Ads by TechWords

See your link here
Subscribe to our e-mail newsletters
For more info on a specific newsletter, click the title. Details will be displayed in a new window.
Microsoft
Computerworld Daily News (First Look and Wrap-Up)
Computerworld Blogs Newsletter
The Weekly Top 10
More E-Mail Newsletters 
 

Dutch hacker breaks into Microsoft Web server again

November 9, 2000 12:00 PM ET

Industry Standard - The Dutch hacker who penetrated one of Microsoft Corp.'s Web servers last Friday has done it again, marking the third time in less than two weeks that the software vendor has had to confirm that its corporate network was successfully breached by outsiders.
A Microsoft Web server that redirects incoming traffic to another system was compromised Tuesday in much the same way it was last week. In the first incident, the hacker, whose alias is "Dimitri," took advantage of a known security hole in Microsoft's Internet Information Server (IIS) that the company had failed to plug even though it recently urged users to install an already-available patch (see story).
On Tuesday, Dimitri took credit for another incursion in which the Web server was defaced with a text file that read, "Patching your systems is very hard, huh?" Dimitri also complimented pop singer Britney Spears, who he claims is his idol, for a concert she performed last Saturday in the Netherlands.
Microsoft spokesman Adam Sohn confirmed the latest incident took place, but he said the hacked pages on the server weren't visible to regular users of the company's Web site. Only people privy to the specific Web address of the pages that Dimitri created could view them, Sohn said, adding that the hacker disseminated the URL to reporters and other hackers.
Microsoft's systems administrators "just don't bother securing their networks," Dimitri said when asked why he had broken into the Web server for a second time. "The only thing they did on Friday was remove the file I left [then]," the 19-year-old student added. "Basically, they lied about applying patches."
However, Sohn said the software giant remains unsure of exactly how the second hack was accomplished. The patch that's supposed to plug the IIS security hole was indeed installed after the initial incident last week, he added. Sohn couldn't say why the patch wasn't applied in the first place but claimed that the oversight was "certainly the exception, not the rule."
Sohn also downplayed the impact of Dimitri's hacking exploits, saying the victimized Web server is in semiretirement and is only being used to redirect traffic to a second system that stores information about upcoming Microsoft events. "It's an unfortunate and annoying occurrence," Sohn said.
But the two hacks by Dimitri came close on the heels of Microsoft's disclosure that it had been hit by a more serious month-long intrusion in which an attacker was able to view the source code for an unspecified future product (see story). That incident was


Reprinted with permission from

For more news on the Internet Economy, visit The Industry Standard.
Story Copyright 2009 The Industry Standard. All rights reserved.

Additional Resources

Xerox
By using solid ink technology only from Xerox, you could save up to 65% by printing color for the cost of black and white. Enter for a chance to WIN a PhaserTM 8860 network color printer!
Microsoft
Save time and mitigate security risk. Deploy it now.
Sybase
In this white paper, IDC analyzes the role of next-generation mobile enterprise platforms as organizations seek a more strategic deployment of mobile solutions.

Learn the important issues you must consider before starting your next mobility initiative. Get your mobility white paper from IDC now, compliments of Sybase.

White Papers & Webcasts

Accelerate SSL Encrypted Applications
The amount of SSL traffic is growing in the enterprise. Because it is encrypted, it cannot be properly controlled and accelerated. Blue Coat...  

Usability Is Everything
Learn what sets Workday's HR and Payroll solutions apart from the competition....

ESG Lab Field Audit
Many companies have successfully implemented Riverbed WAN optimization solutions within their Cisco networks. This ESG Lab Field Audit document explores the success that...  

The Value of Real SaaS at Workday
Cost savings, speed to value, and innovation brought to the enterprise by Workday's software-as-a-service solutions for HR and Payroll....

Shape Your Apps Strategy to Reflect New SaaS Licensing and Pricing Trends
Why are smart companies choosing software-as-a-service? Find out in the complimentary Forrester Research report...  

SaaS at Flextronics, Inc.
Dave Smoley, CIO of Flextronics, discusses the real value of software-as-a-service and why he chose Workday for his HR solution....

Natural User Interface for Enterprise Applications
Learn how a revolutionary user interface can make a complex enterprise application so intuitive even casual users can jump right in....  

Why Compliance Pays
This OnDemand webcast explores the relationship that firms with best compliance records have higher revenue, greater customer retention, lower financial losses from data...

A Truly Global HCM System
Learn about a system built with advanced object-oriented technology that support multi-national requirements and costs less to implement, maintain and upgrade....  

Agile Enterprise Content Management (ECM) for Rapid ROI
Find out how combining ECM and BPM will help adress issues about content rich business processes....