ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Details emerge of Microsoft website hack

Tom Espiner ZDNet.co.uk

Published: 02 Jul 2007 17:52 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Details have emerged of an attack which defaced Microsoft's UK website.

Hackers broke through the site's security, defacing it and replacing genuine content with a photo of a child waving a Saudi Arabian flag.

It is likely that Microsoft.co.uk, which was breached on Wednesday, was subverted using SQL injection, according to security site Zone-H, which has also run a picture of the defacement. "Most probably, the attacker exploited the site by means of SQL injection to insert HTML code in a field belonging to the table which gets read every time a new page is generated," said Zone-H on its site.

Microsoft said it was investigating the breach. "Microsoft has learned of a criminal attempt to deface a sub-site of Microsoft.com," the software giant said in a statement. "Upon notification of the criminal activity, Microsoft took the appropriate action to resolve the issue and stop any additional criminal activity. Microsoft is not currently aware of any customer impact as a result of this criminal activity but will continue to investigate the incident and take any necessary action to help protect customers. In addition, the defaced website was restored to its original content within hours."

Read this

Watch Debbie wrestle the Kraken

ZDNet UK member Xwindowsjunkie is pitting the next Windows Home Server against a homemade alternative built from open-source components. So how's it going?

Read the discussion+

"We apologise if customers are inconvenienced by the unavailability of the affected website. Microsoft is committed to helping protect our customers and we're working diligently with the third-party hosting company to ensure the continued security of the website."

Ed Gibson, Microsoft UK's chief security advisor, played down the impact of the security breach. "I think it's always difficult when any company suffers from an intrusion by a criminal organisation," said Gibson. "As to the question of long-standing damage — [Microsoft will not suffer], because that particular matter was cleaned up quickly. Criminals are always trying to steal or break into systems — it shows we can't be complacent. By all of us working as an industry to make the [ecosystem] better, we'll continue to make it better tomorrow. Unfortunately these things happen."

Patrick McLaughlin, the European director of security solutions at database company Oracle, said that "software can never be fully tested".

"When building commercial software for databases, there's a finite amount of time to test it — software is never bug-free," said McLaughlin. It is understood that it was not an Oracle database that was subverted.

Gibson and McLaughlin spoke to ZDNet UK at an event organised by RSA Conference Europe.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
7 out of 9 people found this useful


Company/Topic Alerts

Create a new alert from the list below:





Related Jobs

Senior Developer

Supply application level support on all website activity, includes support of all software related to delivering customer accessible services. Senior ...

2 Senior Testers needed by leading Media client - PC based televisual

You will plan, execute and report testing activity, and this will predominantly be web-based, so previous experience in this area is key. Two of the ...

Graduate Opportunities in Technology

If you do not possess a valid UK work permit please visit our global website at www.capgemini.com) Locations: You must be prepared to be based in our ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment