Hello all,
Have you read this press release where the Microsoft France site was hacked:
http://blog.washingtonpost.com/securityfix/2006/06/microsoft_site_defacement_spur_1.html
Does anyone know if this was caused by the BDPDT flaw issue that was identified a while ago, or is this a different security flaw?
From the Press Release:
First thoughts were: "initial investigation points to a mis-configuration of a web server at
a third party hosting facility as the most likely cause of the
compromise. Upon completion of our investigation more information
regarding the cause will be posted to the
MSRC blog."
And on:
Update, 10:35 a.m. ET, June 20: Web site defacement archive
Zone-h.org posted
a follow-up today on this break-in, where they apparently interviewed the guy that attacked Microsoft's site. According to Zone-H co-author
Roberto Preatoni, the hacker broke in using an unpatched flaw in
DotNetNuke
an open-source content management system designed to interact with
ASP.NET, a Web development language from Microsoft. I left a message
with the people over at DotNetNuke, but no word yet on whether they're
aware of this issue.
"The attacker revealed that he exploited a
.net script 0day vulnerability after discovering that expert.microsoft.fr had installed and was running a vulnerable .net nuke script.
This
hole allowed the attacker to gain the same rights as the script, and
that was enough to to upload a FSO script, a kind of shell used by the
attacker to create a new folder and upload the defacement. "