Information Security News mailing list archives

Security Firm's Site Defaced


From: William Knowles <wk () C4I ORG>
Date: Fri, 1 Dec 2000 04:34:48 -0600

http://www.wired.com/news/business/0,1367,40445,00.html

by Michelle Delio
2:40 p.m. Nov. 30, 2000 PST

Crackers have entered and defaced two websites belonging to Network
Associates, the company that bills itself as the world's largest
independent network security company.

The intruders splattered a montage of bilingual cyber-graffiti over
two of the company's Brazilian-based websites, www.nai.com.br and
www.mcafee.com.br.

The crack has been attributed to a group called Insanity Zine Corp.

Network Associates media spokeswoman Jennifer Kavney said that Network
Associates itself was not cracked, but Matrix, the ISP that hosts the
company's Brazilian websites, was breached and this allowed the
attackers access to Network Associates sites.

"To make matters worse they hacked in through a known vulnerability,
which Matrix had received a patch for on November 7 and evidently
never applied," said Kavney in disgust.

Kavney said this was a "nuisance hack" and stressed that there was no
actual penetration of Network Associates' websites or databases.

"There was no damage to our systems, no destruction of data, no
exposure of any of our information."

The crackers reportedly entered the sites early on Thursday morning
(EST) and redecorated, tossing up sentences that poked fun at Network
Associates security and anti-virus software tools, and claiming
ownership of the site.

They also added a few personal sentiments like "God Save the Script
Kiddies."

Reaction to the attack in hacking circles has been mixed.

"I hate to see any site defaced, OK, because I believe in hacking not
cracking," said a "subterranean security expert" who goes by the name
of MunkeebIz.

MunkeebIz noted that "hacking is exploration, and cracking is
exploitation."

"But you gotta give props to the people who can crack a computer
security site. It's like shooting a porn film at the Vatican while the
pope looks on in wonder."


*==============================================================*
"Communications without intelligence is noise;  Intelligence
without communications is irrelevant." Gen Alfred. M. Gray, USMC
================================================================
C4I.org - Computer Security, & Intelligence - http://www.c4i.org
*==============================================================*

ISN is hosted by SecurityFocus.com
---
To unsubscribe email LISTSERV () SecurityFocus com with a message body of
"SIGNOFF ISN".


Current thread: