Hacker wrecks 175 websites, leaves Facebook fan link

Permission slip opens exploit

An audacious hacker has defaced 175 Australian websites in an attack that links viewers to his personal website, email and Facebook fan page.

The hacker, who is described as a 26 year old male from Tunisia, launched the attacks after a Brisbane hosting provider — which Computerworld Australia will not name — left a permission level too low on an Apache server.

A manager at the provider said the exploit was present in an obscure program on the provider’s servers, which the hacker used in the mass defacements that included the hosting provider’s websites.

The hacker provided links to his Facebook, Myspace and Blogger accounts, along with a phone number based in Romania.

Some websites appeared to still experience problems, while others were functioning normally.

Last month, 159 Australian websites were hijacked and vandalised after a hacker gained administrative access to the Direct Admin server management system used by a hosting provider.

In May, former strategic chief information officer for the Commonwealth of Pennsylvania, Bob Maley, said defacements could be seen as examples of slack security derived from isolated security management. He acknowledged defacements are "low-hanging fruit" in terms of the risk of exposure to sensitive data, and said websites become vulnerable to similar attacks when security is tackled in isolation by agencies.

We understand disclosure and discretion are top of mind for organisations that have endured a data breach. Tell Computerworld Australia and help your colleagues protect themselves. All tip-offs remain anonymous. Contact us here.

More about: Apache, Facebook
References show all

Comments

Post new comment

The content of this field is kept private and will not be shown publicly.
Users posting comments agree to the Computerworld comments policy.
Login or register to link comments to your user profile, or you may also post a comment without being logged in.
Related Coverage
Related Whitepapers
Latest Stories
Community Comments
Tags: defacements, exploits and vulnerabilities, network access control (NAC)
Whitepapers
All whitepapers
Sign up now to get free exclusive access to reports, research and invitation only events.
Featured Download
/downloads/product/133/feeddemon/

FeedDemon

FeedDemon is an easy-to-use RSS reader for Windows which will keep you informed with the latest news and information. The Google Reader Synchronization allows you ...

Computerworld newsletter

Join the most dedicated community for IT managers, leaders and professionals in Australia