Microsoft Got Hacked Via a SQL injection attack

June 29, 2007 by Raj
Filed under: Security News 

‘The official Microsoft U.K. Domain was attacked and defaced by a hacker identified as rEmOtEr’

Microsoft confirmed that the hack has been successful. rEmOtEr altered a webpage in the Microsoft.co.uk domain with two images and multiple references to the kingdom of Saudi Arabia. The U.K. branch of the Redmond company managed to fix the problem, and the functionality of the website is back to normal parameters. The webpage hacked dealt with Microsoft events and can be found here. In the adjacent image you can see how the hacker defaced the page, courtesy of Zone-H.

Roger Halbheer, chief security advisor for Microsoft in Europe, the Middle East and Africa admitted that the hack was successful and revealed that the whole event was unfortunate. According to Microsoft, no sensitive information was compromised in the attack. This is a clear indication that the hack was done for show, rather than to actually cause any harm. Another argument that supports such a scenario is the fact that rEmOtEr took time to document the hack in two separate video fragments. You will be able to watch for yourselves the live hacking via the two “remoter_vs_microsoft.avi” files.

Zone-H

The hack was possible mainly because of the fact that the database was allowed to return error messages explained Halbheer, as cited by InfoWorld. The attack was possible through a technique referred to as SQL injection. This fact is also confirmed by the hacker in the two videos that were made available. Via Structured Query Language injection rEmOtEr was able to gain access to the database. In the video fragments you will be able to see how easy the hacker obtains both usernames and passwords for the database. Working his way from error message to error message, rEmOtEr finally could switch from SQL queries with an unexpected form to direct instructions to the database.

Source: Softpedia News

Comments

Tell me what you're thinking...
and oh, if you want a pic to show with your comment, go get a gravatar!





    • Translate from:

      Translate to:

  • Recent Comments

    Freeware Sticky Notes App For Windows... I have found some ...
    Yes Neville, 1 Gbps sure is amazing. I doubt the arrival of ...
    "1 gbps", thats an insane speed........ i mean WOW..... j...
    Google ISP, Offering 1 Gbps Data Transfer Speed... Google h...
    please provide sum pic regarding the technologies also nee...
    Hi Anne. The technology is indeed very interesting and ambit...
    I read about it on the newspaper a while ago. Pretty amazing...
    In Research: Computer Systems With Capabilities Of The Human...
    Yes you are right. I am sure his parents and the company are...
    Wow. She .... He really needs to go out and play. Work is on...
  • Recent Posts

  • Categories