Tech Forums
(#1 (permalink))
Old
Cabe's Avatar
Cabe Cabe is offline
Super Moderator
 
Posts: 51
Join Date: Jun 2007
Location: Glasgow, Scotland
Send a message via MSN to Cabe
Default Microsoft.co.uk Hacked - 07-02-2007, 01:48 PM

Looks like the official Microsoft U.K. Domain was attacked and defaced by a hacker identified as rEmOtEr. Microsoft confirmed that the hack has been successful. rEmOtEr altered a webpage in the Microsoft.co.uk domain with two images and multiple references to the kingdom of Saudi Arabia. The U.K. branch of the Redmond company managed to fix the problem, and the functionality of the website is back to normal parameters. The webpage hacked dealt with Microsoft events and can be found here. In the image below you can see how the hacker defaced the page, courtesy of Zone-H.



Roger Halbheer, chief security advisor for Microsoft in Europe, the Middle East and Africa admitted that the hack was successful and revealed that the whole event was unfortunate. According to Microsoft, no sensitive information was compromised in the attack. This is a clear indication that the hack was done for show, rather than to actually cause any harm. Another argument that supports such a scenario is the fact that rEmOtEr took time to document the hack in two separate video fragments. You will be able to watch for yourselves the live hacking via the two “remoter_vs_microsoft.avi” files.

The hack was possible mainly because of the fact that the database was allowed to return error messages explained Halbheer, as cited by InfoWorld. The attack was possible through a technique referred to as SQL injection. This fact is also confirmed by the hacker in the two videos that were made available. Via Structured Query Language injection rEmOtEr was able to gain access to the database. In the video fragments you will be able to see how easy the hacker obtains both usernames and passwords for the database. Working his way from error message to error message, rEmOtEr finally could switch from SQL queries with an unexpected form to direct instructions to the database.

Download the videos: HERE



To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
Reply With Quote
Sponsored Links
(#2 (permalink))
Old
x0r x0r is offline
Junior Member
 
Posts: 14
Join Date: Jun 2007
Location: Brussels
Default 07-04-2007, 11:37 AM

a microsoft site prone to SQL injection .. god wtf !!
Reply With Quote
(#3 (permalink))
Old
MasterSteve MasterSteve is offline
Administrator
 
Posts: 66
Join Date: Apr 2007
Default 07-05-2007, 08:08 AM

Very strange, I guess some hackers are just smarter than the Microsoft coders/programmers themselves.
Reply With Quote
(#4 (permalink))
Old
MARQO's Avatar
MARQO MARQO is offline
Super Moderator
 
Posts: 94
Join Date: Jun 2007
Location: California
Default 07-06-2007, 12:58 AM

Quote:
Originally Posted by MasterSteve View Post
Very strange, I guess some hackers are just smarter than the Microsoft coders/programmers themselves.
very true maybe microsoft should hire them



To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.


To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
Reply With Quote
(#5 (permalink))
Old
Chris_Ord Chris_Ord is offline
Junior Member
 
Posts: 12
Join Date: Jul 2007
Location: Prudhoe, England
Send a message via MSN to Chris_Ord
Default 07-06-2007, 09:12 AM

LOL.

lol lol lol.

Lmao.

That is sweet, I love the irony, microsoft, the king of error messages, gets hacked through the returned errors.

"the hack was done for show" It's rubbing it in their faces, he did it for a laugh, I bet their teams of techies maintainging the site are feeling stupid now.


The saying goes, 'Nobody is perfect, I am nobody, therefore, I am perfect.'

Also my spelling is correct, no matter what you say, I am British, we spell differently than Americans. Trust me it's right.
Reply With Quote
(#6 (permalink))
Old
g0atbutt g0atbutt is offline
Junior Member
 
Posts: 2
Join Date: Jul 2007
Default 07-10-2007, 02:22 AM

Well, if I understand it correctly, they just worked over their SQL database...


read: Whoever coded that was lazy.
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On




Powered by: vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0 RC8
vBulletin Skin developed by: vBStyles.com
Return to: TechEBlog