Dutch hacker breaks into Microsoft Web server again
Industry Standard - The Dutch hacker who penetrated one of Microsoft Corp.'s Web servers last Friday has done it again, marking the third time in less than two weeks that the software vendor has had to confirm that its corporate network was successfully breached by outsiders.
A Microsoft Web server that redirects incoming traffic to another system was compromised Tuesday in much the same way it was last week. In the first incident, the hacker, whose alias is "Dimitri," took advantage of a known security hole in Microsoft's Internet Information Server (IIS) that the company had failed to plug even though it recently urged users to install an already-available patch (see story).
On Tuesday, Dimitri took credit for another incursion in which the Web server was defaced with a text file that read, "Patching your systems is very hard, huh?" Dimitri also complimented pop singer Britney Spears, who he claims is his idol, for a concert she performed last Saturday in the Netherlands.
Microsoft spokesman Adam Sohn confirmed the latest incident took place, but he said the hacked pages on the server weren't visible to regular users of the company's Web site. Only people privy to the specific Web address of the pages that Dimitri created could view them, Sohn said, adding that the hacker disseminated the URL to reporters and other hackers.
Microsoft's systems administrators "just don't bother securing their networks," Dimitri said when asked why he had broken into the Web server for a second time. "The only thing they did on Friday was remove the file I left [then]," the 19-year-old student added. "Basically, they lied about applying patches."
However, Sohn said the software giant remains unsure of exactly how the second hack was accomplished. The patch that's supposed to plug the IIS security hole was indeed installed after the initial incident last week, he added. Sohn couldn't say why the patch wasn't applied in the first place but claimed that the oversight was "certainly the exception, not the rule."
Sohn also downplayed the impact of Dimitri's hacking exploits, saying the victimized Web server is in semiretirement and is only being used to redirect traffic to a second system that stores information about upcoming Microsoft events. "It's an unfortunate and annoying occurrence," Sohn said.
But the two hacks by Dimitri came close on the heels of Microsoft's disclosure that it had been hit by a more serious month-long intrusion in which an attacker was able to view the source code for an unspecified future product (see story). That incident was



- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- VMware View Optimization Guide for Windows 7
- This document provides guidelines for configuring a standard Windows 7 image to be used within a VMware View™ environment, providing administrators with the...
- Microsoft Volume Licensing Comparison - Small/Med. Business
- This quick-reference document lets small and medium organizations (i.e. those with five or more devices) to easily compare the available Microsoft Volume Licensing...
- Microsoft Volume Licensing Comparison - Enterprise
- With this quick-reference document, you can easily compare the available Microsoft Volume Licensing programs for enterprise organizations with 250+ devices, and tailor a...
- Microsoft Open Value Program Guide
- In this overview, see how Microsoft Open Value provides a flexible, affordable way for small to midsize organizations (i.e. those with five or...
- HP Software Licensing & Management Solutions for Microsoft
- See how HP Software Licensing & Management Solutions (SLMS) can help you identify the best Microsoft licensing program for your needs, get the... All Windows White Papers
- Optimizing Networks for the Cloud
- Join guest speaker, Rohit Mehra, IDC Director of Enterprise Communications Infrastructure, to explore current trends, discuss best practices for optimizing Data Center and...
- Apps QuickStart Series Part 2: Designing and Deploying SQL Server on VMware vSphere
- Download this webcast to learn about the design considerations for virtualizing SQL workloads, performance and scalability information and high-availability options, as well as...
- Apps QuickStart Series Part 1: Designing and Deploying Exchange 2010 on VMware vSphere
- Download this webcast to learn the virtual hardware design considerations for Exchange 2010, deployment using the building block approach, options for high-availability and...
- Customer Spotlight: How IPC The Hospitalist Company Implemented Oracle on VMware
- Have you been looking to hear about customer's experiences with the new VMware vCenter Site Recovery Manager product? View this webcast to learn...
- Virtualize Business-Critical Applications with Confidence
- Virtualizing business-critical applications has become a key focus for organizations as they move along their virtualization journey. With the launch of VMware vSphere®... All Windows Webcasts