Korean Microsoft Site Hax0red
Results 1 to 2 of 2

Thread: Korean Microsoft Site Hax0red

  1. #1
    Master-Jedi-Pimps0r & Moderator thehorse13's Avatar
    Join Date
    Dec 2002
    Washington D.C. area

    Korean Microsoft Site Hax0red

    Yep, earlier today if you went here: (there is a space in the URL on purpose)

    http:// news.msn.co.kr/image/banner/bbs003302.css

    You would get a downloader trojan. At the bottom of the site there is an iframe statement

    <iframe height=0 width=0 src="../../image/banner/list.htm"></iframe>
    list.htm loads bbs003302.gif with basically runs down a list of javascript exploits in attempts to run the above css file.

    At the moment, I get 404 errors for the .css and .gif file but the iframe statement is still there. MS was notified and apparently acted *extremely* fast.

    Anyway, happy Tuesday and look for some kind of story on this to appear in the upcomming days...

    Symantec picked up the trojan as PWSteal.Lineage

    Our scars have the power to remind us that our past was real. -- Hannibal Lecter.
    Talent is God given. Be humble. Fame is man-given. Be grateful. Conceit is self-given. Be careful. -- John Wooden

  2. #2
    the beign of authority kurt_der_koenig's Avatar
    Join Date
    Jan 2004

    Microsoft admits MSN site hacked in South Korea


    Microsoft acknowledged Thursday that hackers booby-trapped its popular MSN Web site in South Korea to try to steal passwords from visitors. The company said it was unclear how many Internet users might have been victimized.
    Microsoft said it cleaned the Web site, www.msn.co.kr, and removed the dangerous software code that unknown hackers had added earlier this week. A spokesman, Adam Sohn, said Microsoft was confident its English-language Web sites were not vulnerable to the same type of attack.

    South Korea is a leader in high-speed Internet users worldwide. Microsoft's MSN Web properties which offer news, financial advice, car- and home-buying information and more are among the most popular across the Web.

    The affected Microsoft site in South Korea offers news and other information plus links to the company's free e-mail and search services. Its English-language equivalent is the default home Internet page for the newest versions of its flagship Windows software sold in the United States.

    The Korean site, unlike U.S. versions, was operated by another company Microsoft did not identify. Microsoft's own experts and Korean police authorities were investigating, but Microsoft believes the computers were vulnerable because operators failed to apply necessary software patches, said Sohn, an MSN director.

    "Our preliminary opinion here was, this was the result of an unpatched operating system," Sohn said. "When stuff is in our data center, it's easier to control. We're pretty maniacal about getting servers patched and keeping our customers safe and protected."

    Microsoft's acknowledgment of the hacking incident was the latest embarrassment for the world's largest software company, which has spent hundreds of millions of dollars to improve security and promote consumer confidence in its products.

    Security researchers noticed the suspicious programming added to the Korean site and contacted the company Tuesday. Microsoft traced the problem and removed the hacked computers within hours, Sohn said, but it doesn't yet know how long the dangerous programming was present.

    In recent days no customers have reported problems stemming from visits to the Web site, Sohn said.

    The hacker program scanned visitors' computers and tried to activate password-stealing software that was found separately to exist on some hacked Chinese Web sites.

    Microsoft said it was trying to decide whether to issue a broad public warning to recent visitors of the Korean site as it examines its own records to attempt to trace anyone who might have been victimized.

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts