De novo, Microsoft desfigurada

02/08/2008 Written by Marcelo Almeida (Vympel)

billg_casuallNova­mente a Microsoft teve seus sites des­fig­u­ra­dos por uma falha de Injeção de SQL. Poucos dias atrás o defacer con­hecido como Agd_​scorp, des­fig­urou 6 web­sites da Microsoft, todos por uma falha de SQL no código dos sites.
Alguns anos atrás, a Microsoft era o alvo preferido dos defac­ers que que­riam “divul­gar” o Linux, hoje em dia, com a adoção em massa do Linux eles pref­erem ape­nas a “fama” de invadir um site famoso. Nos sites o defacer Agd_​Scorp ape­nas deixou uma men­sagem dizendo que o site tinha sido invadido.

O mesmo defacer vem ata­cando sites famosos nos últi­mos dias (por exem­plo https://​dol​.hqda​.pen​ta​gon​.mil) todos por SQL Injec­tion, em uma clara demon­stração que empre­sas famosas e sites do Gov­erno não estão dando a dev­ida atenção ao código fonte de seus sites, ou seus admin­istradores não tem a menor idéia do que sig­nifica segurança…


Abaixo segue os links de algu­mas invasões aos sites da Microsoft:

Date Attacker Flags Domain OS View
2008/​07/​28 R  …ner​.microsoft​.co​.kr/​p​d​s​/​n​e​w​_​p​d​s​_​l​i​s​t.asp Win 2003  View Mirror
2008/​07/​28 M  microsoft​.com​.mk/​L​i​c​e​n​c​i​ranje Win 2003  View Mirror
2008/​07/​28 H M win​dowsxp​.com​.mk Win 2003  View Mirror
2008/​07/​28 microsoft​.com​.al Win 2003  View Mirror
2008/​06/​20 microsoft​-press​.dk Win 2003  View Mirror
2008/​06/​20 H M  microsoft​press​.dk Win 2003  View Mirror
2008/​02/​05 microsoft​.com​.tr Win 2003  View Mirror
2006/​06/​18 experts​.microsoft​.fr/​d​e​f​a​u​l​t​.aspx Win 2003  View Mirror
2007/​04/​29 ieak​.microsoft​.com/​1​.​0​/​N​e​w​L​i​c​e​n​s​e​e.asp Win 2000  View Mirror
2007/​03/​10   …t.co.kr/msdn/Notice/Notice_View_List.asp Win 2000  View Mirror
2007/​06/​27 …events/net/eventdetail.aspx?eventid=8399 Win 2003  View Mirror
2005/​07/​06   microsoft​.co​.uk/​A​p​o​c​a​l​y​p​s​e.gif Win 2003  View Mirror
2005/​08/​31 part​ner​.microsoft​.co​.kr/​m​a​p​/​g​b​r.asp Win 2000  View Mirror
2004/​03/​30 H M  mem​ber​.microsoft​.co​.kr Win 2000  View Mirror
2004/​03/​30 reg​is​ter​.microsoft​.co​.kr/​i​n​d​e​x.htm Win 2000  View Mirror
2004/​05/​25 microsoft​.com/​m​s​p​r​e​ss/uk Win 2003  View Mirror
2002/​03/​25 cust​-supp​-chat​.one​.microsoft​.com Windows  View Mirror
2002/​03/​16 office​coun​cil​.rte​.microsoft​.com Win NT9 View Mirror
2002/​03/​13 office​coun​cil​.rte​.microsoft​.com/fp Win 2000  View Mirror
2002/​03/​10 olab2​.research​.microsoft​.com Windows  View Mirror
2001/​06/​22 arulk​.rte​.microsoft​.com Windows  View Mirror
2001/​06/​21 red​sand​.rte​.microsoft​.com Windows  View Mirror
2001/​05/​09 streamer​.microsoft​.com Windows  View Mirror
2001/​05/​04 microsoft​.co​.uk Windows  View Mirror


Lista com­pleta dos domínios Microsoft invadidos:

2005-​05-​11 00:20:24 Unknown Core http://​www​.microsoft​.com​.mx/​c​g​i-bin
2004-​03-​29 01:58:58 c0d3rz http://​reg​is​ter​.microsoft​.co​.kr/​i​n​d​e​x.htm
2004-​05-​25 04:42:26 Out­Law http://​www​.microsoft​.com/​m​s​p​r​e​ss/uk
2004-​05-​16 17:24:47 isko­r­pitx http://​www​.microsoft​.com​.mx/​c​g​i-bin
2003-​11-​09 18:24:30 Affix http://​www​.microsoft​.pl
2002-​03-​16 11:00:00 Per​fect​.br http://​office​coun​cil​.rte​.microsoft​.com 
2002-​03-​13 11:31:34 Sil­ver Lords http://​office​coun​cil​.rte​.microsoft​.com/fp
2001-​04-​27 17:35:31 WoH http://​www​.microsoft​.com​.gr
2001-​01-​23 15:19:07 Prime Sus­pectz http://​www​.microsoft​.co​.nz
2001-​04-​21 03:55:23 Prime Sus­pectz http://​www​.microsoft​.com​.gr
2001-​05-​04 02:01:22 Prime Sus­pectz http://​www​.microsoft​.co​.uk
2001-​05-​04 23:59:01 Prime Sus­pectz http://​www​.microsoft​.com​.mx
2001-​05-​09 00:22:40 Prime Sus­pectz http://​streamer​.microsoft​.com
2001-​05-​10 01:34:35 Prime Sus­pectz http://​pc​.microsoft​.is
2001-​06-​21 17:56:07 Prime Sus­pectz http://​red​sand​.rte​.microsoft​.com
2001-​05-​18 16:10:44 pen­ta­guard http://​www​.microsoft​.ro
2001-​07-​27 10:21:37 m0sad http://​www​.microsoft​.com​.sa
2000-​01-​08 07:18:39 inferno​.br http://​www​.microsoft​.com​.tw
2001-​05-​13 11:04:35 cr1m3 0rg4n1z4d0 http://​www​.microsoft​.nsk​.ru
2000-​12-​19 08:53:25 BoLoDoRiO http://​www​.microsoft​.si
2001-​06-​20 06:33:33 Black­Sun http://​www​.inter​face​.microsoft​.co​.za
2001-​04-​20 05:38:35 BLACK-​FUUUUUUUU http://​www​.microsoft​.be
2005-​07-​06 00:37:02 Apoc­a­lypse http://​www​.microsoft​.co​.uk/​A​p​o​c​a​l​y​p​s​e.gif
2005-​08-​12 08:05:13 Apoc­a­lypse http://​ftp​.microsoft​.pa​.no/​i​n​d​e​x.htm
2005-​08-​30 23:17:47 G.B.R TEAM http://​part​ner​.microsoft​.co​.kr/​m​a​p​/​g​b​r.asp
2006-​04-​24 06:22:53 Simiens http://​blogs​.microsoft​.co​.il
2006-​06-​18 19:19:41 TiTHacK http://​experts​.microsoft​.fr/​d​e​f​a​u​l​t​.aspx
2004-​03-​30 07:40:25 r00t_​system http://​mem​ber​.microsoft​.co​.kr
2003-​11-​09 18:24:30 Affix http://​www​.microsoft​.com​.pl
2002-​12-​06 14:56:17 Crime Per­fect http://​www​.microsoft​.co​.yu/​c​r​i​m​e​p​e​r​f​e​c​t​.html
2002-​03-​24 11:00:00 Sil­ver Lords http://​cust​-supp​-chat​.one​.microsoft​.com 
2002-​03-​25 03:25:37 Sil­ver Lords http://​cust​-supp​-chat​.one​.microsoft​.com
2002-​03-​16 15:41:57 Per​fect​.Br http://​office​coun​cil​.rte​.microsoft​.com
2002-​03-​10 07:04:29 Sil­ver Lords http://​olab2​.research​.microsoft​.com
2001-​05-​05 02:53:48 Prime Sus­pectz http://​www​.microsoft​.com​.sa
2001-​06-​22 00:40:18 Prime Sus­pectz http://​arulk​.rte​.microsoft​.com
2000-​06-​04 03:15:28 InSaN­iTy ZiNe c0rp. http://www.microsoft.com.br
2000-​12-​15 05:47:19 Furia​.BR http://​www​.microsoft​.si
2007-​03-​10 02:50:59 black­wolf http://​reg​is​ter​.microsoft​.co​.kr/​m​s​d​n​/​N​o​t​i​c​e​/​N​o​t​i​c​e​_​V​i​e​w​_​L​i​s​t.asp
2007-​04-​28 19:33:02 Cyber-​Terrorist http://​ieak​.microsoft​.com/​1​.​0​/​N​e​w​L​i​c​e​n​s​e​e.asp
2007-​06-​26 22:07:33 rEmOtEr http://​www​.microsoft​.co​.uk/​e​v​e​n​t​s​/​n​e​t​/​e​v​e​n​t​d​e​t​a​i​l​.​a​s​p​x​?​e​v​e​n​t​i​d​=8399
2007-​10-​18 18:48:49 mdx http://​web03​.microsoft​.se/​p​o​r​t​f​olio/
2007-​12-​19 22:53:44 SPY-​CX5 http://​www​.microsoft​.com​.tr
2008-​07-​23 18:50:06 Agd_​Scorp http://​www​.microsoft​.com​.mk/​L​i​c​e​n​c​i​ranje
2008-​07-​23 18:53:52 Agd_​Scorp http://​www​.microsoft​.com​.al
2008-​07-​28 00:57:45 Agd_​Scorp http://​part​ner​.microsoft​.co​.kr/​p​d​s​/​n​e​w​_​p​d​s​_​l​i​s​t.asp




Share this content: