Ads by TechWords

See your link here
Receive the latest technology news and information.
Microsoft
Computerworld Daily News (First Look and Wrap-Up)
Computerworld Blogs Newsletter
The Weekly Top 10
Cloud Computing
View all newsletters




Privacy Policy
 

Dutch hacker breaks into Microsoft Web server again

November 9, 2000 12:00 PM ET

Industry Standard - The Dutch hacker who penetrated one of Microsoft Corp.'s Web servers last Friday has done it again, marking the third time in less than two weeks that the software vendor has had to confirm that its corporate network was successfully breached by outsiders.
A Microsoft Web server that redirects incoming traffic to another system was compromised Tuesday in much the same way it was last week. In the first incident, the hacker, whose alias is "Dimitri," took advantage of a known security hole in Microsoft's Internet Information Server (IIS) that the company had failed to plug even though it recently urged users to install an already-available patch (see story).
On Tuesday, Dimitri took credit for another incursion in which the Web server was defaced with a text file that read, "Patching your systems is very hard, huh?" Dimitri also complimented pop singer Britney Spears, who he claims is his idol, for a concert she performed last Saturday in the Netherlands.
Microsoft spokesman Adam Sohn confirmed the latest incident took place, but he said the hacked pages on the server weren't visible to regular users of the company's Web site. Only people privy to the specific Web address of the pages that Dimitri created could view them, Sohn said, adding that the hacker disseminated the URL to reporters and other hackers.
Microsoft's systems administrators "just don't bother securing their networks," Dimitri said when asked why he had broken into the Web server for a second time. "The only thing they did on Friday was remove the file I left [then]," the 19-year-old student added. "Basically, they lied about applying patches."
However, Sohn said the software giant remains unsure of exactly how the second hack was accomplished. The patch that's supposed to plug the IIS security hole was indeed installed after the initial incident last week, he added. Sohn couldn't say why the patch wasn't applied in the first place but claimed that the oversight was "certainly the exception, not the rule."
Sohn also downplayed the impact of Dimitri's hacking exploits, saying the victimized Web server is in semiretirement and is only being used to redirect traffic to a second system that stores information about upcoming Microsoft events. "It's an unfortunate and annoying occurrence," Sohn said.
But the two hacks by Dimitri came close on the heels of Microsoft's disclosure that it had been hit by a more serious month-long intrusion in which an attacker was able to view the source code for an unspecified future product (see story). That incident was


Reprinted with permission from

For more news on the Internet Economy, visit The Industry Standard.
Story Copyright 2009 The Industry Standard. All rights reserved.

Jump to comments

Windows

Additional Resources

Xerox
By using solid ink technology only from Xerox, you could save up to 65% by printing color for the cost of black and white. Enter for a chance to WIN a PhaserTM 8860 network color printer!
Microsoft
Save time and mitigate security risk. Deploy it now.
Sybase
In this white paper, IDC analyzes the role of next-generation mobile enterprise platforms as organizations seek a more strategic deployment of mobile solutions.

Learn the important issues you must consider before starting your next mobility initiative. Get your mobility white paper from IDC now, compliments of Sybase.

White Papers & Webcasts

Forrester Consulting - Optimizing Users and Applications in a Mobile World
Learn how to successfully deploy a WAN optimization solution that is specifically tuned for a mobile environment!  

Faster, Cheaper and Easier to Maintain
Can you afford not to upgrade your servers to today's advanced, energy-efficient technologies?  

Effectively Implementing Datacenter Automation
Effectively select and deploy the best datacenter automation solution today!

Aligning IT to Business: The Rising Importance of Application Delivery Networks
Application Delivery Networking (ADN) will play a vital role in helping enterprises incorporate strategic technologies to achieve business initiatives.

Mitigate Risk, Lower Costs and Improve Network Efficiency
Create a stable IP network that not only meets today's challenges, but is flexible enough to also meet future demands.