172 Comments
- maht, on 10/12/2007, -3/+51state the bleeding obvious
- inactive, on 10/12/2007, -4/+33I'm not a hosting company and I don't work for a hosting company. 1and1 hosts that particular server (the only server that's been hacked out of the 8 I manage).
As for linux - I'm a .NET / MSSQL developer. I hope you're old enough to understand the differences between LAMP & .NET, and how they're not just "interchangable" in theory or career wise. - Murdats, on 10/12/2007, -0/+24or even better, crippling the RIAA systems
- mrtrick, on 10/12/2007, -1/+20Why, is there only 10 people in Turkey with computers?
- msaleem, on 10/12/2007, -0/+18Statistics about Iskorpitx's incidents can be found at:
http://www.zone-h.org/en/en/defacements/filter/filter_defacer=iskorpitx/
while the full list of the 21,549 defacements can be found at:
www.zone-h.org/defaced/list.txt - zigzagdesigns, on 10/12/2007, -4/+22I am Armenian... This hacker is really not helping his people by doing this. He's just angry because the French government has acknowledged the events of Genocide of the Armenians by the Turks in 1915 where 1 500 000 Armenians died "accidentally" under the Turk's occupation.
I don't think by keeping on denying the pas that country is going to move forward. - SidU, on 10/12/2007, -0/+17Heres a what the hacked pages looked like; http://www.zone-h.net/defaced/2006/05/18/www.majesticsky.net/ssfm/isko.htm
- miztadux, on 10/12/2007, -0/+17<meta name="GENERATOR" content="Microsoft FrontPage 5.0">
Now that's a real FrontPage Hacker ! - tHePeOPle, on 10/12/2007, -1/+14@mrtrick
It takes more than that to attain the rank of Captain. Lets give this one a Lieutenant Obvious. - inactive, on 10/12/2007, -3/+16p9s50W5k4G ...
It's not. This is the third time one of my clients' servers has made zone-h's list because of some bug allowing remote users to create files.
The first time it happened (~a month ago) the hacker created files matching IIS's default index files, and unfortunately overrode the default.aspx (lower on the list) which caused me some annoyance temporarily.
This time at least it's "iska.html" files, small mercy I guess.
The server in question has a firewall, Win2003 Standard and MSSQL Standard. The firewall is blocking everything bar port 80 (http), 21 (ftp) and 3389 (remote desktop), because there's only web & ftp on it. - p9s50W5k4GUD2c6, on 10/12/2007, -16/+27These exploits are, in large measure, the result of poor hosting security.
- mrtrick, on 10/12/2007, -6/+16I was going to say "thank you captain obvious", but that works too.
- inactive, on 10/12/2007, -5/+13If this is an IIS 6 bug it will be only the third in it's lifetime.
- Jams, on 10/12/2007, -4/+12What is it with people assuming that installing Linux guarantees you a secure machine? The majority of the machines I used to see exploited were poorly mainitined Linux boxes.
Thats not to say because the Windows machines were secure, this was simply because they were far more useful to the hacker/script kiddie as he or she could use it as a platform to launch further "attacks". eg. Running portscans of large subnets grepping the results for exploitable machines then running to gain yet more boxes.
It this instance I suppose it doesnt really matter as it was just a defacing, but it could just of easily have been a *nix machine. - nailbunny, on 10/12/2007, -0/+8such as?
there's no such thing as objectivity. history is written by a people with points of view. - theHM, on 10/12/2007, -1/+9"free cyprus!" etc
- TigerWalk, on 10/12/2007, -0/+7I am turkish too...and like to say a few words here;
We should not reply anger with anger...no hate please...and what this so called "turkish hacker" did is totally wrong..and statement he put up there is politically and morally wrong.....so I have to apologies for that.
You can't blame whole Turkish population what was happened long time ago.You guys have to understand that there are many Turks in Turkey believe that many Armenians died. And we are sadden for that. But people in Turkey having hard time to accept the word "Genocide". Ottoman Empire was not barbarians. If they were, half of Europe, Middle East wouldn't be existing by now. And there is historical proof for that (if you smart enough and do the Google or read some history books).
Again, as I Turkish, I have to apologies for that.
p.s: it is also sad that when you check the map (en.wikipedia.org/wiki/Armenian_Genocide#The_position_of_the_international_community) and seeing that “Although there is no federal recognition of the Armenian Genocide, 39 of the 50 U.S. states including Alaska, Arizona, Arkansas, California, Colorado, Connecticut, Delaware, Florida, Georgia, Idaho, Illinois, Kansas, Louisiana, Maryland, Massachusetts, Michigan, Minnesota, Missouri, Montana, Nebraska, Nevada, New Hampshire, New Jersey, New Mexico, New York, North Carolina, Ohio, Oklahoma, Oregon, Pennsylvania, Rhode Island, South Carolina, Tennessee, Utah, Vermont, Virginia, Washington, and Wisconsin recognize the events of 1915 to 1917 as genocide.
What about Indians in USA? Once Chris Rock made a joke “Tell me how many of you seen two Indians walking together” Genocide? Maybe, maybe not.
Peace & Love - estvir, on 10/12/2007, -12/+19using a linux distro isn't going to magically make them secure apotropaic . .
i'd suggest freebsd or even openbsd of linux actually. - jrbrewin, on 10/12/2007, -5/+11looks like someone needs to go and look at how secure iis6 is v apache, or other web servers. You'll be pleasantly surprised to learn iis6 is actually very stable, if not more so, in terms of exploitable vulnerabilities.
- estvir, on 10/12/2007, -2/+8um, go through zone-h and see how many defacements there are for *nix based systems.
scripts are usually created to target a single known hole which can be exploited efficiently, so he found one on iis 6 (which there are barely any, and almost 0 publicly known ones and 0d ones have barely ever surfaced).
also, reading up on it more apparently the way he did it wasn't through a hole of sorts, but from a misconfiguration which there is alot and the main reason for defacements. - jackskellington, on 10/12/2007, -5/+11well, it is also funny how Armenian's distort the reality in their way. First of all, French parliament talked the issue in a meeting and it never got to the closure that the issue to be voted. Second, the French prime minister (or one of the ministers) talked at the meeting and said that governments should not write history, this is the duty of the historians. The last thing is that the Turkish government has called for a neutral meeting for all the historians (from both sides plus any neutral observers) but neither the Armenian government nor any Armenian historian has accepted this meeting. Ottoman archives are open, anyone can go and read the details.
Only because Armenians are yelling out that there was a genocide this doesn't turn it into a fact. Armenians and Turks were living happily side by side before the first world war along the eastern borders of Ottoman Empire. But during the war, the Armenians decided to help the Russians and started to kill people. Then the government told them to move. Forced them to move to the south, far from the borders. That is what happened. Logically people got killed on the road. Because of the conditions but no one has killed systematically with government support.
And check the news what the Armenians are capable of when they attacked a village in Chechnya. - LordLucless, on 10/12/2007, -2/+8@Jams: You mean being ignored/sued for your efforts? I'm not condoning his actions, but they're probably more likely to get stuff done than a hundred polite emails.Not that I think that was his motivation. Personally, if I found a vulnerability in a system like that, I would do absolutely nothing. People have been sued for explaining to people the flaws in their computer system. Many more have simply been ignored. It is in no way in my interest to put myself on the line for people who cannot perform their jobs properly.
- estvir, on 10/12/2007, -2/+7err, botnet's don't "do hacking for you."
.. and look @ the websites on zone-h that are defaced, notice how many are *nix based ? .. yeah, enough of the ms bashing. - Jams, on 10/12/2007, -4/+9I think he should be using his time more constructively, like nforming the webmasters that he "could" hack there servers and suggesting a fix. You know, going White hat..
- dc2447, on 10/12/2007, -5/+10Eventually come up with? People have been using scripts to deface windows servers since I can remember.
- zecreven, on 10/12/2007, -0/+4Americans are killing iraq people.. isnt it called barbarian?
- xtremesniper, on 10/12/2007, -0/+4The topic comes up because if you would click the link, you would see Armenians are mentioned (spelt wrong) by the hacker in his defaced websties.
- nailbunny, on 10/12/2007, -0/+4don't forget about the americans who beat matthew shepard to death for being gay. and some cops who rape some guy with a broom handle about once every three years. such violent hate crimes here are rare enough that they make world news when they happen.
but still, to say that if acts of cruelty take place in america, then it's OK if it happens elsewhere, is moral relativism and a shoddy argument. cruelty is cruelty, and it deserves to be punished, and in all the cases of these outrageous hate crimes, it is.
now obviously there's no one left in turkey who is responsible for what took place, so its not necessary to punish their grandchildren. however, this genocide, like every genocide, needs to be brought out into the open, into everyday discussion, in order to remain conscious of the human capacity for cruelty and be able to anticipate it in the future and work to prevent it. - zecreven, on 10/12/2007, -0/+3everyone knows that americans are raping iraqi people, torturing them.. isnt it called barbarian either?
- miker71, on 10/12/2007, -6/+9The press should have a field day with this. Wasn't IIS6 rewritten with security in mind, and didn't Microsoft spend a couple of years squashing all bugs as part of their "Trusted Computing" baloney? Maybe I just have a bad memory that goes beyond two weeks. Maybe I just read the wrong journos.
- semihaker, on 10/12/2007, -2/+5This is what we call ARMENIAN LOBBY; everyone knows about it, don't misguide people..
Places you count are full of Armenian immigrants. So this is a pure result of dirty politics... Djorkaeff, son of an Armenian descendent, was a national hero in France for years.
This issue just got our attention and you cannot expand your ideas as easily as in the old times. - inactive, on 10/12/2007, -0/+3@ f00xx0riz3r
They're not interchangeable because the server in question has about a half a million lines of c# and a couple of mssql databases with plenty of sprocs and triggers. The locations with inline sql also take advantage of mssql-specific functions.
Maybe on the level you work at you can just switch languages and db platforms at the drop of a hat, but you will find many digg users are a little past "select title, body from content". - 0n7R, on 10/12/2007, -2/+5hmm last time I checked, Ottomans ruled Greece over 300 years.
Do they still speak Greek? YES
Are they still Christians? YES
Do they still live in their homeland (Greece) ? YES
Was there any genocide or any geneocide attemps? NO
SO WTF?
Why did they want to kill 1.5 Armenians (which was a false population count according to French they were 900,000, so now there are only -600,000 Armenians left)
be logical , why Turks wanted them to be eliminated (if it was true)
The land? NO (Armenia is a locked land with no valuable resources)
The people? NO (as far as I know Armenians do not carry gold inside them)
To kill all Christians? NO (hmm Ottomans ruled 3 continent with a mixture of religions, why choose them)
this list go on, please my friends see this from logical side, none of this makes any sense...
Ottomans actually never assimilate, destroy or convert them forcefully.
All these false genocide claims are false.
Ok last thing, if Armenians hate Turks, and think that they killed their relatives, etc. why are they selling all Turkish products on their markets in USA? I hardly believe a Jewish friend will sell Hitler only products in his store...
nonsense - brokoli, on 10/12/2007, -0/+3It's in French because France is gonna accept the Armenian genocide officially.
- estvir, on 10/12/2007, -7/+10meh, creating a script [usually perl] which targets an easy/well known vulnerability isn't all that great (there are many tutorials found on 'shady' websites but i assume this guy figured it out himself), but this guy sure has alot of spare time for defacing websites, go him.
- nailbunny, on 10/12/2007, -2/+5in the states, we call that 'freedom of assembly'
- n3yt, on 10/12/2007, -1/+4"Forced them to move to the south, far from the borders. That is what happened. Logically people got killed on the road. Because of the conditions but no one has killed systematically with government support."
Being forced to march for 80-100 miles nonstop is a death sentence for many, especially children and the elderly. I think that is both systematic and with government support. - inactive, on 10/12/2007, -1/+4Uh.. have you never heard of a worm? Agrobot? Come on now.. eventually nothing.. that's so 10 years ago..
- elkos, on 10/12/2007, -1/+4Today May 19th is the Memorial Day of the Pontian Greek Genocide in many US states and in europe.
http://en.wikipedia.org/wiki/Pontian_Greeks_Genocide
I live in a suburb of Athens were many Pontians live and i believe their Grandparents stories. Genocides are not a criminal act of a nation but an act of it's leaders for me. I believe that the leaders of Turkey and the people of Turkey today are wise enough to consider such atrocities a scar on Turkeys history as did our felow Germans did, I hope... - zigzagdesigns, on 10/12/2007, -2/+5Here U go! http://en.wikipedia.org/wiki/Armenian_Genocide
- Jams, on 10/12/2007, -0/+3Digg removed some of my text because I used a tag. It should read:
"then running various scripts to gain yet more boxes." - GBoS, on 10/12/2007, -0/+2So was this actually a 'racially targeted' defacement-spree? Or did he just put Turkish hacker for the sake of it?
- inactive, on 10/12/2007, -0/+2The site for the city government where I work got hacked by this group. It's hosted by a small-time hosting company though. They patched it quick.
- akifbayram, on 10/12/2007, -0/+2Im turkish
Must of took him a wile to hack them all
O *****, my site..................
taht bastard - heffer2k02, on 10/12/2007, -12/+14And if it's an IIS bug, we can expect a fix in a third of our lifetimes.
- inactive, on 10/12/2007, -0/+2I knew that it would be a Turk. Mamma il Turchi!
- KCorax, on 10/12/2007, -1/+3We are talking about massive defacement.
This is a criminal not a vigilante in a middle age literature script. - DJMajickman, on 10/12/2007, -1/+3"apotropaic
So this is your hosting company that got hacked by Iskorpitx?? Try using linux. Should fix the problem OF ALLOWING HIM TO CREATE FILES REMOTELY!"
Did you even check the list... Hmm what's this a Linux box got "M - Mass defacement" gee now that's security
2006/05/19 iskorpitx M ...ADES.COM/ssfm/isko.htm Linux - dhughes, on 10/12/2007, -0/+2 Yeah I know it's crazy but you still have to act civil even though you are facing your most dire enemy. You can't give anyone a chance to say you're violent or uncivilized by acting aggressively by not discussing what to do, even though you have truth on your side.
- zigzagdesigns, on 10/12/2007, -2/+4Countries officially recognizing the Armenian genocide include Argentina, Armenia, Austria, Belgium, Canada, Cyprus, France, Germany, Greece, Italy, Lebanon, Lithuania, The Netherlands, Poland, Russia, Slovakia, Sweden, Switzerland, Uruguay, Vatican City and Venezuela.
39 of the 50 U.S. states including Alaska, Arizona, Arkansas, California, Colorado, Connecticut, Delaware, Florida, Georgia, Idaho, Illinois, Kansas, Louisiana, Maryland, Massachusetts, Michigan, Minnesota, Missouri, Montana, Nebraska, Nevada, New Hampshire, New Jersey, New Mexico, New York, North Carolina, Ohio, Oklahoma, Oregon, Pennsylvania, Rhode Island, South Carolina, Tennessee, Utah, Vermont, Virginia, Washington, and Wisconsin recognize the events of 1915 to 1917 as genocide.
Ref: http://en.wikipedia.org/wiki/Armenian_Genocide#The_position_of_the_international_community -
Show 51 - 100 of 172 discussions



What is Digg?
The Digg Toolbar for Firefox lets you Digg, submit content, and keep track of Digg even when you're not on the Digg site. Download the official