Advertisement
Home arrow ITsec News
Saturday, 22 November 2008
 
 
Last week attacks
O.S.  Defs.  %
Linux  8778  71.58%
Win 2003  1950  15.90%
Win 2000  722  5.89%
Solaris 9/10  402  3.28%
FreeBSD  226  1.84%
Other  185  1.51%

Total attacks: 12263 of which 4619 single ip and 7644 mass defacements

Main Menu
Home
Digital Warfare
Geopolitics
ITsec News
ITsec Advisories
Test Drive
360°
Digital Attacks Archive
Zone-H events
Publications
Zone-H Friends/Partners
Contact Us
Search
Download Area
Zone-H forum
About this website
Login Form





Lost Password?
No account yet? Register
Visitors' Map
ITsec News


The Microsoft France incident: IIS 6.0 bug or not? How it happened... and why
User Rating: / 118
Written by R. Preatoni - D. Werner   
Tuesday, 20 June 2006

 After yesterday's incident where a Microsoft France website was hacked and defaced by a Turkish cracker going by the handle of TIThack, Zone-H investigated a bit and contacted the cracker and asked to detail the intrusion methodology [the cracker originally reported  a generic "web server intrusion"].

So, are we looking at a new win2k3 / IIS 6.0 0day exploit here?

Write Comment (7 Comments)
Read more...
 
Googlepages downloads Trojan
User Rating: / 5
Sunday, 18 June 2006

 Today security company Websense is reporting conformation that a site hosting Googlepages contains malicious code.

According to the article the malware contains a banking information stealing component that captures user banking credentals and keylogger components. Accordingly it appears that this was caught before any infections could begin.

At the current time we are unaware if the hacker is using a browser vulnerability  to trigger the attack, or was a prelude to phishing attacks using Google's trusted domain to lure users into clicking and downloading the Trojan file.

Write Comment (1 Comments)
Read more...
 
Microsoft France: DEFACED!
User Rating: / 995
Written by D. Werner - R. Preatoni   
Sunday, 18 June 2006

Microsoft France was defaced today by Turkish crackers, going by the handle TiTHacK

Zone-h received notification at 2006/06/18 19:19 (GMT+2) that the experts site was defaced "just for fun".

The defacement reads:

 

Hi Master (: Your System 0wned By Turkish Hackers!

redLine ownz y0u!

Special Thanx And Gretz RudeBoy |SacRedSeer|

The_Bekir And All Turkish HacKers

next target: microsoft.com

date: 18/06/2006 @ 19:06

WE WERE HERE....


The attackers notified Zone-H that this was by "WEB SERVER INTRUSION", which could mean a possibility of either a vulnerability in IIS6 or a web-application running on the site...

A mirror of the defacement may be viewed here...

Write Comment (76 Comments)
Read more...
 
Defacement Disclosure: No Comment ?
User Rating: / 9
Sunday, 18 June 2006

 At Zone-h we are privy to a first look at a large number of defaced sites before the fact of the defacement has been made public via our mirrors. As one who verifies sites to the mirror, the author often visits the site before looking at and verifying the mirror, which our site captures immediately when the defacer submits his site, and more than often, later, at the time of the mirror verification the site appears to be normal. By normal we mean that there is no defacement anymore and everything looks as it should. In our estimate 99.9% of the sites have no mention of any intrusion period... and this troubles us.

A defacement may be just that, a defacement, or it is possible that the defacer has also captured valuable data. The most valuable data, apart from identity and credit card data, is information of your users...

Write Comment (5 Comments)
Read more...
 
New York State doesn't like Google's porn
User Rating: / 6
Friday, 16 June 2006

 In a statement issued, The New York State Consumer Protection Board [CBP] is warning parents that Google is providing easy access to material containing "videos with sexual themes and off-color material". In particular they are targeting Google Video because in it's present form it does not allow for safe searching options that should restrict content to exclude inappropriate content.

Since Google has become a de facto standard as well as it's globalization and privatization, it now has separate and distinct geographical search engine Points Of Presence (hint: China), Google has become, as far as I can see, a body that can be regulated and governed under each of its global server entities and that nations rules and laws.

Write Comment (0 Comments)
Read more...
 
Yahoo Webmail vs Scripting: 2-3
User Rating: / 9
Friday, 16 June 2006

 Despite Yahoo fixing a serious bug in its webmail within 30 minutes of public notification on the Full Disclosure  mailing list, it was once again vulnerable today. Creative hackers had found ways to modify the scripting that causes the flaw and it was once again vulnerable to attack.

At least one security researcher even has a page that lets you test the flaw. Also on the page they give a timeline of the problem, the fixes and the modified vulnerability status...

Write Comment (1 Comments)
Read more...
 
<< Start < Prev 1 2 3 4 5 6 7 8 9 10 Next > End >>

Results 209 - 234 of 4508
Advertisement
 
Top! Top!