link to the recipe subdomain from its Health news tab - it was there earlier in December, but has since vanished. The recipe site had been previously advertised as “powered by MyDish”.

El Reg was unable to find any evidence of the other subdomains being attacked. It appears that the compromise was restricted to recipes.dailymail.co.uk.

At the time of the hack, recipes.dailymail.co.uk resolved to the IP address 78.143.240.61, which is owned by web-hosting company Dark Group (dg.co.uk) and is also the same IP used to serve mydish.co.uk.

The site was run from IIS 6.0 web server software from servers running Windows 2003, according to Zone-h.

We invited both MyDish and the Daily Mail Group to comment on the security snafu on Friday morning but are yet to hear back from either party.

This isn’t the first time recipes.dailymail.co.uk has been hacked. Last year, when it appears to have been a MyDish site served from Dark Group, it was defaced by the notorious Team Poison crew with a more political message (recorded by Zone-h here) criticising the Mail's stance on issues such as immigration. ®

Bootnotes

Thanks to Reg reader Wyn for the tip.

We did hear back from Dark Group, however, who had this to say:

Dark Group provides this client with unmanaged dedicated and virtual servers, where we just look after the hardware, power and network. Our client has their own in-house technical team who manage the operating system and software.

Combat fraud and increase customer satisfaction

More from The Register

next story
Parent gabfest Mumsnet hit by SSL bug: My heart bleeds, grins hacker
Natter-board tells middle-class Britain to purée its passwords
Samsung Galaxy S5 fingerprint scanner hacked in just 4 DAYS
Sammy's newbie cooked slower than iPhone, also costs more to build
Obama allows NSA to exploit 0-days: report
If the spooks say they need it, they get it
Web data BLEEDOUT: Users to feel the pain as Heartbleed bug revealed
Vendors and ISPs have work to do updating firmware - if it's possible to fix this
Snowden-inspired crypto-email service Lavaboom launches
German service pays tribute to Lavabit
One year on: diplomatic fail as Chinese APT gangs get back to work
Mandiant says past 12 months shows Beijing won't call off its hackers
Call of Duty 'fragged using OpenSSL's Heartbleed exploit'
So it begins ... or maybe not, says one analyst
NSA denies it knew about and USED Heartbleed encryption flaw for TWO YEARS
Agency forgets it exists to protect communications, not just spy on them
prev story

Whitepapers

Designing a defence for mobile apps
In this whitepaper learn the various considerations for defending mobile applications; from the mobile application architecture itself to the myriad testing technologies needed to properly assess mobile applications risk.
3 Big data security analytics techniques
Applying these Big Data security analytics techniques can help you make your business safer by detecting attacks early, before significant damage is done.
Five 3D headsets to be won!
We were so impressed by the Durovis Dive headset we’ve asked the company to give some away to Reg readers.
The benefits of software based PBX
Why you should break free from your proprietary PBX and how to leverage your existing server hardware.
Securing web applications made simple and scalable
In this whitepaper learn how automated security testing can provide a simple and scalable way to protect your web applications.