Hackers hit Network Solutions customers
IDG News Service - Hackers have managed to deface several hundred Web sites hosted by Network Solutions, the company said Tuesday.
In a blog posting, the Internet service provider described the incident as a "limited attack on websites hosted on Network Solutions Unix servers." Several servers were hit and "intruders were able to get through by using a file inclusion technique," the blog post said.
A Network Solutions representative could add little to the blog's description of the attack, but remote file inclusion attacks are a relatively common way of exploiting buggy Web server programming in order to run unauthorized content on the server. "Our preliminary investigation indicates that the source of entry was through a single site," said spokeswoman Susan Wade in an e-mail.
Network Solutions customer Lucina Mastro learned Sunday that someone had crawled the folders on the Web site she maintains and replaced all of the index.html and main.html files with new files claiming that the defacement was "For Palestine."
Mastro, a volunteer Web administrator with St Anne of the Sunset Catholic Church in San Francisco, replaced the files from backup. That seemed to fix the problem, she said.
Harry Brooks was not so lucky. He learned that one of his clients had been hacked with a similar defacement Monday, and restored the site from backup, only to learn that it had been defaced anew on Tuesday, apparently by someone else.
The second defacement made no mention of Palestine, but said simply "Server Is RooT!"
Brooks, president and CEO of Search First Internet Marketing in Gainesville, Virginia, was upset with the defacement. "You can't have 15 simple static HTML pages hosted in a shared hosting environment without some maniac getting in," he said. "Clearly there is a vulnerability in their shared hosting environment otherwise this wouldn't be happening."


- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Obtaining Fortune 500 Security without Busting your Budget
- Network Security and Compliance on a Budget Made Simple
- Controlling the Cost of File Transfers
- This solution brief explains why something as seemingly simple and straightforward as a file transfer task turns into such a costly operation. It...
- Practice Management: Double Billing Rate and Improve Patient Services
- Would you like to double your billing rate and achieve faster payment for services?
Download this customer success story to see how One Health... - Mission Critical Data Explosion and Customer Case Study
- Would you like to double your tier 1 storage capacity while simultaneously reducing your storage footprint?
Download this customer success story to see how... - Protecting Against Database Attacks and Insider Threats: Top 5 Scenarios
- Read this new eBook to learn the top five scenarios and essential best practices for preventing database attacks and insider threats. All Network Security White Papers
- Distributed Database Security with Real-time Monitoring
- View this demo and learn how IBM InfoSphere Guardium database activity monitoring can help protect your sensitive data in distributed DBMS environments with...
- InfoSphere Warehouse Packs Demo
- These flash modules make warehousing more tangible and relevant to business users through detailed explanations of the InfoSphere Warehouse Packs.
- Delivery Management -- Extending Lifecycle Management
- Date: Wednesday, June 20, 2012, 1:00 PM EDT
Siloed organizations continue doing the wrong things and doing things wrong, leading to increased costs,... - Leverage automation today to reduce IT complexity
- Date: Tuesday, June 5, 2012, 2:00 PM EDT
Whether your B2B complexity is caused by multiple technologies due to M&A, business or application specific... - Redefine Expectations in the Data Center
- Need to do more with less? Watch this video to learn how HP ProLiant Gen8 servers can help your business deploy servers three... All Network Security Webcasts