Microsoft UK Web Site Hacked via SQL Flaw

By Ed Oswald | Published July 3, 2007, 2:47 PM

More details are now available on the hacking of the Microsoft UK Web site, with experts saying that the attackers got in through a SQL injection exploiting a vulnerability in the Web server software.

The attack, which occurred last Wednesday, defaced the front page of the Web site and inserted the image of a child waving the flag of Saudi Arabia. According to Zone-H.org, a hacking news Web site, the attacker used the SQL flaw to inject his own HTML code.

Microsoft has not confirmed how the attackers entered the site, saying only that it was investigating and had removed the injected code to return the page to normal. It also took action to ;stop any additional criminal activity."

It also said it was in contact with the third party which hosts the UK Web site to improve the security and prevent similar attacks from occurring. It is not known whether the database that was hacked was Microsoft's, although Zone-H speculated that it was MS SQL Server.

Microsoft's security chief in the UK played down the incident in an interview with ZDNet UK. ""Criminals are always trying to steal or break into systems--it shows we can't be complacent," Ed Gibson said. "Unfortunately, these things happen."

Comments

View comments by with a score of at least

No doubt the clever person who invaded the MS UK Web Site will be offered employment for their fine efforts and then they'll all live incestuosly "happily ever after".

Score: 0

|

Yeah, I'm sure that's how these things are happend--This is an indication of poor programming and security levels.

Score: 0

|

As always, the OS that is on a majority of servers or home users PC's is under attack constantly. If Mac OS or Linux were a majority on servers or home PC's they would be under constant attack also.

Score: 0

|

So the majority of internet web "SERVERS" run LAMP (Linux, Apache, MySQL, PHP), and have a lower number of security incidents then WIMPA (Windows, IIS, MSSQL, PHP, ASP) has no bearing on this?

Yes LAMP servers do get hacked, yes the majority of internet facing web servers are LAMP servers, and yes LAMP servers get hacked "less" then a WIMPA server despite having a larger install base.

Windows is on the majority of home computers, but this topic isn't about home computers.

Score: 0

|

What a completely wacko statement indicative of someone who understands neither OS design nor SQL injection.

This is an indication of poor programming and security practices.

SQL injection is a fundamental attack and one of the most simple to harden a system against.

Score: 0

|

Dude, LAMP WON'T make headline. Only time when they make headline is when someone company like DELL or HP start including them with their system.

I don't remember when was the last time I read something about LAMP without a big next on the same sentence.

Score: 0

|

"SQL injection is a fundamental attack and one of the most simple to harden a system against."

Really? Then why are there so many patches to fix SQL vulnerabilities in *nix OSes as well as Microsoft's?

"It also said it was in contact with the third party which hosts the UK Web site to improve the security and prevent similar attacks from occurring. It is not known whether the database that was hacked was Microsoft's, although Zone-H speculated that it was MS SQL Server."

Figured that...MS may not have impenetrable servers here in the states, but they definately have enough oversight to notice little things before they get through...they'd of shut out the user's ip address from accessing it before they could have changed the site had it been on Microsoft's servers here in the states...IMO, anyway.

Score: 0

|

IIS.. hahahaha... whew. .. .. .

IIS.. ohh hahahah ha.. ha ha.. oh boy.. wheew..

IIS.. oh ohh hahahahaha ...whoo hooo hoo. ahhh.

Man no matter how many times I hear that joke, it always makes me laugh.

Score: 0

|

Moral of the story:

Smoke less pot, and keep up on your server security (regardless of what platforms you use).

Score: 0

|

I hate when people call these SQL flaws. This is just simple SQL injection caused by people not validating input correctly. If you shoot yourself in the foot its not a flaw in the gun or your shoe, its actually the user of the gun.

Score: 0

|

Well said. Yet because it's MS site, people start to blame IIS & SQL Server.

Having said that, MS should have conducted thorough penetration testing across all its websites. Otherwise people will never take them seriously.

Score: 0

|

Apparently it wasn't Microsoft's direct oversight--remember these servers are hosted by a third party company?

Microsoft.com's servers here in the US used to run off of conxion.com, but they haven't been hacked--at least not that I recall--since they were directly hosted by Microsoft themselves.

Score: 0

|

"Unfortunately, these things happen." ... to sites that run IIS or use weak passwords.

Score: 0

|

Yeah, I'm sure that's how it was hacked--Microsoft always uses simple passwords because they only employ ignorant morons for security-- hence their insignificant market share (/end sarcasm)

Score: 0

|

PDC 2009: What have we learned this week?

There was the freebie that no one will forget, the heebie-jeebies courtesy of Scott Guthrie, and a teensy bit clearer picture of how this cloud thingie should work.

Live report: Will Google Chrome OS change Linux?

The mysteries of just what Chrome OS is, and how much of an operating system it truly is, may be resolved today.

PDC 2009: Microsoft cares about Web browser performance

The effort to give users of the world's dominant Web browser the impression of quality, is a personal one for the man who leads that battle.

Nokia re-affirms its commitment to Symbian, sort of

Maemo won't necessarily be replacing Symbian in the Nokia N-Series, but that's definitely a place where it will be found.

E-book readers will be in short supply this holiday season

E-readers are hot this year, and a lot of compelling new products have been released, but are there enough electrophoretic displays to go around?

Sony looks to finally open a single storefront for downloads

Sony has had many different download portals for movies, music, e-books, and games, and now it's looking to make a single shop for all of it.

Tuning out the tablet: Time to give the endless speculation a rest

Wide Angle Zoom: Wishing and hoping and thinking and praying....won't put an iTablet on the market.

Five improvements for IT managers in 2010

If businesses are to improve their efficiency for next year, they need to stop and reassess the basic tenets of their job.

AOL's spinoff from Time Warner to shed 2,500 jobs

As AOL moves toward become an independent company again, it will cut nearly a third of its workforce.

Gartner: SMS-based money transfer will be bigger than mobile browsing, search

Gartner issues its predictions for the 10 things our phones will be doing in 2012.

Don't forget to upgrade to Firefox 3.6 beta 3 today

Mozilla has released the latest beta its Firefox 3.6 browser software, just over one week after beta 2.