Dailydave mailing list archives

coolio microsoft hack


From: Dave Aitel <dave () immunitysec com>
Date: Mon, 24 May 2004 20:13:59 -0400

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

http://zone-h.org/en/news/read/id=4251/

*
Siegfried and SyS64738, www.zone-h.org admins <mailto:admin () zone-h org>
05/25/2004
* A Portuguese group dubbed "Outlaw group" has defaced the Microsoft.com
web site, the hacked page (www.microsoft.com/mspress/uk/) isn't
available anymore since 9:00pm GMT monday 24.

The defacers modified the title and introduction of the Microsoft
Press section to write "Owned OutLaw Group by Pharoeste e Wolfblack"
in order to prove that they compromised it. They found the
administration page and performed a SQL injection attack, allowing
them to manage the content of the section.

Here are the mirror and a screenshot of the defacement:

http://www.zone-h.org/defacements/mirror/id=1246363/

http://www.zone-h.org/files/77/microsoft.com.gif

However, the defacement seems contained in google's cache since a long
time, but somehow Microsoft took off the page only when it got
notified to our mirror robots. As if Microsoft was constantly
monitoring our "on hold" list as many companies are doing. We remind
you about the possibility to subscribe our early warning list to be
promptly notified about intrusions into your server (it's a FREE
service!) http://www.zone-h.org/en/warnlist

http://www.google.com/search?q=cache:R7iYePwUPrsJ:www.microsoft.com/mspress/uk/

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.1 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iD8DBQFAso/HzOrqAtg8JS8RAp2bAJ9cnD3gQqGpafsIu2giTi1LHOmQcgCg0t6L
LSHvqbKGPYCYarg6T9j7xLg=
=h0ex
-----END PGP SIGNATURE-----

_______________________________________________
Dailydave mailing list
Dailydave () lists immunitysec com
http://www.immunitysec.com/mailman/listinfo/dailydave


Current thread: