<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-29940404</id><updated>2011-11-07T10:39:20.844-05:00</updated><title type='text'>defacement in the web today</title><subtitle type='html'>current trends and examples of website defacement
*warning: links to mirrors of hacked sites may contain malicious code*</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://digitaldefacement.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/29940404/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://digitaldefacement.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>watching the web</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>25</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-29940404.post-115455126675016518</id><published>2006-08-02T16:25:00.000-04:00</published><updated>2006-08-02T16:41:06.763-04:00</updated><title type='text'>Not quite web defacement but still defacement.</title><content type='html'>&lt;p&gt;Looks like Hezbollah’s Al-Manar television was defaced by Israeli attackers on monday. While its not a website they defaced I would imagine defacing a television broadcast would require quite the amount of work. It isn't yet known for sure what method was used to perform the defacement but regardless of that fact this shows to what extent Israelis are going to in the ongoing Israel-Lebannon conflict&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/29940404-115455126675016518?l=digitaldefacement.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.zone-h.org/content/view/13938/30/' title='Not quite web defacement but still defacement.'/><link rel='replies' type='application/atom+xml' href='http://digitaldefacement.blogspot.com/feeds/115455126675016518/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=29940404&amp;postID=115455126675016518' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/29940404/posts/default/115455126675016518'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/29940404/posts/default/115455126675016518'/><link rel='alternate' type='text/html' href='http://digitaldefacement.blogspot.com/2006/08/not-quite-web-defacement-but-still.html' title='Not quite web defacement but still defacement.'/><author><name>watching the web</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-29940404.post-115437193419305416</id><published>2006-07-31T14:45:00.000-04:00</published><updated>2006-07-31T14:52:23.626-04:00</updated><title type='text'>Yahoo! finance sites victim to attack</title><content type='html'>&lt;p&gt;In the never ending stream of major organizations sites getting hacked Yahoo! is the current victim. Over the weekend the site &lt;a href="http://biz.yahoo.com/"&gt;biz.yahoo.com&lt;/a&gt; was hacked but has recently been fixed. The site normally redirects to &lt;a href="http://finance.yahoo.com/"&gt;finance.yahoo.com&lt;/a&gt; but was instead replaced with what you can find &lt;a href="http://www.zone-h.org/index2.php?option=com_mirrorwrp&amp;Itemid=44&amp;id=4411841"&gt;here&lt;/a&gt;. There were a few subdomains of the finance site hacked as well but they have the same thing displayed. One strange detail of this attack is that the server was running FreeBSD which is usually known for being very secure. The attack was reported, by the attackers, to be a weakness in a 3rd party app but could possibly have been a configuration error as well.&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/29940404-115437193419305416?l=digitaldefacement.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.zone-h.org/content/view/13933/31/' title='Yahoo! finance sites victim to attack'/><link rel='replies' type='application/atom+xml' href='http://digitaldefacement.blogspot.com/feeds/115437193419305416/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=29940404&amp;postID=115437193419305416' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/29940404/posts/default/115437193419305416'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/29940404/posts/default/115437193419305416'/><link rel='alternate' type='text/html' href='http://digitaldefacement.blogspot.com/2006/07/yahoo-finance-sites-victim-to-attack.html' title='Yahoo! finance sites victim to attack'/><author><name>watching the web</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-29940404.post-115411144895120397</id><published>2006-07-28T13:16:00.000-04:00</published><updated>2006-07-28T14:30:49.010-04:00</updated><title type='text'>Look even more NASA defacements</title><content type='html'>&lt;p&gt;Seems like the recent defacements of widely known sites is only increasing in frequency. Now NASA was just defaced but it looks like its happened again... maybe they don't take security very seriously. The two sites &lt;a href="avdc.gsfc.nasa.gov/phpgdv2"&gt;here&lt;/a&gt; (&lt;a href="http://www.zone-h.org/index2.php?option=com_mirrorwrp&amp;Itemid=43&amp;id=4402740"&gt;mirror&lt;/a&gt;) and &lt;a href="avdc1.gsfc.nasa.gov/phpgdv2"&gt; there&lt;/a&gt; (&lt;a href="http://www.zone-h.org/index2.php?option=com_mirrorwrp&amp;Itemid=43&amp;id=4402742"&gt;mirror&lt;/a&gt;) have been fixed as of now so check out the links to the mirrors. The attacks were most definitely politically motivated and are a result of the invasion in Lebanon. Times would appear they've hit the point that real world conflicts have noticeable consequences on the internet as well.&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/29940404-115411144895120397?l=digitaldefacement.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.zone-h.org/content/view/13932/30/' title='Look even more NASA defacements'/><link rel='replies' type='application/atom+xml' href='http://digitaldefacement.blogspot.com/feeds/115411144895120397/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=29940404&amp;postID=115411144895120397' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/29940404/posts/default/115411144895120397'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/29940404/posts/default/115411144895120397'/><link rel='alternate' type='text/html' href='http://digitaldefacement.blogspot.com/2006/07/look-even-more-nasa-defacements.html' title='Look even more NASA defacements'/><author><name>watching the web</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-29940404.post-115394376112055560</id><published>2006-07-26T15:40:00.000-04:00</published><updated>2006-07-26T15:58:17.903-04:00</updated><title type='text'>Netscape defaced...</title><content type='html'>&lt;p&gt;Well in a way. Today &lt;a href="http://www.netscape.com/"&gt;Netscape&lt;/a&gt; was the victim of one of those notorious XSS attacks. The attack wasn't malicious and only made javascript pop-ups that at worse redirected users to &lt;a href="http://digg.com/"&gt;Digg&lt;/a&gt;. Lucky for Netscape it could have been much worse and it wasn't. The good part of this is that they have already fixed the problem, which is much faster than sites usually remedy the issues they have. F-secure has a screenshot on their &lt;a href="http://www.f-secure.com/weblog/archives/archive-072006.html#00000927"&gt;site&lt;/a&gt; if you want to see exactly what it looked like.&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/29940404-115394376112055560?l=digitaldefacement.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://searchsecurity.techtarget.com/originalContent/0,289142,sid14_gci1204568,00.html' title='Netscape defaced...'/><link rel='replies' type='application/atom+xml' href='http://digitaldefacement.blogspot.com/feeds/115394376112055560/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=29940404&amp;postID=115394376112055560' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/29940404/posts/default/115394376112055560'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/29940404/posts/default/115394376112055560'/><link rel='alternate' type='text/html' href='http://digitaldefacement.blogspot.com/2006/07/netscape-defaced.html' title='Netscape defaced...'/><author><name>watching the web</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-29940404.post-115376696031913692</id><published>2006-07-24T12:11:00.000-04:00</published><updated>2006-07-24T14:49:20.430-04:00</updated><title type='text'>some real defacement</title><content type='html'>&lt;p&gt;Over the weekend there were some actual big name defacements. Both of them are the result of an SQL injection vulnerability. I'm in no way surprised about this as these issues have been popping up all over the web recently. The more problems actually arise as a result of SQL injection I hope will lead to everyone looking at them as the much more serious problem that they actually are.&lt;/p&gt;&lt;p&gt;The first page hacked was &lt;a href="shopping.msn.com.sg/"&gt;Microsoft MSN of Singapore&lt;/a&gt; (&lt;a href="http://www.zone-h.org/index2.php?option=com_mirrorwrp&amp;Itemid=44&amp;id=4376766"&gt;mirror&lt;/a&gt;)  site specifically the shopping subdomain. While it happened on Saturday the hacked page still seems to be up now which is two days later. Second was a subdomain of the &lt;a href="http://technology.grc.nasa.gov/success/success.asp?cat=all"&gt;NASA site&lt;/a&gt; (&lt;a href="http://www.zone-h.org/index2.php?option=com_mirrorwrp&amp;Itemid=44&amp;id=4372830"&gt;mirror&lt;/a&gt;). Third was not from an SQL injection but rather a vulnerability with the CMS software but it was the women page of the &lt;a href="http://iwomen.msn.co.il"&gt;Microsoft MSN of Israel&lt;/a&gt; (&lt;a href="http://www.zone-h.org/index2.php?option=com_mirrorwrp&amp;Itemid=43&amp;id=4380853"&gt;mirror&lt;/a&gt;) site.&lt;/p&gt;&lt;p&gt;Two defacements for Microsoft over the same weekend. I'm sure that makes them feel just great about themselves. Maybe they'll get around to securing all their different sites around the world at some point in the near future.&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/29940404-115376696031913692?l=digitaldefacement.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://digitaldefacement.blogspot.com/feeds/115376696031913692/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=29940404&amp;postID=115376696031913692' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/29940404/posts/default/115376696031913692'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/29940404/posts/default/115376696031913692'/><link rel='alternate' type='text/html' href='http://digitaldefacement.blogspot.com/2006/07/some-real-defacement.html' title='some real defacement'/><author><name>watching the web</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-29940404.post-115342021243309500</id><published>2006-07-20T14:26:00.000-04:00</published><updated>2006-07-20T14:30:12.450-04:00</updated><title type='text'>dont forget cron jobs</title><content type='html'>&lt;p&gt;Read something rather amusing today yet it still had a bit of advice. After somebody had their server hacked and used for a phishing site he of course removed it. Even though he removed it he got a call the next day about it still being there. Turns out the attacker setup a cron job to recreate the phishing page each day if it does not exist. Luckily he had savy enough friends to help him find this out otherwise it may have been an endless amount of headaches for him. Moral of the story, keep an eye on your cron jobs.&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/29940404-115342021243309500?l=digitaldefacement.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://ha.ckers.org/blog/20060720/phishing-cron-job/' title='dont forget cron jobs'/><link rel='replies' type='application/atom+xml' href='http://digitaldefacement.blogspot.com/feeds/115342021243309500/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=29940404&amp;postID=115342021243309500' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/29940404/posts/default/115342021243309500'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/29940404/posts/default/115342021243309500'/><link rel='alternate' type='text/html' href='http://digitaldefacement.blogspot.com/2006/07/dont-forget-cron-jobs.html' title='dont forget cron jobs'/><author><name>watching the web</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-29940404.post-115325821799410028</id><published>2006-07-18T17:24:00.000-04:00</published><updated>2006-07-18T17:30:18.006-04:00</updated><title type='text'>XSS via proxies</title><content type='html'>&lt;p&gt;Cross-site scripting is bad enough and causes plenty of problems when implemented in the traditional way. After reading the post and his &lt;a href="http://jeremiahgrossman.blogspot.com/2006/07/devil-made-me-do-it.html"&gt;friend's&lt;/a&gt; I realize how horrible the consequences really could be if attacks like this were carried out. Let's hope nothing like these attacks ever becomes widespread.&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/29940404-115325821799410028?l=digitaldefacement.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://ha.ckers.org/blog/20060718/attacking-applications-via-xss-proxies/' title='XSS via proxies'/><link rel='replies' type='application/atom+xml' href='http://digitaldefacement.blogspot.com/feeds/115325821799410028/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=29940404&amp;postID=115325821799410028' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/29940404/posts/default/115325821799410028'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/29940404/posts/default/115325821799410028'/><link rel='alternate' type='text/html' href='http://digitaldefacement.blogspot.com/2006/07/xss-via-proxies.html' title='XSS via proxies'/><author><name>watching the web</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-29940404.post-115315696145595290</id><published>2006-07-17T13:08:00.000-04:00</published><updated>2006-07-17T13:31:10.590-04:00</updated><title type='text'>myspace attack spreading quickly</title><content type='html'>&lt;p&gt;Myspace seems to be the place to be these days with all those users, music, and an attack spreading at very high speed. The attack is flash based and will redirect users to a blog with a 9/11 rant. After that the flash is embedded into that users profile and it will continue to spread in such a manner. The &lt;a href="http://chaseandsam.com/2006/07/myspace-hack-spreading-like-wildfire.html"&gt;attack details&lt;/a&gt; and also the &lt;a href="http://kinematictheory.phpnet.us/"&gt;exploit details&lt;/a&gt; have been posted to the net already so go give them a read if you'd like to know more about the specifics. While it can be removed and is mostly just annoying, could this be a hint of things to come? If so I can only imagine attacks becoming much more malicious in the future.&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/29940404-115315696145595290?l=digitaldefacement.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.securitypronews.com/insiderreports/insider/spn-49-20060717MySpaceFlashAttackCorruptsProfiles.html' title='myspace attack spreading quickly'/><link rel='replies' type='application/atom+xml' href='http://digitaldefacement.blogspot.com/feeds/115315696145595290/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=29940404&amp;postID=115315696145595290' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/29940404/posts/default/115315696145595290'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/29940404/posts/default/115315696145595290'/><link rel='alternate' type='text/html' href='http://digitaldefacement.blogspot.com/2006/07/myspace-attack-spreading-quickly.html' title='myspace attack spreading quickly'/><author><name>watching the web</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-29940404.post-115315562099669126</id><published>2006-07-17T09:51:00.000-04:00</published><updated>2006-07-17T13:24:44.526-04:00</updated><title type='text'>analyzing a cyber-terrorism defacement</title><content type='html'>&lt;p&gt;I've just discovered that &lt;a href="http://www.beyondsecurity.com/"&gt;Beyond Security&lt;/a&gt; has done an &lt;a href="http://www.beyondsecurity.com/besirt/advisories/team-evil-incident.pdf"&gt;analysis **PDF file**&lt;/a&gt; of a recent cyber-terrorism web defacement. The analysis is quite in depth and technical but if you're up for the challenge its very interesting because you don't get a chance to see this sort of analysis too often.&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/29940404-115315562099669126?l=digitaldefacement.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://blogs.securiteam.com/index.php/archives/510' title='analyzing a cyber-terrorism defacement'/><link rel='replies' type='application/atom+xml' href='http://digitaldefacement.blogspot.com/feeds/115315562099669126/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=29940404&amp;postID=115315562099669126' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/29940404/posts/default/115315562099669126'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/29940404/posts/default/115315562099669126'/><link rel='alternate' type='text/html' href='http://digitaldefacement.blogspot.com/2006/07/analyzing-cyber-terrorism-defacement.html' title='analyzing a cyber-terrorism defacement'/><author><name>watching the web</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-29940404.post-115288908358730218</id><published>2006-07-14T09:53:00.000-04:00</published><updated>2006-07-14T10:58:03.673-04:00</updated><title type='text'>Vulnerabilities in CMS</title><content type='html'>&lt;p&gt;If you're one of the many people who use Mambo or Joomla as the content management system for your website you're going to want to be careful. There's a perl bot on the loose that exploits components of both Mambo and Joomla. SimpleBoard and perForms are the two components which bots were found to be currently exploiting. The most vulnerabilities are in the third part components so even though the core of the CMS may be quite secure you'll want to watch out what other components you're using with it.&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/29940404-115288908358730218?l=digitaldefacement.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://isc.sans.org/diary.php?storyid=1483' title='Vulnerabilities in CMS'/><link rel='replies' type='application/atom+xml' href='http://digitaldefacement.blogspot.com/feeds/115288908358730218/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=29940404&amp;postID=115288908358730218' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/29940404/posts/default/115288908358730218'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/29940404/posts/default/115288908358730218'/><link rel='alternate' type='text/html' href='http://digitaldefacement.blogspot.com/2006/07/vulnerabilities-in-cms.html' title='Vulnerabilities in CMS'/><author><name>watching the web</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-29940404.post-115256672704256345</id><published>2006-07-10T17:10:00.000-04:00</published><updated>2006-07-10T17:25:27.053-04:00</updated><title type='text'>Google searches inside executables</title><content type='html'>&lt;p&gt;Seems Websense has actually done something other than block every other website on the net. In the last month they have managed to find 2000 malicious sites using Google's binary search. The search allowed them to look inside executables (.exe) code and determine if some of them were trojans. Many of these were posted as something helpful on forms and newsgroups hoping to lure users into running them. Hopefully sites are aware that they might unknowingly have malicious code posted to their site if they have a forum or wiki setup. If a security company can use google to find this malicious code so should the webmasters. A Google search of "Signature: 00004550Â will result in many different executables and viewing a result as html will allow you to see some information about that executable. I would suggest searching your own site to make sure you don't have any executables you're not aware of that could have been remnats of someone hacking/defacing your site. "site:&lt;span style="font-style:italic;"&gt;yoursite&lt;/span&gt; Signature: 00004550" should do the trick.&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/29940404-115256672704256345?l=digitaldefacement.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.securitypronews.com/news/securitynews/spn-45-20060710WebsenseandGoogleIdentifyThousandsofMaliciousSites.html' title='Google searches inside executables'/><link rel='replies' type='application/atom+xml' href='http://digitaldefacement.blogspot.com/feeds/115256672704256345/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=29940404&amp;postID=115256672704256345' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/29940404/posts/default/115256672704256345'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/29940404/posts/default/115256672704256345'/><link rel='alternate' type='text/html' href='http://digitaldefacement.blogspot.com/2006/07/google-searches-inside-executables.html' title='Google searches inside executables'/><author><name>watching the web</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-29940404.post-115229352189425193</id><published>2006-07-07T11:43:00.000-04:00</published><updated>2006-07-07T13:32:01.960-04:00</updated><title type='text'>Even More Defacements</title><content type='html'>&lt;p&gt;Today it looks like the &lt;a href="http://ws-i.novell.com/delta.html"&gt;Novel&lt;/a&gt; site was defaced. Right now all that's on that site is the text "&lt;Delta Hacking&gt;". While it may only be a subdomain, that is the norm when it comes to defacements. Recently it seems like many big companies' sites are always getting defaced. People keep finding vulnerabilities faster than companies are able to patch them yet not many of the attacks are on main sites but rather just a subdomain that no one would be navigating to in the first place. Attacks like these are definitely not trying to convey any important kind of message.&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/29940404-115229352189425193?l=digitaldefacement.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://digitaldefacement.blogspot.com/feeds/115229352189425193/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=29940404&amp;postID=115229352189425193' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/29940404/posts/default/115229352189425193'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/29940404/posts/default/115229352189425193'/><link rel='alternate' type='text/html' href='http://digitaldefacement.blogspot.com/2006/07/even-more-defacements.html' title='Even More Defacements'/><author><name>watching the web</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-29940404.post-115221620744589672</id><published>2006-07-06T15:50:00.000-04:00</published><updated>2006-07-06T16:11:15.703-04:00</updated><title type='text'>Google vulnerability closed</title><content type='html'>&lt;p&gt;Seems it took less than a day for the vulnerability Google had with their feed reader to be &lt;a href="http://news.zdnet.com/2100-1009_22-6090974.html?part=rss&amp;tag=feed&amp;subj=zdnn"&gt;closed&lt;/a&gt;. This was quite the relief because I realize so many people trust Google without really thinking about it and the quick fix didn't give anybody a chance to exploit the hole with a cross site scripting attack.&lt;/p&gt;
&lt;p&gt;The &lt;a href="http://ha.ckers.org/"&gt;blogger and security expert&lt;/a&gt; that went full disclosure with the issue still isn't entirely happy as the problem with redirects he's also talked about hasn't been touched in six months. In addition he doesn't sound like he would repeat the even with all the problems and hassle it created for him. Many people contacted him and called him a Google hater but he knows he's not and life goes on. Hopefully Google doesn't have another problem like this since it looks like one person who could find it might not be looking&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/29940404-115221620744589672?l=digitaldefacement.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://ha.ckers.org/blog/20060706/google-disclosure-fallout/' title='Google vulnerability closed'/><link rel='replies' type='application/atom+xml' href='http://digitaldefacement.blogspot.com/feeds/115221620744589672/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=29940404&amp;postID=115221620744589672' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/29940404/posts/default/115221620744589672'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/29940404/posts/default/115221620744589672'/><link rel='alternate' type='text/html' href='http://digitaldefacement.blogspot.com/2006/07/google-vulnerability-closed.html' title='Google vulnerability closed'/><author><name>watching the web</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-29940404.post-115221540190812813</id><published>2006-07-05T14:55:00.000-04:00</published><updated>2006-07-06T15:50:01.916-04:00</updated><title type='text'>Vulnerability with google</title><content type='html'>&lt;p&gt;What better way to celebrate the 4th of July than with a vulnerability in Google's site? No, that could never happen. While I definitely know some believe Google can do no wrong and never has problems with their site, not everyone is going to agree. Recent developments may show reason would have to show otherwise. Looks like a cross site scripting attack could allow someone to do a multitude of unwanted things. Collecting all sorts of information that may be stored in cookies or in a persons google account by using cross site scripting to setup a login page. Why would you login to a page like this? Well, maybe it looks like some new Google beta and you just have to try it out. By the time you realize its not real its already too late. Beyond that, exploiting page rank by using the vulnerability is a possibility as well.&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/29940404-115221540190812813?l=digitaldefacement.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://ha.ckers.org/blog/20060704/cross-site-scripting-vulnerability-in-google/' title='Vulnerability with google'/><link rel='replies' type='application/atom+xml' href='http://digitaldefacement.blogspot.com/feeds/115221540190812813/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=29940404&amp;postID=115221540190812813' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/29940404/posts/default/115221540190812813'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/29940404/posts/default/115221540190812813'/><link rel='alternate' type='text/html' href='http://digitaldefacement.blogspot.com/2006/07/vulnerability-with-google.html' title='Vulnerability with google'/><author><name>watching the web</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-29940404.post-115211499164541959</id><published>2006-07-03T11:19:00.000-04:00</published><updated>2006-07-07T13:36:25.623-04:00</updated><title type='text'>A dissertation on Hacktivism</title><content type='html'>&lt;p&gt;While her PhD dissertation has been online for nearly 2 months I just recently stumbled upon it. &lt;a href="http://www.alexandrasamuel.com/about.html"&gt;Alexandra Samuel&lt;/a&gt; has made her entire dissertation, &lt;a href="http://www.alexandrasamuel.com/dissertation"&gt;Hacktivism and the Future of Political Participation&lt;/a&gt;, available to the public. The dissertation is very long but has a wealth of information on politically motivated hacking among other things. If you have the time and interest I would suggest giving it a read.&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/29940404-115211499164541959?l=digitaldefacement.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.alexandrasamuel.com/20060510/now-available-hacktivism-the-future-of-political-participation' title='A dissertation on Hacktivism'/><link rel='replies' type='application/atom+xml' href='http://digitaldefacement.blogspot.com/feeds/115211499164541959/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=29940404&amp;postID=115211499164541959' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/29940404/posts/default/115211499164541959'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/29940404/posts/default/115211499164541959'/><link rel='alternate' type='text/html' href='http://digitaldefacement.blogspot.com/2006/07/dissertation-on-hacktivism.html' title='A dissertation on Hacktivism'/><author><name>watching the web</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-29940404.post-115161180037682589</id><published>2006-06-29T15:56:00.000-04:00</published><updated>2006-06-29T16:10:00.386-04:00</updated><title type='text'>Jihad on the internet</title><content type='html'>&lt;p&gt;The conflict between Israelis and Palestinians seems to have moved, at least in part, to the digital front. In response to an operation by Israel Defense Forces, Islamic hackers took down greater than 700 sites with the .co.il extension. The sites were replaced with the message &lt;a href="http://213.219.122.11/en/defacements/mirror/id=4210157/"&gt;"Hacked By Team-Evil Arab hackers u KIll palestin people we kill Israel servers"&lt;/a&gt;.&lt;/p&gt;&lt;p&gt;I can only see something like this expanding in the future to become even more widespread and common. While from here in the states it may not seem too dire, if our banks and hospitals sites are going down in addition to other companies there could be serious problems.&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/29940404-115161180037682589?l=digitaldefacement.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://digitaldefacement.blogspot.com/feeds/115161180037682589/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=29940404&amp;postID=115161180037682589' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/29940404/posts/default/115161180037682589'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/29940404/posts/default/115161180037682589'/><link rel='alternate' type='text/html' href='http://digitaldefacement.blogspot.com/2006/06/jihad-on-internet.html' title='Jihad on the internet'/><author><name>watching the web</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-29940404.post-115161099122705527</id><published>2006-06-28T18:25:00.000-04:00</published><updated>2006-06-29T15:56:31.250-04:00</updated><title type='text'>don't mess with pirates</title><content type='html'>&lt;p&gt;If you've been out of the loop or don't care to pay much attention then you may not have heard about the fiasco with thepiratebay.org. Back at the beginning of this month they were raided by the sweedish police and their servers were confisgated. They only ended up being down for 3 days. It turned out that the MPAA had encouraged the sweedish goverment to make this all happen in lengthy discussions. Members of the piratebay.org community or possibly the sweedish pirate party took it upon themselves to &lt;a href="http://news.bbc.co.uk/1/hi/technology/5041848.stm"&gt;take down&lt;/a&gt; the Sweedish police's website after the event. Those Sweedes are pretty serious about their copyright reform, so much so they have a political party with serious backing that wants to do something about it and it even ended up on &lt;a href="http://www.youtube.com/watch?v=m6DBn0BncMk"&gt;tv&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;The new news is that a sweedish newspaper now revealed the full letter that was signed by the directory of anti-piracy in the MPAA. Apparently political lobbying knows no borders.&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/29940404-115161099122705527?l=digitaldefacement.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.zone-h.org/content/view/13787/30/' title='don&apos;t mess with pirates'/><link rel='replies' type='application/atom+xml' href='http://digitaldefacement.blogspot.com/feeds/115161099122705527/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=29940404&amp;postID=115161099122705527' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/29940404/posts/default/115161099122705527'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/29940404/posts/default/115161099122705527'/><link rel='alternate' type='text/html' href='http://digitaldefacement.blogspot.com/2006/06/dont-mess-with-pirates.html' title='don&apos;t mess with pirates'/><author><name>watching the web</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-29940404.post-115144026463033766</id><published>2006-06-25T19:04:00.000-04:00</published><updated>2006-06-27T17:00:45.213-04:00</updated><title type='text'>update on Ohio University's security breach</title><content type='html'>&lt;p&gt;Looks like there is some more information on the huge breach at OU. The tidbit I found most revolting is that the Computing and Network Services had an average of a 1.4 million dollar annual surplus over the past ten years. Not only is that money that could have been spent better securing their systems but there was still that much left after giving their employees special benefits like health club benefits which other university empolyees were not receiving.&lt;/p&gt;
&lt;p&gt;The board of trustees approved of 4 million to secure university computers so it seems somebody there realized they would actually have to do something about it. Hopefully the network staff can either handle it or they find somebody that will.&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/29940404-115144026463033766?l=digitaldefacement.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://news.yahoo.com/s/ap/20060624/ap_on_hi_te/university_data_theft_2' title='update on Ohio University&apos;s security breach'/><link rel='replies' type='application/atom+xml' href='http://digitaldefacement.blogspot.com/feeds/115144026463033766/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=29940404&amp;postID=115144026463033766' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/29940404/posts/default/115144026463033766'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/29940404/posts/default/115144026463033766'/><link rel='alternate' type='text/html' href='http://digitaldefacement.blogspot.com/2006/06/update-on-ohio-universitys-security.html' title='update on Ohio University&apos;s security breach'/><author><name>watching the web</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-29940404.post-115109404777271486</id><published>2006-06-23T11:33:00.000-04:00</published><updated>2006-06-27T16:36:50.526-04:00</updated><title type='text'>how easy is it to learn to deface websites</title><content type='html'>I decided to look around and see how easy it is to find small explanations for defacing websites. First page of the google search brought up to pretty good ones. The first one &lt;a href="http://blogs.securiteam.com/index.php/archives/105"&gt;here&lt;/a&gt; is not actually a tutorial but rather an explanation of how websites are usually defaced and under what circumstances it occurs. It may not explicitly tell you how to do it but it is an interesting read. The second was more descriptive but I still don't think these along could get somebody going on defacing websites. Still &lt;a href="http://www.acm.uiuc.edu/sigmil/talks/webtrash/webtrashtalk.html"&gt;#2&lt;/a&gt; is worth the read if you don't know much about how defacement occurs and would like some simple examples.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/29940404-115109404777271486?l=digitaldefacement.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://digitaldefacement.blogspot.com/feeds/115109404777271486/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=29940404&amp;postID=115109404777271486' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/29940404/posts/default/115109404777271486'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/29940404/posts/default/115109404777271486'/><link rel='alternate' type='text/html' href='http://digitaldefacement.blogspot.com/2006/06/how-easy-is-it-to-learn-to-deface.html' title='how easy is it to learn to deface websites'/><author><name>watching the web</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-29940404.post-115101089675583144</id><published>2006-06-22T17:03:00.000-04:00</published><updated>2006-06-22T17:15:40.476-04:00</updated><title type='text'>nobody wants to trust you when you're compromised</title><content type='html'>&lt;p&gt;While this isnt really a case of website defacement it is an unwanted system intrusion. Ohio University had 173,000 ssn and 60,000 medical records accessed on a system that was obviously not very secure. Why might it be obvious? Well that would be the fact it took 13 months for anyone to discover the breach in security occured. Now this may be an extreme example of when something like this happens but it does happen. If you have lots of confidential information on your network it is vitally important to protect that information. In this case an alumni even took a hefty donation to the university out of her will and on top of the loss of trust 2 million has already been spent on the universities audit trying to find out what really happened. Any breach like this will create a rift between you and your users where a strong trust may have been before. Things like this should never take that long to detect but it really shows you how you have to closely watch all any secure information stored on your network.&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/29940404-115101089675583144?l=digitaldefacement.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.tmcnet.com/usubmit/2006/06/19/1686625.htm' title='nobody wants to trust you when you&apos;re compromised'/><link rel='replies' type='application/atom+xml' href='http://digitaldefacement.blogspot.com/feeds/115101089675583144/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=29940404&amp;postID=115101089675583144' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/29940404/posts/default/115101089675583144'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/29940404/posts/default/115101089675583144'/><link rel='alternate' type='text/html' href='http://digitaldefacement.blogspot.com/2006/06/nobody-wants-to-trust-you-when-youre.html' title='nobody wants to trust you when you&apos;re compromised'/><author><name>watching the web</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-29940404.post-115100581275630779</id><published>2006-06-22T11:49:00.000-04:00</published><updated>2006-07-05T12:02:20.633-04:00</updated><title type='text'>hackers, blackhat and whitehat</title><content type='html'>&lt;p&gt;So what incentive do these hackers with technical knowledge have in discovering vulnerabilities and publishing the information? I believe you can divide them into two different groups. There are those who do it because they want to help in getting the problem fixed by making everyone aware it exists and how it works and are trying to help out the web community in general by doing so. While they have good intentions, those intentions cannot stop would be criminals from taking what they've discovered and using it maliciously. On the other hand are those who discover the security hole and may or may not want the problem fixed and they release it in a way that may be easier to use maliciously against websites or to people they know will use it in such a way. The latter are the ones you need to worry about because they don't care about the well being of the web and could care less about everyone's websites being defaced by the script kiddies.&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/29940404-115100581275630779?l=digitaldefacement.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://digitaldefacement.blogspot.com/feeds/115100581275630779/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=29940404&amp;postID=115100581275630779' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/29940404/posts/default/115100581275630779'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/29940404/posts/default/115100581275630779'/><link rel='alternate' type='text/html' href='http://digitaldefacement.blogspot.com/2006/06/hackers-blackhat-and-whitehat.html' title='hackers, blackhat and whitehat'/><author><name>watching the web</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-29940404.post-115100313510609589</id><published>2006-06-21T21:04:00.000-04:00</published><updated>2006-06-22T15:06:20.263-04:00</updated><title type='text'>who's doing the defacement</title><content type='html'>&lt;p&gt;You may wonder why so many web defacements seem so petty and juvenile. Most of them get nothing across except that they "hacked" the site and have their hacker handles all over the site. The main reason behind this is because the real hackers are the ones that find the vulnerabilities. When they find the vulnerability they may publish some proof of concept or exploit code. A large majority of the time they do nothing and it moves down to someone who writes a program for it or a script that runs the exploit code to take advantage of a vulnerable system. Then the script kiddies, who have no real knowledge of their own and just run the programs, get a hold of this and are the ones that do most of the damage around the web.&lt;/p&gt;
&lt;p&gt;While occasionally its not the kiddies and somebody that knows what they're doing will hack into a system and deface a site, it is much less common. Because of this the best way to defend against a defacement is to keep up on all security updates and patches on your system. Usually if you have everything updated the the old tools that the script kiddies have are not going to be effective and you can avoid the majority of defacements&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/29940404-115100313510609589?l=digitaldefacement.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://digitaldefacement.blogspot.com/feeds/115100313510609589/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=29940404&amp;postID=115100313510609589' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/29940404/posts/default/115100313510609589'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/29940404/posts/default/115100313510609589'/><link rel='alternate' type='text/html' href='http://digitaldefacement.blogspot.com/2006/06/whos-doing-defacement.html' title='who&apos;s doing the defacement'/><author><name>watching the web</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-29940404.post-115092290812684743</id><published>2006-06-20T10:44:00.000-04:00</published><updated>2006-06-22T15:10:52.676-04:00</updated><title type='text'>updates about the microsoft defacement</title><content type='html'>&lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;&lt;p&gt;The microsoft defacement of the site experts.microsoft.fr from the &lt;a href="http://digitaldefacement.blogspot.com/2006/06/microsoft-france-was-hacked.html"&gt;last post&lt;/a&gt; has had some more information released about it. First of all microsoft's initial investigation into the issue pointed, as a likely cause, to a misconfigured web server hosted by a third party. When the company gets more information on the issue they will post it to their &lt;a href="http://blogs.technet.com/msrc/default.aspx"&gt;MSCR blog&lt;/a&gt;. On the other end of the issue, the attacker revealed that a vulnerable .net nuke script was the hole they used for the attack. In addition to that the attacker admitted his motive was revenge for a Windows XP upgrade that broke his system. Hardly sounds like a class act with top notch computing skills but its not as if thats a huge surprise.&lt;/p&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/29940404-115092290812684743?l=digitaldefacement.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://digitaldefacement.blogspot.com/feeds/115092290812684743/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=29940404&amp;postID=115092290812684743' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/29940404/posts/default/115092290812684743'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/29940404/posts/default/115092290812684743'/><link rel='alternate' type='text/html' href='http://digitaldefacement.blogspot.com/2006/06/updates-about-microsoft-defacement.html' title='updates about the microsoft defacement'/><author><name>watching the web</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-29940404.post-115075073567247569</id><published>2006-06-19T16:55:00.000-04:00</published><updated>2006-06-19T16:58:55.683-04:00</updated><title type='text'>microsoft france was hacked</title><content type='html'>&lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;&lt;p&gt;Somehow I managed to miss earlier that Microsoft was hacked over the weekend albeit the main site was not the target. A subdomain of the Microsoft France site was the actual site to be defaced. The site was &lt;a href="http://experts.microsoft.fr/default.aspx"&gt;http://experts.microsoft.fr/default.aspx&lt;/a&gt; which will lead you nowhere right now. A mirror of the hacked site can be seen &lt;a href="http://www.zone-h.org/index2.php?option=com_mirrorwrp&amp;amp;id=4181592"&gt;here&lt;/a&gt;. From the body of the hacked site it would appear that this group's next target is microsoft.com. When the site of a technology company of this size is defaced it really has to make you worry that most sites are potentially targets.&lt;/p&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/29940404-115075073567247569?l=digitaldefacement.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://digitaldefacement.blogspot.com/feeds/115075073567247569/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=29940404&amp;postID=115075073567247569' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/29940404/posts/default/115075073567247569'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/29940404/posts/default/115075073567247569'/><link rel='alternate' type='text/html' href='http://digitaldefacement.blogspot.com/2006/06/microsoft-france-was-hacked.html' title='microsoft france was hacked'/><author><name>watching the web</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-29940404.post-115073844016716915</id><published>2006-06-19T12:34:00.000-04:00</published><updated>2006-06-19T17:03:29.743-04:00</updated><title type='text'>website defacement, still an issue today</title><content type='html'>&lt;p&gt;Recently I have been under the impression that no one worried about website defacement anymore. Yes, many probably remember hearing much more about it in the 90's especially when really big sites like Yahoo! were defaced. Defacement does still happen regularly but usually its to smaller sites that are not as renowned because internet security has become a much more pertinent issue in this newfangled web we have today.&lt;/p&gt;
&lt;p&gt;This does not mean that bigger sites are impervious to defacement attacks. After a little looking around I found some sites that have been defaced recently. Links to mirrors of the sites while they were defaced follow.
&lt;ul&gt;&lt;li&gt;The Argentina Volkswagen &lt;a href="http://www.zone-h.org/index2.php?option=com_mirrorwrp&amp;Itemid=44&amp;amp;id=4156069"&gt;site&lt;/a&gt;&lt;/li&gt;&lt;li&gt;A &lt;a href="http://www.zone-h.org/index2.php?option=com_mirrorwrp&amp;Itemid=44&amp;amp;id=3690847"&gt;lab&lt;/a&gt; in the Harvard Medical School&lt;/li&gt;&lt;li&gt;The Kansas Department of Agriculture (&lt;a href="http://www.zone-h.org/index2.php?option=com_mirrorwrp&amp;Itemid=44&amp;amp;id=3690847"&gt;ksda&lt;/a&gt;)&lt;/li&gt;&lt;/ul&gt;
Even though defacement may not find its way into mainstream news anymore it is definitely still a problem to be dealt with.&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/29940404-115073844016716915?l=digitaldefacement.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://digitaldefacement.blogspot.com/feeds/115073844016716915/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=29940404&amp;postID=115073844016716915' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/29940404/posts/default/115073844016716915'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/29940404/posts/default/115073844016716915'/><link rel='alternate' type='text/html' href='http://digitaldefacement.blogspot.com/2006/06/website-defacement-still-issue-today.html' title='website defacement, still an issue today'/><author><name>watching the web</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry></feed>
