ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Online business Toolkit

Lovesick hacker hits Microsoft

ZDNN, US ZDNet US

Published: 27 Oct 1999 08:30 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Earning a footnote in the annals of computer vandalism, a lovesick hacker known as "flipz" on Tuesday became the first person known to have defaced one of Microsoft Corp.'s Web sites. The hacker, who also altered a handful of government Web sites in recent days, says he expects to be arrested soon. "Its (sic) all about fun till the feds bust down the door," said a message left on one of the defaced Web sites.

A Microsoft spokesman said early Tuesday that he was unable to confirm the attack on the company's Conference Management Server site, but the defacement was documented by attrition.org, a reliable computer security site that maintains an archive of hacked Web sites. Representatives of two government Web sites hacked by "flipz" -- the Department of Veterans Affairs and the White Sands Missile Range in New Mexico -- confirmed that attrition.org's account of the vandalism of their sites was accurate.

Part love note, part threat

On Monday, the hacker replaced Microsoft's Conference Management Server home page, which was not accessible Tuesday morning, with a message that was part love letter and part threat, attrition.org reported.

"flipz was here and f0bic, your seksi (sic) voice helped me through the night," it read in part before concluding with a threat against Microsoft CEO Bill Gates.

B.K. DeLong, curator of the attrition.org Web defacement archive, said research of other hacking mirror sites -- which use a computer's "screen grab" function to document vandalized Web sites -- indicates that this is the first time Microsoft has been victimized.

"This is the first time that we've been publicly notified (about a hacking claim against Microsoft) ... and to build our mirror we borrowed mirrors from other sites," he said.

All of the recent hacked pages were accessed through Microsoft NT servers, attrition.org said.

Other sites affected?

The hack appeared to impact a series of Internet domains Microsoft maintains outside its standard corporate presence on the Net. As of Tuesday morning, at least six sites registered to Microsoft weren't functioning, though some may have been removed prior to the hack.

While most Microsoft corporate site IP addresses start with 207, the hacked page started with 131. On Tuesday, all Microsoft sites between 131.107.65.0 and 131.107.65.20 weren't functioning. These likely were all hosted on the same server, which apparently was offline.

The impacted Web pages appear to be conference information sites, including "icassp.microsoft.com," "isys.microsoft.com," and "cuai-97.microsoft.com." Another non-functioning site was "uncertainty.microsoft.com." The purpose of that site was not known.

A prominent target

Microsoft has long been a prominent target of hackers. The 2600 Web site, the online home of a hackers' magazine, has the Redmond, Wash., company prominently listed on a page of "Hacked Sites of the Future."

But DeLong said he wasn't aware of any competition to break into Microsoft's computers.

"I haven't really heard people saying, 'Ooh, I'm going to hack Microsoft!' Part of it may be that they think they can't get in or ... that they fear retribution from Microsoft," he said.

DeLong said "flipz" first came to his attention in March, when he reported he had hacked a Web page operated by NASA's Jet Propulsion Laboratory. The hacker added attacks on Duracell Corp. in June and People's Bank of Connecticut in September to his resume before the recent spate of attacks, which began Wednesday.

According to attrition.org, "flipz" altered the University of California at Riverside Police Department's Web site that day before turning to government targets, knocking off, in rapid succession, the home pages of the U.S. Army Reserve Command, the White Sands Missile Range, the U.S. Army Dental Care System, the Navy Management System Support Office and the Department of Veterans Affairs.

Hacker love?

The love notes that "flipz" left on two of the defaced sites suggest that the hacker has a crush on a fellow computer intruder.

The person known as "f0bic" is a member of "Team Spl0it," a hacking group that retaliated for the FBI's arrest in September of alleged hacker Chad Davis by vandalizing several Web sites.

Davis, a 19-year-old Green Bay, Wisconsin resident, is accused of breaking into a U.S. Army computer at the Pentagon. According to a federal complaint filed at the time of his arrest, Davis is a founder and leader of the "Global Hell" hacking group, which vandalized Web sites of the White House, FBI and U.S. Senate Web sites earlier this year.

The FBI did not respond to a query about whether "flipz" hacking attacks were under investigation, but DeLong said the hacker expects to be arrested before long.

"flipz said he doesn't care if the feds come and get him," DeLong said. "He's expecting to get picked up, but he's going to have fun while he's waiting."

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with HP

Did you find this article useful?
33 out of 64 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:








Related Jobs

Business Integration Analyst

We would love you to have; - The ability to handle complex problems requiring judgement, taking issues from first principles. You will also have ...

J2EE Team Leader (Telecoms) - Customer Management

We would love you to have; - Significant experience in managing task focused teams and the ability to systematically plan, organise, schedule and ...

Websphere Architect / Technican

We would love you to have experience in some or all of the following skills; - Websphere 4/5/6 Architecture - Websphere Application Server - ...

Sentry Posts Blog

Mobile Linux Better For Mobile Busines...

Mobile Linux Better For Mobile Business Apps? Author: Eric Everson, MyMobiSafe.com As mobile Linux is carving it’s footprint on the future of mobile application development, the... More

Post a comment

DWP downplays security breach

The Department for Work and Pensions (DWP) has admitted that some of its staff have been forwarding passwords with password protected material. An email that was leaked on the 'Dizzy... More

Post a comment

How many headshots does one chairperso...

We got a strange request last week from the head of PR from Russian security experts Kaspersky. It seems although the company was very happy with the interview we recently carried with... More

Post a comment

Featured Talkback

I wonder, who needs .asia domain? I cannot imagine, what would be useful for Microsoft.asia? Toyota.asia? Then let's register .europe (if .eu is too short). Or perhaps Microsoft.southamerica, Dell.australiaandnewzealand, Coca-Cola.africa... Sound funny? Then why not just use the global and country domains? Or perhaps it is time to drop the domains at all?

By: LadyRoot

Read full story:
Businesses advised to register .asia domains