You are here: silicon.com > Software > Security Strategy

Security Strategy

Microsoft.co.uk defaced

Hackers brandish their virtual spray cans...

Tags: hackers, deface, microsoft.co.uk, microsoft

By Tom Espiner

Published: 3 July 2007 08:47 BST

Details have emerged of an attack which defaced Microsoft's UK website.

Hackers broke through the site's security, defacing it and replacing genuine content with a photo of a child waving a Saudi Arabian flag.

It is likely that Microsoft.co.uk, which was breached on Wednesday, was subverted using SQL injection, according to security website Zone-H, which has also run a picture of the defacement. "Most probably, the attacker exploited the site by means of SQL injection to insert HTML code in a field belonging to the table which gets read every time a new page is generated," said Zone-H on its site.

Microsoft said it is investigating the breach. It said in a statement: "Microsoft has learned of a criminal attempt to deface a sub-site of Microsoft.com. Upon notification of the criminal activity, Microsoft took the appropriate action to resolve the issue and stop any additional criminal activity.

"Microsoft is not currently aware of any customer impact as a result of this criminal activity but will continue to investigate the incident and take any necessary action to help protect customers. In addition, the defaced website was restored to its original content within hours.

"We apologise if customers are inconvenienced by the unavailability of the affected website. Microsoft is committed to helping protect our customers and we're working diligently with the third-party hosting company to ensure the continued security of the website."

Ed Gibson, Microsoft UK's chief security advisor, played down the impact of the security breach. "I think it's always difficult when any company suffers from an intrusion by a criminal organisation," he said. "As to the question of long-standing damage - [Microsoft will not suffer], because that particular matter was cleaned up quickly.

"Criminals are always trying to steal or break into systems - it shows we can't be complacent. By all of us working as an industry to make the [ecosystem] better, we'll continue to make it better tomorrow. Unfortunately these things happen."

Patrick McLaughlin, the European director of security solutions at database company Oracle, said "software can never be fully tested".

He added: "When building commercial software for databases, there's a finite amount of time to test it - software is never bug-free." It is understood that it was not an Oracle database that was subverted.

Tom Espiner writes for ZDNet UK

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

Martin Brampton Brampton Factor: Open source stands up for its rights Copyright can keep the movement alive...

Bob Tarzey The rise and rise of Infor Quocirca's Straight Talking: Where next for the apps giant?


  • Jobs
Do you want to be an oil TRADER ?? London

Due to the nature of this role you will gain an excellent understanding of all areas of the business and as you are sitting on the trading floor you ...

Energy Product Control Analyst, Leading Energy Trading Major

In this product control position your activities will include the daily reporting of profit and loss generated by the trading teams and the ...

Systems Analyst London Up to 65,000

The role will include taking overall responsibility for testing activity within an IT development project. Additional responsibilities will also ...

CIO50 2008
The silicon.com CIO50 2008 profiles the most influential and innovative tech chiefs in the UK across all industries and organisation size, from the biggest FTSE100 companies to high growth dot-com start ups and the public sector. The list was voted on by the UK CIO community and a panel of experts. Find out more in our latest special report.





Quick Sitemap Links: