ieak.microsoft.com — Someone called "Cyb3rT" has defaced a Microsoft's web page - not the main one, but anyway. If you're fast you'll see it. In case it's fixed, a capture can be found at http://img254.imageshack.us/img254/949/defacefg5.jpg. Not good news for the company that claims to be the first software company of the world.
Apr 28, 2007 View in Crawl 4
cmallinsonApr 29, 2007
This has nothing to do with the security of the host. The site was hacked because form input was not validated. That's the developer's fault.
danielsimonApr 29, 2007
so muhc o' teh awesomnesz
hitman6800Apr 29, 2007
Ok people, fact is, as has been said before the host server is not the security flaw here. The moron who didn't sanitize user input is the one who should be in trouble. Fact is, very many 'dynamic' sites do not make sure that valid html code or scripting was used where the user inputs data into a form.Read up on cross-site scripting and SQL injection techniques to see exactly how this is done. Also, SANS keeps a list of vulnerable web applications. It is so long that is is scary, because most programmers work with a mindset of 'get the s**t working' rather than, make it work securely.Moral of the story, sanitize user input.
oceanmoonApr 29, 2007
Argh, story could not have been buried...
tjfloyd24517Apr 29, 2007
Looks like Microsoft has taken it down now
steve95613Apr 29, 2007
Login page is down too.<a class="user" href="http://ieak.microsoft.com/1.0/login.asp">http://ieak.microsoft.com/1.0/login.asp</a>
washcapsfan37Apr 29, 2007
That's kind of the point. The defacement wasn't rewriting the HTML. All he did was manipulate unvalidated forms to inject some HTML/CSS that hides the old page and only shows the one entry making it look like the site was "hacked". Interesting but not difficult.
shanesemlerApr 29, 2007
So some asinine script kiddie with nothing better to do vandalizes some page on an MS site? You're giving this retard attention he doesn't deserve. Buried as lame.
shawnzJun 4, 2007
well i kind of expected it to convert them to text -- you would have got that impression if you read my post