ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Emerging tech Toolkit

AOL communities get hacked again

Wendy McAuliffe ZDNet.co.uk

Published: 29 Jun 2001 14:28 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

AOL's ICQ servers were hacked on Monday for the second time this year, it was revealed last night.

The ICQ homepage was defaced by the hacking group Innocent Boys, while a separate server ICQgroup01.icq.com was simultaneously attacked by the notorious Men in Hack (MiH) crackers who added a defaced page to the community page.

The free peer-to-peer ICQ software uses the Microsoft IIS Web server. "This has more holes than Swiss cheese," said Mark Read, systems security analyst for computer security company MIS Corporate Defence Solutions. "It seems that Microsoft doesn't understand the terms of bounds checking -- I strongly suspect that within the next couple of weeks another hack of this system will be found."

The two main vulnerability exploits of IIS that crackers are targeting at the moment are the index server buffer overflow for which no official patch has yet been released, and the IIS 5 remote printer overflow, said Read. "Microsoft has released patches for known exploits, but people install servers and don't install the patches or subscribe to any bugtraq mailing lists," he said.

AOL said that the electronic defacement vulnerability was quickly patched, and that no customer details were accessed. But Read argues that it is difficult for AOL to be certain of this. "When you do a search on ICQ, you don't know if this is directing you to another server, or carrying out the search on the screen being defaced where data could be compromised," he said.

On Tuesday, the UK Web site of the fast food chain Burger King was defaced for the third time this year, this time by a cracker operating under the nickname of MrAgent. The flash-enabled site was hacked using a similar IIS buffer-overflow vulnerability.

Is your PC safe? Find out in ZDNet UK's Viruses and Hacking News Section.

Have your say instantly, and see what others have said. Click on the TalkBack button and go to the Security forum.

Let the editors know what you think in the Mailroom. And read other letters.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
40 out of 71 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:












Related Jobs

1st/2nd Line Technical Support/Helpdesk Agent/Analyst/Engineer HR.net, SQL, IIS, RDBMS, .NET Salary up to 21,000 - Worle, Weston-Super-Mare Nr Bristol

1st/2nd Line Technical Support/Helpdesk Agent/Analyst/Engineer HR.net, SQL, IIS, RDBMS, .NET Salary up to 21,000 - Worle, Weston-Super-Mare Nr ...

Technical Consultant, Wholesale Banking Payment, Swift, AIX, Watford

This is an application focussed role & your responsibilities will be to install, configure & set-up these Wholesales Banking Payment systems for my ...

Web Support Engineer (IIS,Apache,Tomcat) BANKING

The ideal candidate MUST have experience supporting complex web applications, troubleshooting, experience in Unix/NT & Windows 2000 & strong web ...

Discussions

keithmv keithmv

Password Deadlock

Saturday 26 July 2008, 12:02 PM

2 comments

Blog Posts

Avatar geek

Gateway 450SX4 Laptop Computer

Saturday 26 July 2008, 4:46 AM

0 comments
Avatar geek

Windows XP

Saturday 26 July 2008, 4:41 AM

0 comments

Featured Talkback

While full medical records may be of (dubious) value at rear/base medical facilities, these could be provided much simpler by either physical disk or electronic transfer to an "in theatre" database for individuals posted in. That £80m (and it's associated running costs) could have been far better employed in resuscitating a disbanded infantry battalion or providing a big boost in equipment quality and quantity.

By: 1000215420

Read full story:
Photos: MoD unveils £80m IT health programme