<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>DDoSed.com - An IT security information blog &#187; Defacements</title>
	<atom:link href="http://www.ddosed.com/category/defacements/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.ddosed.com</link>
	<description></description>
	<lastBuildDate>Sat, 04 Oct 2008 07:21:19 +0000</lastBuildDate>
	
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Jun 2007 &#8211; Feb 2008 U.S. Gov Website Defacements + Commentary</title>
		<link>http://www.ddosed.com/2008/04/05/jun-2007-to-feb-2008-us-gov-website-defacements-commentary/</link>
		<comments>http://www.ddosed.com/2008/04/05/jun-2007-to-feb-2008-us-gov-website-defacements-commentary/#comments</comments>
		<pubDate>Sat, 05 Apr 2008 12:32:10 +0000</pubDate>
		<dc:creator>D1m</dc:creator>
				<category><![CDATA[Defacements]]></category>
		<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Hacktivism]]></category>
		<category><![CDATA[crackers]]></category>
		<category><![CDATA[frontpage extensions]]></category>
		<category><![CDATA[gov defaces]]></category>
		<category><![CDATA[mirror archive]]></category>
		<category><![CDATA[php inclusion]]></category>
		<category><![CDATA[script kiddies]]></category>
		<category><![CDATA[sql injection]]></category>
		<category><![CDATA[website defacements]]></category>
		<category><![CDATA[zone-h]]></category>

		<guid isPermaLink="false">http://www.ddosed.com/?p=51</guid>
		<description><![CDATA[Below is a list of US governmental websites which were defaced by crackers &#8211; or elite hackers as the media would say &#8211; since 26th of June 07 until late February 2008. It is quite interesting to know that most of the security vulnerabilities affecting the following *.gov websites are known for some years now.

buckinghamcounty.virginia.gov [...]]]></description>
			<content:encoded><![CDATA[<p align="justify">Below is a list of US governmental websites which were defaced by crackers &#8211; or elite hackers as the media would say &#8211; since 26th of June 07 until late February 2008. It is quite interesting to know that most of the security vulnerabilities affecting the following *.gov websites are known for some years now.</p>
<p align="justify"><span id="more-51"></span></p>
<p align="justify"><a title="buckinghamcounty.virginia.gov - Archived at Zone-H.org" href="http://www.zone-h.org/index2.php?option=com_mirrorwrp&amp;Itemid=44&amp;id=6529007" target="_blank">buckinghamcounty.virginia.gov</a> &#8211; IIS5.0 on Win 2000 &#8211; Defaced by a Turkish cracker. Possibly he successfully exploited the FrontPage extensions misconfiguration vulnerability. He added his e-mail address. Of course if you contact him to ask what was the method used to deface, most probably he is going to reply that was a 0day vulnerability. What a stupid thing to do (add contact details). I am not going to explain why. He should work his own mind. I&#8217;m sure that at some point he is going to check this blog post because his nickname (<span class="category">UyuSsman</span>) will be soon enough indexed in search engines&#8230; <img src='http://www.ddosed.com/wp-includes/images/smilies/icon_razz.gif' alt=':P' class='wp-smiley' /> </p>
<p align="justify"><a title="genome.nasa.gov/delivery/affy-C2wPDrGz - Archived at Zone-H.org" href="http://www.zone-h.org/index2.php?option=com_mirrorwrp&amp;Itemid=44&amp;id=6514459">genome.nasa.gov/delivery/affy-C2wPDrGz</a> &#8211; Apache on Linux &#8211; Defaced by an Algerian cracker. Exploited an open door left in a web application. It is NASA! Automatically becomes teh uber h4&#215;0r. LOL. Worths admiring l33t skills that even my grandma could use.</p>
<p align="justify"><a href="http://www.zone-h.org/index2.php?option=com_mirrorwrp&amp;Itemid=44&amp;id=6555137" target="_blank">williamsburgva.gov/uk/4ever.htm</a> &#8211; IIS6.0 on Win 2003 &#8211; Another deface by a Turkish cracker. You can contact him via MSN, just add turkishmember@yahoo.com.br!!! Obviously he is collaborating with Brazilian defacers. Without collaboration he wont be able to climb his way up on Zone-H&#8217;s hall of shame board for special defacements.</p>
<p align="justify"><a href="http://www.zone-h.org/index2.php?option=com_mirrorwrp&amp;Itemid=44&amp;id=6499258" target="_blank">cncsoig.gov/cum.htm</a> &#8211; IIS6.0 on Win 2003 &#8211; Defaced by a cracker from Panama. Silly him, named the defaced page &#8220;cum.htm&#8221;. Notice to how many people sends greets. You can find him at <a href="irc://irc.gigachat.org:6667">irc.GigaChat.net</a> [<em>Now down for some reason</em>] #core-project, #whackerz, #Xtech, #Segfault &#8211; where all the l33t peeps are idling and privately exchanging messages about their achievements. In this defacement there is a reference to the recent <a title="Chilean Crackers Caught - Zone-H.org News - November 2006" href="http://www.zone-h.org/content/view/14321/30/" target="_blank">arrest</a> of four Chilean crackers who were members of the &#8220;Byond Hackers Team&#8221;. Most probably the defaced page was influenced from watching too many h4&#215;0r movies! h0h0.</p>
<p align="justify"><a href="http://www.zone-h.org/component/option,com_mirrorwrp/Itemid,160/id,6469760/" target="_blank">dialog.cancer.gov</a> &#8211; IIS5.0 on Win 2000 &#8211; Defaced by crackers from the Dominican Republic. They seem to know how to exploit basic SQL injection vulnerabilities. They just defaced the page with the message &#8220;D.O.M TEAM 2007 === xarnuz === &#8220;. No specific reason for their deface. Just for fun I guess. Surely showing off their team and nicknames to the defacers underground community.</p>
<p align="justify"><a href="http://www.zone-h.org/component/option,com_mirrorwrp/Itemid,160/id,6469685/" target="_blank">ncilistens.cancer.gov</a> &#8211; IIS5.0 on Win 2000 &#8211; Defaced by Brazilian crackers. Exploited an SQL injection vulnerability to add &#8220;Hacked by AciDmuD &#8211; RitualistaS GrouP&#8221;. They also added a contact e-mail address.</p>
<p align="justify"><a href="http://www.zone-h.org/component/option,com_mirrorwrp/Itemid,160/id,6498853/" target="_blank">cncsig.gov</a> &#8211; IIS6.0 on Win 2003 &#8211; Defaced by Brazilian crackers. Funny thing they call their team &#8220;<span class="defaulttext">linuXploit_crew&#8221;. That means they exploit Linux boxes as well. OMG! Those guys must be uber-l33t0r. So ultimate respect for them. They support that hacking is not a crime. I certainly agree, but what they did is not hacking but cracking, and this is illegal aka a crime. </span></p>
<p align="justify"><a href="http://www.zone-h.org/component/option,com_mirrorwrp/Itemid,160/id,6457557/" target="_blank">whitecounty-il.gov</a><a href="http://www.zone-h.org/component/option,com_mirrorwrp/Itemid,160/id,6457557/" target="_blank">/index.html</a> Win 2003<br />
woolwichnj.gov &#8211; Apache on Linux &#8211; Defaced by Brazilian crackers. Possibly exploited a PHP inclusion vulnerability, called a remote command shell script, checked with &#8220;uname -a&#8221; that the kernel is vulnerable to a local root exploit, run wget to download a backdoor to a writable directory, run the backdoor, telneted to the specific backdoor port, run wget to download <a title="h00lyshit.c" href="http://archives.neohapsis.com/archives/fulldisclosure/2006-07/att-0310/h00lyshit.c" target="_blank">h00lyshit</a> or <a title="raptor_prctl2.c" href="http://www.milw0rm.com/exploits/2031" target="_blank">prctl</a> local root kernel exploits, tested successfully one of the local root exploits, got root, owned the web server. They didn&#8217;t even spell right the word &#8220;owned&#8221; in the defaced page. Quite possibly, maybe they even tried to deceive by changing the kernel version in the defaced page. They would look more l33t that way: &#8220;2.6.16-1.2111_FC5smp #1 SMP Thu May 4 21:35:09 EDT 2006 &#8220;.</p>
<p align="justify"><a href="http://www.zone-h.org/component/option,com_mirrorwrp/Itemid,160/id,6406440/" target="_blank">armenia.ca.gov</a> &#8211; Apache on Linux &#8211; Defaced by a cracker from Saudi Arabia. This guy seems to know who he is, not a hacker, but a &#8220;R00T Cracker&#8221;. ROFL! Even that, maybe he is lying. Could be a &#8220;UID=APACHE Cracker&#8221;. You can contact him &#8220;For Mor Security&#8221; at S4curity@HotMail.Com and Admin@611.Com. This cracker used the same exploitation methodology as the Brazilian group above. No further commentary for this deface&#8230; <img src='http://www.ddosed.com/wp-includes/images/smilies/icon_razz.gif' alt=':-P' class='wp-smiley' /> <span style="color: #c0c0c0; font-size: large;"> </span></p>
<p><a href="http://www.zone-h.org/component/option,com_mirrorwrp/Itemid,160/id,6399444/" target="_blank">arb.ca.gov/research</a> &#8211; Apache on Linux &#8211; Defaced by crackers from Brazil.</p>
<p>Concluding this commentary, all of the above defacements were a result of the following security vulnerabilities which were already known &#8211; some for many years now.</p>
<p>- <a title="SQL Injection Cheat Sheet" href="http://ferruh.mavituna.com/makale/sql-injection-cheatsheet/" target="_blank">SQL injections</a> (programming mistake)</p>
<p>- <a title="PHP Undergroud Security - PlayHack.net" href="http://www.playhack.net/view.php?type=1&amp;id=22" target="_blank">PHP inclusion</a> (programming mistake)</p>
<p>- <a href="http://www.ddosed.com/uploads/penetration_testing/webfolders.txt" target="_blank">FrontPage Extensions</a> (misconfiguration)</p>
<p align="justify">Windows or Unix with enabled FrontPage extensions could be vulnerable due to misconfiguration. If vulnerable, open the target domain or ip as web folder and you are in its webroot. It is very possible that you have write access. What if such misconfiguration exists in a web server which hosts thousand of sites and supports server side languages as ASP and PHP? Attackers can upload scripts which allow them to mass deface in few seconds all the hosted sites, run backdoors, download confidential data if any, use server as part of their botnet and erase all the log files. The best solution is to totally disable FrontPage extensions.</p>
<p align="justify"><a title="Written by soznic" href="http://www.ddosed.com/uploads/penetration_testing/webfolders.txt" target="_blank">Read this text</a> for more detailed information about web folders and FrontPage extensions.</p>
<p>- <a href="http://seclists.org/fulldisclosure/2005/Jan/0032.html" target="_blank">Microsoft Data Access Internet Publishing Provider DAV 1.1</a> and <a title="mod_dav: a DAV module for Apache" href="http://www.webdav.org/mod_dav/" target="_blank">mod_dav</a> (misconfiguration)</p>
<p align="justify">Attackers can import a list of high-profiled domains and check against if they allow PUT requests. Using the PoC for this vuln, they can PUT /theirdeface.htm to the webroot of the vulnerable domains. They can even PUT /ntdaddy.asp or other shorter in size web administration scripts in order to grant complete access to the web server. Also Linux web servers with mod_dav could be vulnerable.</p>
<p>The sysadmins, webmasters and web developers surely learnt their lesson. It is always the human factor to blame first for any occurrence  of security breaches.</p>
<p>Quite ironic that gov systems are consistently attacked by confused script-kiddies. After all for them is just &#8220;show off&#8221; game.</p>
<p>More U.S. governmental defacements submitted to Zone-H by the crackers:</p>
<blockquote><p>DigitalMind       woolwichnj.gov              Linux<br />
ArREs           vil.prentice.wi.gov             Linux<br />
S4udi-S3curity-T3rror   armenia.ca.gov          Linux<br />
Apocalypse        cncsoig.gov/cum.htm       Win 2003<br />
D.O.M            dialog.cancer.gov             Win 2000<br />
RitualistaS       ncilistens.cancer.gov     Win 2000<br />
linuXploit_crew   cncsig.gov                     Win 2003<br />
Kript3X        bowmar.gov/hacked.htm      Win 2003<br />
soyletmez        https://sc-isac.sc.gov      Win 2003<br />
SegmentationFault ops.sgp.arm.gov             Win 2000<br />
SegmentationFault nevadatreasurer.gov             Win 2000<br />
SuZuki        commerce.idaho.gov              Win 2003<br />
SuZuki            community.idaho.gov             Win 2003<br />
XTech Inc       lmhc.la.gov                     Win 2003<br />
XTech Inc       lmhc.louisiana.gov             Win 2003<br />
Phantom Orchid       cstx.gov/home             Win 2000<br />
BiyoSecurityTeam  roundrocktexas.gov             Win 2003<br />
S4t4n1c_s0uls        csac.ca.gov/doc.asp              Win 2003<br />
RootDamages       vacsp.gov/news.cfm             Win 2003<br />
beyrut-KaI3uS       vivote.gov                     Win 2003<br />
PowerDream        leesburgva.gov/pwd.htm      Win 2003<br />
SuZuki            remember.gov                     Win 2000<br />
S4udi-S3curity-T3rror     armenia.usaid.gov     Linux<br />
sinaritx        doe.nv.gov                      Win 2003<br />
s@bun           secure.sc.gov//LexSheriff     Win 2003<br />
W4n73d_H4ck3r       senegal.usaid.gov             Win 2000<br />
DigitalMind       seagrantdev.noaa.gov             Linux<br />
W4n73d_H4ck3r       admin.fmcs.gov             Win 2003<br />
W4n73d_H4ck3r       fmcs.gov                     Win 2003<br />
DigitalMind       seagrantdev.noaa.gov             Win 2000<br />
DigitalMind       seagrantdev.noaa.gov             Win 2000</p></blockquote>
<p>and many other that we don&#8217;t know about&#8230;</p>
<p>View the mirrors of the defaced sites on Zone-H and if you want add a comment below:<br />
<a title="U.S. Governmental Website Defacements on Zone-H.org" href="http://old.zone-h.org/en/defacements/special/filter/filter_domain=gov " target="_blank">http://old.zone-h.org/en/defacements/special/filter/filter_domain=gov </a></p>
<p>Clearly they &#8220;promoted&#8221; themselves to the script kiddies scene with a &#8220;wannabe an elite defacer, thats why I deface .gov/s and publish them on Zone-H&#8221; attitude. Of course they will never admit to this and continue to feed their bogus pride until is jail time!! <img src='http://www.ddosed.com/wp-includes/images/smilies/icon_razz.gif' alt=':P' class='wp-smiley' /> </p>
<p>Nuff said.</p>
<script type="text/javascript">
  addthis_url    = 'http%3A%2F%2Fwww.ddosed.com%2F2008%2F04%2F05%2Fjun-2007-to-feb-2008-us-gov-website-defacements-commentary%2F';
  addthis_title  = 'Jun+2007+%26%238211%3B+Feb+2008+U.S.+Gov+Website+Defacements+%2B+Commentary';
  addthis_pub    = 'dpan';
</script><script type="text/javascript" src="http://s7.addthis.com/js/addthis_widget.php?v=12" ></script>
]]></content:encoded>
			<wfw:commentRss>http://www.ddosed.com/2008/04/05/jun-2007-to-feb-2008-us-gov-website-defacements-commentary/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>How Crackers Deface Websites? Why They Do It?</title>
		<link>http://www.ddosed.com/2007/08/09/how-crackers-deface-websites-why-they-do-it/</link>
		<comments>http://www.ddosed.com/2007/08/09/how-crackers-deface-websites-why-they-do-it/#comments</comments>
		<pubDate>Thu, 09 Aug 2007 01:33:04 +0000</pubDate>
		<dc:creator>D1m</dc:creator>
				<category><![CDATA[Defacements]]></category>
		<category><![CDATA[Hacktivism]]></category>
		<category><![CDATA[Penetration Testing]]></category>
		<category><![CDATA[Personal Opinions]]></category>
		<category><![CDATA[Security Articles]]></category>

		<guid isPermaLink="false">http://www.ddosed.com/2007/08/09/how-crackers-deface-websites-why-they-do-it/</guid>
		<description><![CDATA[Through the following post I am not purposing to influence you to start defacing, but to briefly give you a better understanding of how and why it is done.
Almost everyday I visit Zone-H&#8217;s archive of special digital attacks, I find that at least 1 or 2 attacks were done against US governmental web servers. The domain suffix of [...]]]></description>
			<content:encoded><![CDATA[<p align="justify">Through the following post I am not purposing to influence you to start defacing, but to briefly give you a better understanding of how and why it is done.</p>
<p align="justify">Almost everyday I visit Zone-H&#8217;s <a target="_blank" href="http://www.zone-h.org/component/option,com_attacks/Itemid,43/" title="Zone-H.org Digital Attacks Archive">archive</a> of special digital attacks, I find that at least 1 or 2 attacks were done against US governmental web servers. The domain suffix of the defaced websites was *.gov. Does this fact means that they are totally secure? I don&#8217;t think so&#8230; Obviously the web servers may host very confidential data. In this case the web server administrators seemed to have allowed threats against governmental assets. Any unwanted consequences that a breach of security can lead to, are mainly caused by the irresponsibility and lazyness of system administrators and web developers.</p>
<p align="justify"><span id="more-50"></span></p>
<p align="justify">The methodology for defacing a website is pretty standard. Here is the standard sequence of tasks that normally the crackers/defacers would follow: <a target="_blank" href="http://en.wikipedia.org/wiki/Footprinting" title="Wikipedia.org - Footprinting">Footprinting</a>, <a href="http://netsecurity.about.com/cs/hackertools/a/aa030404.htm" title="Introduction to Vulnerability Scanning">scanning</a>, enumeration, penetration, attack, covering of tracks and installation of backdoors. As I mentioned before, the motivations for defacing any website are various, whereas when defacing governmental websites, could be a promotion of an ideology, revenge, or just a challenge.</p>
<p align="justify">I don&#8217;t believe that people who are serial website defacers hold good real-life jobs, or any job at all. This is just my personal opinion which is based on the fact that defacing is illegal in most countries &#8211; thus involving a high risk of getting arrested - and requires some basic knowledge, time, and patience. Advanced knowledge of technical and theoretical network security issues is not always required to deface. I think that understanding IT security theories, enhances intelligently your logical application of related practicalities. Achieving a deface could require the application of a complex exploitation methodology. This is enough reason to give up for some defacers without patience and with incomplete knowledge.</p>
<p align="justify">Tools assisting each step mentioned in the last paragraph are widely available for free on the internet. Most of the authors coded them for ethical, legal and educational use. Of course some were specifically coded for easily generating domain lists, exploiting security vulnerabilities, and mass-defacing websites. These are not easy to find on the web, nor are that difficult to code. Instead, individual defacers and groups exchange them in IRC channels, private forums  and servers, and through instant messengers.</p>
<p>One example of such an IRC server is irc.gigachat.net.</p>
<p align="justify">Script kiddies who deface, prefer to use fancy GUIs for tools rather than command line. Command line tools seem to exceed their learning and memory capabilities, or they don&#8217;t have the will and patience to research and analyze effective methodologies used by professionals in netsec pen-testing. They would be more technically skilled and better exercise their brain to remember simple and complex command sequences in multi-OS environments. Plus they would develop their practical skill-set which may be necessary if they choose to follow an IT career at some point &#8211; if they don&#8217;t end up in jail.</p>
<p align="justify">Depending on their ethical and legal attitudes, usually what they want is to quickly accomplish breaking in a network, maybe lookup for confidential data, download them and deface the home pages of hosted sites. Always counting in exceptions, most probably they didn&#8217;t use their own exploits, but what was already public.</p>
<p>Now I&#8217;m going to quote from another of my posts the following:</p>
<p align="justify">&#8220;In the mind and soul of the crackers who deface high-profiled websites, there is a false sense of pride. They think that it reflects their cracking skills and status in the defacers scene. For them defacing is more like a game. The messages shown in their defacements are more like an excuse for taking part in this game. The real motivation and reasoning behind their attacks, in most of the cases is not political, patriotic or other; but is just to show off themselves and their country to the world…</p>
<p align="justify">They attach a nickname to their personalities and cracking abilities, and they try to raise its status in the scene. They like searching for their nicknames in news websites and showing off the link to other crackers in their IRC channel, other channels, or through their websites.&#8221;</p>
<p align="justify">You will be ignored if you request mentioned tools or help to deface a website. Comments are welcome of course. <img src='http://www.ddosed.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<p align="justify">&nbsp;</p>
<script type="text/javascript">
  addthis_url    = 'http%3A%2F%2Fwww.ddosed.com%2F2007%2F08%2F09%2Fhow-crackers-deface-websites-why-they-do-it%2F';
  addthis_title  = 'How+Crackers+Deface+Websites%3F+Why+They+Do+It%3F';
  addthis_pub    = 'dpan';
</script><script type="text/javascript" src="http://s7.addthis.com/js/addthis_widget.php?v=12" ></script>
]]></content:encoded>
			<wfw:commentRss>http://www.ddosed.com/2007/08/09/how-crackers-deface-websites-why-they-do-it/feed/</wfw:commentRss>
		<slash:comments>8</slash:comments>
		</item>
		<item>
		<title>XSSed.com: What, Who, Why?</title>
		<link>http://www.ddosed.com/2007/03/06/xssedcom-what-who-why/</link>
		<comments>http://www.ddosed.com/2007/03/06/xssedcom-what-who-why/#comments</comments>
		<pubDate>Tue, 06 Mar 2007 13:28:35 +0000</pubDate>
		<dc:creator>D1m</dc:creator>
				<category><![CDATA[Defacements]]></category>
		<category><![CDATA[Security News]]></category>
		<category><![CDATA[XSS]]></category>

		<guid isPermaLink="false">http://www.ddosed.com/2007/03/06/xssedcom-what-who-why/</guid>
		<description><![CDATA[The goals of XSSed.com are to provide informative resources on cross-site scripting(XSS) vulnerabilities and exploitation methodologies, and to archive XSS vulnerable websites for statistic purposes. Mirroring websites is a way to prove to vendors and webmasters that the vulnerability really existed &#8211; in case of denial. Users will become more aware on protecting themselves on [...]]]></description>
			<content:encoded><![CDATA[<p align="justify">The goals of <a href="http://www.xssed.com" title="XSSed.com - XSS information and vulnerable websites archive" target="_blank">XSSed.com</a> are to provide informative resources on cross-site scripting(XSS) vulnerabilities and exploitation methodologies, and to archive XSS vulnerable websites for statistic purposes. Mirroring websites is a way to prove to vendors and webmasters that the vulnerability really existed &#8211; in case of denial. Users will become more aware on protecting themselves on some websites, as XSS vulnerabilities are mostly targeting the users and not the websites.</p>
<p align="justify">XSSed.com is also an attempt to spread education and awareness about XSS to IT professionals and amateurs involved or interested in secure web application development.</p>
<p><span id="more-40"></span></p>
<p>The project is run by Kevin Fernandez and Dimitris Pagkalos.<br />
There are still a lot of improvements in the TODO list including the ones listed below:<br />
<strong> -RSS feeds.<br />
-Search filters.<br />
-More statistics.<br />
-Submit POST data in the submission page.<br />
-Add public and protected informations with the submitted XSS (more details will soon be available).<br />
-Additional informations will be published on the mirror page (for instance the use of a specific browser to reproduce the vulnerability).</strong></p>
<p align="justify"><a href="http://www.xssed.com/submit" title="XSSed.com - Submit XSS vulnerable websites" target="_blank">Submitting XSS</a> vulnerable websites, should not be seen as a game for getting the lead in total submissions. Nevertheless we encourage you to submit XSS vulnerable websites for the greater good of a secure web. As RSnake <a href="http://ha.ckers.org/blog/20070209/yet-another-xss-archive/#comment-17259" title="RSnake's comment on XSSed.com" target="_blank">commented on his blog post about XSSed.com</a>, &#8220;It’s not who finds the most, it’s about the ease of finding them, the difficulty in stopping them, the various vectors, etc…&#8221;. We seriously take in consideration such comments and suggestions for improvements by people with significant experience and expertise in the web application security field.</p>
<p>We call for papers and video tutorials that focus on exploiting XSS vulnerabilities and on preventing them.</p>
<p>Since the launch of <a href="http://www.xssed.com" title="XSSed.com" target="_blank">XSSed.com</a>, we received many <a href="http://www.xssed.com/submit" title="XSSed.com - Submit XSS vulnerable websites" target="_blank">notifications</a> of high-profiled websites that got XSS&#8217;ed.</p>
<p>Here is a list of notable XSS&#8217;ed websites in the <a href="http://www.xssed.com/archive/special=1/" title="XSSed.com - Special XSS'ed websites archive" target="_blank">archive</a>:</p>
<p><a href="http://www.xssed.com/mirror/158/">hushmail.com</a><br />
<a href="http://www.xssed.com/mirror/197/">youtube.com</a><br />
<a href="http://www.xssed.com/mirror/138/">members.microsoft.com</a><br />
<a href="http://www.xssed.com/mirror/418/">netscape.com</a><br />
<a href="http://www.xssed.com/mirror/1316/" target="_blank">*.search.yahoo.com</a><br />
<a href="http://www.xssed.com/mirror/899/">my.screenname.aol.com</a><br />
<a href="http://www.xssed.com/mirror/139/">my.imageshack.us</a><br />
<a href="http://www.xssed.com/mirror/876/">register.go.com</a><br />
<a href="http://www.xssed.com/mirror/739/">cafepress.com</a><br />
<a href="http://www.xssed.com/mirror/646/">thawte.com</a><br />
<a href="http://www.xssed.com/mirror/617/">verisign.com</a><br />
<a href="http://www.xssed.com/mirror/642/">zonelabs.com</a><br />
<a href="http://www.xssed.com/mirror/374/">www4.symantec.com</a><br />
<a href="http://www.xssed.com/mirror/290/">domaintools.com</a><br />
<a href="http://www.xssed.com/mirror/201/">controlpanel.netfirms.com</a><br />
<a href="http://www.xssed.com/mirror/97/">2600.com</a><br />
<a href="http://www.xssed.com/mirror/306/">sun.com</a><br />
<a href="http://www.xssed.com/mirror/1197/">*.globo.com</a> &#8211; Famous portal in Brazil<br />
<a href="http://www.xssed.com/mirror/256/">*.mynet.com</a> &#8211; Famous portal in Turkey<br />
<a href="http://www.xssed.com/mirror/1000/">login.pathfinder.gr</a> &#8211; Famous portal in Greece</p>
<p>plus many other &#8220;special&#8221; websites, including governmental and military&#8230;</p>
<p align="justify">So far we have had visitors and submitters from &#8211; in order of number of visits &#8211; Turkey, Italy, United Kingdom, United States, Brazil, France, Russia, Germany, Czech Republic and Pakistan. We would like to thank you for supporting our project.</p>
<p>The XSS attack vectors used on the <a href="http://www.xssed.com/archive" title="XSSed.com - Archive of XSS'ed websites" target="_blank">archived websites</a>, were from RSnake&#8217;s XSS <a href="http://ha.ckers.org/xss.html" title="Ha.ckers.org - XSS cheat sheet by RSnake" target="_blank">cheat sheet</a>.</p>
<script type="text/javascript">
  addthis_url    = 'http%3A%2F%2Fwww.ddosed.com%2F2007%2F03%2F06%2Fxssedcom-what-who-why%2F';
  addthis_title  = 'XSSed.com%3A+What%2C+Who%2C+Why%3F';
  addthis_pub    = 'dpan';
</script><script type="text/javascript" src="http://s7.addthis.com/js/addthis_widget.php?v=12" ></script>
]]></content:encoded>
			<wfw:commentRss>http://www.ddosed.com/2007/03/06/xssedcom-what-who-why/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>High-Profiled Websites Getting Hacked And Defaced</title>
		<link>http://www.ddosed.com/2007/02/22/high-profiled-websites-getting-hacked-and-defaced/</link>
		<comments>http://www.ddosed.com/2007/02/22/high-profiled-websites-getting-hacked-and-defaced/#comments</comments>
		<pubDate>Thu, 22 Feb 2007 17:49:16 +0000</pubDate>
		<dc:creator>D1m</dc:creator>
				<category><![CDATA[Defacements]]></category>
		<category><![CDATA[Hacktivism]]></category>
		<category><![CDATA[Personal Opinions]]></category>
		<category><![CDATA[Security News]]></category>

		<guid isPermaLink="false">http://www.ddosed.com/2007/02/22/high-profiled-websites-getting-hacked-and-defaced/</guid>
		<description><![CDATA[Everyday, the security of many high-profiled governmental, military, educational and corporate websites, is broken into by crackers who deface them. Although some defacers protest against wars and other just send greets to their cyberdudes, I believe that their true motive is to get to the top of the lead in &#8220;special&#8221; defacements. The defacers don&#8217;t [...]]]></description>
			<content:encoded><![CDATA[<p align="justify">Everyday, the security of many high-profiled governmental, military, educational and corporate websites, is broken into by crackers who deface them. Although some defacers protest against wars and other just send greets to their cyberdudes, I believe that their true motive is to get to the <a href="http://www.zone-h.org/component/option,com_topatt/Itemid,49/" target="_blank" title="Zone-H.org - Attackers Special Top List">top of the lead in &#8220;special&#8221; defacements</a>. The defacers don&#8217;t want to admit this as the real reason for their attacks.</p>
<p><span id="more-39"></span><br />
<a href="http://www.zone-h.org" target="_blank" title="Zone-H.org - Digital Attacks Archive">Zone-H.org</a> has listed the following reasons in the &#8220;Attacks Notification&#8221; page:</p>
<blockquote><p>- As a challenge<br />
- Heh&#8230;just for fun!<br />
- I just want to be the best defacer<br />
- Not available<br />
- Patriotism<br />
- Political reasons<br />
- Revenge against that website</p></blockquote>
<p>Here is a list of notable hand picked defacements &#8211; archived in <a href="http://www.zone-h.org" target="_blank" title="Zone-H.org - Digital Attacks Archive">Zone-H.org</a>:</p>
<p><strong>US <a href="http://www.zone-h.org/index.php?option=com_attacks&amp;Itemid=44&amp;filter=1" target="_blank" title="Zone-H.org - US Governmental defaces">Governmental</a>:</strong></p>
<p><em>http://dbreports.lanl.gov Win 2003<br />
http://learnlinc.oph.dhh.louisiana.gov Win 2000<br />
http://elbertcounty-co.gov/events.asp Win 2000<br />
http://gis.sedgwick.gov Win 2003<br />
http://gis2.sedgwick.gov Win 2003<br />
http://azdps.gov/inf4z.htm Win 2000<br />
http://csdr-cde.ca.gov/nhst.htm Win 2003<br />
http://join.cio.ca.gov/data/d7j.htm FreeBSD</p>
<p>https://restricted.gov.ca.gov/briefings/files/d7j.htm</p>
<p>http://appointments.ca.gov/3D.htm</em></p>
<p><strong>Famous dot-coms:</strong></p>
<p>http://flightpak.paramount.com Win 2000<br />
http://vassiebel.volvo.com Win 2003<br />
http://ecommercesuite.usbank.com Win 2003<br />
http://panasonickorea.com Linux<br />
http://beta.cmt.msn.com Win 2003</p>
<p><strong>Famous dot-nets:</strong></p>
<p>http://self.wind.it.net/ownz.htm SolarisSunOS<br />
http://korea.net Win 2000</p>
<p>Most defacers of the above websites originate from Turkey, Brazil and Iran.</p>
<p align="justify">The sysadmins of insecure webservers and the developers of insecure web applications are mostly responsible for the cracking incidents. It appears to me that the crackers don&#8217;t have a specific target.</p>
<p align="justify">What they do most of the times, is to use a <a href="http://www.netcraft.com" target="_blank" title="Netcraft.com">Netcraft</a> and a <a href="http://www.google.com" target="_blank" title="Google.com">Google</a> website list generator. After they import the list into a scanner and scan thousands of websites for possible <a href="http://www.securiteam.com/securityreviews/5DP0N1P76E.html" target="_blank" title="SecuriTeam.com - SQL Injection Walkthrough">SQL injections</a>, <a href="http://www.securityfocus.com/columnists/427" target="_blank" title="PHP apps: Security's Low-Hanging Fruit">PHP inclusions</a>, <a href="http://en.wikipedia.org/wiki/Directory_traversal" target="_blank" title="Directory traversal on WikiPedia.org">directory traversals</a>, information leaks and other security <a href="http://www.securityfocus.com/vulnerabilities" target="_blank" title="SecurityFocus.com - Vulnerabilities Archive">vulnerabilities</a>. There have been many cases of crackers using <a href="http://en.wikipedia.org/wiki/Social_engineering_(computer_security)" target="_blank" title="Social Engineering on WikiPedia.org">social engineering</a> techniques, such as <a href="http://en.wikipedia.org/wiki/Social_engineering_(computer_security)#Pretexting" title="What is pretexting?">pretexting</a> and<a href="http://en.wikipedia.org/wiki/Social_engineering_(computer_security)#Phishing" target="_blank" title="What is Phishing?"> phishing</a>, in order to grant access priviledges to confidential information.</p>
<p>Screenshot of a Turkish Googler generating a list of *.gov/s (Click on thumbnail to view it):</p>
<p><a href="http://www.ddosed.com/wp-content/uploads/2007/03/turkish-googler.JPG" title="Turkish Googler" class="imagelink" rel="thumbnail"><img src="http://www.ddosed.com/wp-content/uploads/2007/03/turkish-googler.thumbnail.JPG" alt="Turkish Googler" id="image41" rel="thumbnail" height="119" width="150" /></a></p>
<script type="text/javascript">
  addthis_url    = 'http%3A%2F%2Fwww.ddosed.com%2F2007%2F02%2F22%2Fhigh-profiled-websites-getting-hacked-and-defaced%2F';
  addthis_title  = 'High-Profiled+Websites+Getting+Hacked+And+Defaced';
  addthis_pub    = 'dpan';
</script><script type="text/javascript" src="http://s7.addthis.com/js/addthis_widget.php?v=12" ></script>
]]></content:encoded>
			<wfw:commentRss>http://www.ddosed.com/2007/02/22/high-profiled-websites-getting-hacked-and-defaced/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>MSN.co.uk Money Related Websites Hacked And Defaced</title>
		<link>http://www.ddosed.com/2007/02/01/msn-uk-money-related-websites-hacked-and-defaced/</link>
		<comments>http://www.ddosed.com/2007/02/01/msn-uk-money-related-websites-hacked-and-defaced/#comments</comments>
		<pubDate>Thu, 01 Feb 2007 00:14:28 +0000</pubDate>
		<dc:creator>D1m</dc:creator>
				<category><![CDATA[Defacements]]></category>
		<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Personal Opinions]]></category>
		<category><![CDATA[Security News]]></category>

		<guid isPermaLink="false">http://www.ddosed.com/2007/02/01/msncouk-money-related-websites-hacked-and-defaced/</guid>
		<description><![CDATA[Two websites belonging to MSN (Microsoft Network) in the United Kingdom, were defaced today by an attacker who goes by the nickname &#8220;DARK LORD&#8220;. It looks like someone who is unethically testing  his SQL injection  skills, and &#8220;feeding&#8221; himself with a false sense of pride, just by leaving the message &#8220;DARK LORD WAZ [...]]]></description>
			<content:encoded><![CDATA[<p align="justify">Two websites belonging to <a href="http://www.msn.co.uk" target="_blank" title="MSN.co.uk">MSN</a> (Microsoft Network) in the United Kingdom, were defaced today by an attacker who goes by the nickname <em>&#8220;<a href="http://www.zone-h.org/component/option,com_attacks/Itemid,44/filter_defacer,DARK%20LORD/" target="_blank" title="Zone-H.org - ">DARK LORD</a>&#8220;</em>. It looks like someone who is unethically testing  his <a href="http://www.governmentsecurity.org/articles/SQLInjectionModesofAttackDefenceandWhyItMatters.php" target="_blank" title="SQL Injection: Modes of Attack, Defence, and Why It Matters - Stuart McDonald">SQL injection</a>  skills, and &#8220;feeding&#8221; himself with a false sense of pride, just by leaving the message <em>&#8220;DARK LORD WAZ HERE&#8221;</em>.</p>
<p align="justify">No. I am not a defacer psychologist. I am just  expressing my personal opinion on the matter, which is this: If a website defacement doesn&#8217;t convey a meaningful message, then it is done for selfish reasons.</p>
<p>A bit of an embarassment for Microsoft&#8217;s sysadmins&#8230;</p>
<p><span id="more-26"></span></p>
<p align="justify">The cracker exploited an SQL injection vulnerability in the <em>story.asp</em> file and thus was able to deface the following websites:</p>
<p><em>http://whatinvestment.money.msn.co.uk Win 2003<br />
http://personalfinance.money.msn.co.uk Win 2003</em></p>
<p>Screenshot of the defaced website (Click thumbnail to view it):</p>
<p><a href="http://www.ddosed.com/wp-content/uploads/2007/01/msncoukdefaced.JPG" title="MSN.co.uk money websites defaced" class="imagelink" rel="thumbnail"><img src="http://www.ddosed.com/wp-content/uploads/2007/01/msncoukdefaced.thumbnail.JPG" style="width: 140px; height: 103px" alt="MSN.co.uk money websites defaced" id="image27" /></a></p>
<p align="justify">The most surprising thing &#8211; actually not very suprising, judging from past cracking incidents of Microsoft&#8217;s systems &#8211; is that the website remained defaced for more than 8 hours and the <a href="http://www.governmentsecurity.org/articles/SQLInjectionModesofAttackDefenceandWhyItMatters.php" title="SQL Injection: Modes of Attack, Defence, and Why It Matters - Stuart McDonald" target="_blank">SQL injection</a> vulnerability has not been fixed yet.</p>
<p>Screenshot (Click thumbnail to view it):</p>
<p><a href="http://www.ddosed.com/wp-content/uploads/2007/01/msncouksqlinjection.JPG" class="imagelink" title="MSN.co.uk - SQL injection vulnerability" rel="thumbnail"><img src="http://www.ddosed.com/wp-content/uploads/2007/01/msncouksqlinjection.thumbnail.JPG" style="width: 140px; height: 106px" id="image28" alt="MSN.co.uk - SQL injection vulnerability" /></a></p>
<p align="justify">You can view the above website defacements and 2.092.360 &#8211; as for today at 23:00 GMT &#8211; archived digital attacks at <a href="http://www.zone-h.org" title="Zone-H.org - Largest digital attacks archive" target="_blank">Zone-H.org</a>.</p>
<script type="text/javascript">
  addthis_url    = 'http%3A%2F%2Fwww.ddosed.com%2F2007%2F02%2F01%2Fmsn-uk-money-related-websites-hacked-and-defaced%2F';
  addthis_title  = 'MSN.co.uk+Money+Related+Websites+Hacked+And+Defaced';
  addthis_pub    = 'dpan';
</script><script type="text/javascript" src="http://s7.addthis.com/js/addthis_widget.php?v=12" ></script>
]]></content:encoded>
			<wfw:commentRss>http://www.ddosed.com/2007/02/01/msn-uk-money-related-websites-hacked-and-defaced/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Britney Spears&#8217;s Official German Website Got Hacked And Defaced</title>
		<link>http://www.ddosed.com/2007/01/30/britney-spears-official-german-website-got-hacked-and-defaced/</link>
		<comments>http://www.ddosed.com/2007/01/30/britney-spears-official-german-website-got-hacked-and-defaced/#comments</comments>
		<pubDate>Tue, 30 Jan 2007 19:37:24 +0000</pubDate>
		<dc:creator>D1m</dc:creator>
				<category><![CDATA[Defacements]]></category>
		<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Security News]]></category>

		<guid isPermaLink="false">http://www.ddosed.com/2007/01/30/britney-spearss-official-german-website-got-hacked-and-defaced/</guid>
		<description><![CDATA[Was time for the website defacers to hit the music industry!  Yesterday, visitors of the BritneySpears.de website could read &#8220;XTech Inc Onwed the Music Industry&#8230; and the rest of it  &#8221; at the top of the home page. It appears to me though, that they just did it for fun and not for [...]]]></description>
			<content:encoded><![CDATA[<p align="justify">Was time for the website defacers to hit the music industry!  Yesterday, visitors of the <a href="http://www.britneyspears.de" title="Britney Spears - Official Website in Germany" target="_blank">BritneySpears.de</a> website could read <em>&#8220;XTech Inc Onwed the Music Industry&#8230; and the rest of it <img src='http://www.ddosed.com/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /> &#8221;</em> at the top of the home page. It appears to me though, that they just did it for fun and not for any serious reason.</p>
<p align="justify">Apparently it was hosted in the same webserver with other official german websites of <a href="http://www.sonybmg.de" title="SonyBMG.de - Official German Website" target="_blank">Sony BMG</a> entertainment.</p>
<p align="justify">The attackers exploited a web application vulnerability &#8211; probably <a href="http://www.securityfocus.com/columnists/427" title="SecurityFocus.com - PHP apps: Security's Low-Hanging Fruit" target="_blank">php inclusion</a> &#8211; in order to get access to the Solaris 9/10 webserver.</p>
<p align="justify"><span id="more-24"></span> The most probable attack scenario was this: Initially a backdoor through a php shell script was run, then shell access through a terminal to the attackers specified port was aquired. Having done this, if a local root exploit is successful, then the attackers have complete access to the webserver, leaving it vulnerable to other cracking teams, usually for a short time span.</p>
<p>Screenshot of the deface (Click thumbnail to view it):</p>
<p><a href="http://www.ddosed.com/wp-content/uploads/2007/01/britneyspearsdeface.JPG" class="imagelink" title="BritneySpears.de defaced" rel="thumbnail"><img src="http://www.ddosed.com/wp-content/uploads/2007/01/britneyspearsdeface.thumbnail.JPG" id="image25" alt="BritneySpears.de Defaced" height="84" width="116" /></a></p>
<p>Here is the list of all the affected websites, along with the OS that they run:</p>
<p><em>http://britneyspears.de   SolarisSunOS<br />
http://stuff.sonybmg.de   SolarisSunOS<br />
http://dms.sonybmg.de   SolarisSunOS<br />
http://stats.bmg.de   SolarisSunOS<br />
http://forum.bmg.de   SolarisSunOS<br />
http://research.sonybmg.de  SolarisSunOS<br />
http://live.bmg.de  SolarisSunOS<br />
http://mediaplayer.sonybmg.de  SolarisSunOS</em></p>
<p>All of the above defacements are archived at <a href="http://www.zone-h.org" title="Zone-H.org - Largest digital attacks archive" target="_blank">Zone-H.org</a>.</p>
<script type="text/javascript">
  addthis_url    = 'http%3A%2F%2Fwww.ddosed.com%2F2007%2F01%2F30%2Fbritney-spears-official-german-website-got-hacked-and-defaced%2F';
  addthis_title  = 'Britney+Spears%26%238217%3Bs+Official+German+Website+Got+Hacked+And+Defaced';
  addthis_pub    = 'dpan';
</script><script type="text/javascript" src="http://s7.addthis.com/js/addthis_widget.php?v=12" ></script>
]]></content:encoded>
			<wfw:commentRss>http://www.ddosed.com/2007/01/30/britney-spears-official-german-website-got-hacked-and-defaced/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>A Brief Comment On The Saudi Arabian Defacers Of Zone-H</title>
		<link>http://www.ddosed.com/2007/01/28/comment-on-the-saudi-arabian-defacers-of-zone-h/</link>
		<comments>http://www.ddosed.com/2007/01/28/comment-on-the-saudi-arabian-defacers-of-zone-h/#comments</comments>
		<pubDate>Sun, 28 Jan 2007 02:58:34 +0000</pubDate>
		<dc:creator>D1m</dc:creator>
				<category><![CDATA[Defacements]]></category>
		<category><![CDATA[Personal Opinions]]></category>

		<guid isPermaLink="false">http://www.ddosed.com/2007/01/28/a-brief-comment-on-the-saudi-arabian-defacers-of-zone-h/</guid>
		<description><![CDATA[Since I read the news about the recent defacement of the digital attacks archive Zone-H.org, many people have commented on how &#8220;professional&#8221;  the Saudi Arabian defacers were. I strongly disagree&#8230; They were very &#8220;unprofessional&#8221; kids.
 Just one confused kid who praises the devil &#8211; Devil Hacker &#8211; with his fellow pal Unix Web. Both [...]]]></description>
			<content:encoded><![CDATA[<p align="justify">Since I read the news about the recent defacement of the digital attacks archive <a href="http://www.zone-h.org" title="Zone-H.org - Largest digital attacks archive" target="_blank">Zone-H.org</a>, many people have commented on how &#8220;professional&#8221;  the Saudi Arabian defacers were. I strongly disagree&#8230; They were very &#8220;unprofessional&#8221; kids.</p>
<p align="justify"> Just one confused kid who praises the devil &#8211; Devil Hacker &#8211; with his fellow pal Unix Web. Both from Jeddah in Saudi Arabia.</p>
<p align="justify">Students with too much time on their hands. They proved that they can use a basic backdoor, change the DNS and use the exploits that come together with some security advisories.</p>
<p><span id="more-19"></span></p>
<p align="justify">If you look at Devil Hacker&#8217;s blog, you will immediately notice some really lame posts and links to lame &#8211; &#8220;im going to show you what my cracking skills are&#8221; &#8211; videos.</p>
<p>Devil Hacker&#8217;s blog (muhahahaha):<br />
<a href="http://www.dev.blogfa.com" title="Devil Hacker's blog" target="_blank">www.dev.blogfa.com</a></p>
<p align="justify">I must admit though&#8230; These guys have skills in following the instructions&#8230;</p>
<p align="justify">&nbsp;</p>
<p align="justify">What were their motives? Publicity. I&#8217;m sure the one went to the other&#8217;s house and searched for their nicknames on a search engine. A few good laughs, a false sense of pride. Now lets go listen to Marilyn Manson!</p>
<p align="justify">Neither hackers or crackers! Just script kiddies &#8211; computer power users.<br />
Real hackers and crackers don&#8217;t post their e-mail addresses, they don&#8217;t say from where they are from, they don&#8217;t say who they are.</p>
<p>Nuff said.</p>
<script type="text/javascript">
  addthis_url    = 'http%3A%2F%2Fwww.ddosed.com%2F2007%2F01%2F28%2Fcomment-on-the-saudi-arabian-defacers-of-zone-h%2F';
  addthis_title  = 'A+Brief+Comment+On+The+Saudi+Arabian+Defacers+Of+Zone-H';
  addthis_pub    = 'dpan';
</script><script type="text/javascript" src="http://s7.addthis.com/js/addthis_widget.php?v=12" ></script>
]]></content:encoded>
			<wfw:commentRss>http://www.ddosed.com/2007/01/28/comment-on-the-saudi-arabian-defacers-of-zone-h/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>US Government Websites Get Hacked And Defaced Every Month</title>
		<link>http://www.ddosed.com/2007/01/27/us-goverment-websites-get-hacked-and-defaced-every-month/</link>
		<comments>http://www.ddosed.com/2007/01/27/us-goverment-websites-get-hacked-and-defaced-every-month/#comments</comments>
		<pubDate>Sat, 27 Jan 2007 16:43:47 +0000</pubDate>
		<dc:creator>D1m</dc:creator>
				<category><![CDATA[Defacements]]></category>
		<category><![CDATA[Personal Opinions]]></category>
		<category><![CDATA[Security News]]></category>

		<guid isPermaLink="false">http://www.ddosed.com/2007/01/27/us-goverment-websites-get-defaced-every-month/</guid>
		<description><![CDATA[US government websites are under the spotlight of muslim cracking groups who protest against USA &#8211; this is what they claim as an attack reason. Since the 2nd of January, 17 US governmental websites were defaced, from which 9 were defaced by means of SQL injection.
What seems obvious to me &#8211; after viewing most of [...]]]></description>
			<content:encoded><![CDATA[<p align="justify">US government websites are under the spotlight of muslim cracking groups who protest against USA &#8211; this is what they claim as an attack reason. Since the 2nd of January, 17 US governmental websites were defaced, from which 9 were defaced by means of <a href="http://www.google.co.uk/search?hl=en&amp;q=%22sql+injection%22&amp;meta=" target="_blank" title="SQL injection - Google Results">SQL injection</a>.</p>
<p align="justify">What seems obvious to me &#8211; after viewing most of those defacements on the <a href="http://www.zone-h.org/component/option,com_attacks/Itemid,44/" target="_blank" title="Zone-H.org - Special Digital Attacks Archive">Zone-H digital attacks archive</a> &#8211; is that their motives are not fully justified. Most of these crackers &#8211; better say &#8220;<a href="http://en.wikipedia.org/wiki/Script_kiddie" target="_blank" title="Script Kiddies on Wikipedia">script kiddies</a>&#8221; &#8211; are using <a href="http://www.milw0rm.com" target="_blank" title="Milw0rm.com - Security Exploits Archive">publicly available exploits</a> for <a href="http://www.securityfocus.com/vulnerabilities" target="_blank" title="SecurityFocus.com - Vulnerabilities ">known vulnerabilities</a>, and by applying logic on how to use them, they succeed in the end at gaining access on webservers.</p>
<p align="justify">The fact that the attacked webservers belong to the US government, doesn&#8217;t necessarily mean that there is adequate security implemented.</p>
<p align="justify"><span id="more-17"></span>Apart from the little warning/disclaimer that they put on their websites as a scare tactic for crackers, there is very little done on tracing and catching the crackers who successfully broke into their webservers. Setting up <a href="http://www.honeypots.net/" target="_blank" title="Honeypots, Intrusion Detection, Incident Response">honeypots</a> on their systems in order to track the techniques and methodologies which are used by crackers, is certainly helpful knowledgewise.</p>
<p align="justify">In the mind and soul of the crackers who deface high-profiled websites, there is a false sense of pride. They think that it reflects their cracking skills and status in the defacers scene. For them, defacing is more like a game. The messages shown in their defacements, are more like an excuse for taking part in this game. The real motivation and reasoning behind their attacks, in most of the cases is not political, patriotic or other; but is just to show off themselves and their country to the world&#8230;</p>
<p align="justify">They attach a nickname to their personalities and cracking abilities, and they try to raise its status in the scene. They like searching for their nicknames in news websites and showing off the link to other crackers in their IRC channel, other channels, or through their websites.</p>
<p>Below is the list of all the *.gov websites that were defaced in the past 27 days,  along with the OS that they run:</p>
<p>(Visit <a href="http://www.zone-h.org" target="_blank" title="Zone-H.org Digital Attacks Archive">Zone-H.org</a> to view the defacements)</p>
<p><em>https://www.cahps.ahrq.gov/content/cahpsOverview/faqanswer.asp Win 2000<br />
http://learnabouteva.dgs.virginia.gov/FAQ Win 2003<br />
http://mail.vi.gov/ibh.html   Win 2003<br />
http://webmail.vi.gov/index.html  Win 2003<br />
http://nd.gov/ndins/communications  Linux<br />
http://hca.montgomerycountymd.gov/govtmpl.asp  Win 2000<br />
http://fairfaxva.gov/personnel/Jobs.asp  Win 2003<br />
http://cstx.gov/home/index.asp  Win 2000<br />
https://ssl.cstx.gov/csjobs/job_list.asp  Win 2000<br />
http://oss.monroecounty-fl.gov/1923tg.htm  Win 2000<br />
http://asc.gov/default.aspx  Win 2003<br />
http://eppcapps.ky.gov/earthday/ideas.aspx  Win 2003<br />
http://tncarefraud.tennessee.gov/newsAndInfo.aspx  Win 2003<br />
http://floydcounty.in.gov  Win 2000<br />
http://radsite.lbl.gov/testhost.htm  FreeBSD<br />
http://hobbes.lbl.gov/ibh.htm  FreeBSD<br />
http://floyd.lbl.gov/ibh.htm  FreeBSD<br />
http://archivesindex.sc.gov  Win 2000<br />
https://fortress.wa.gov/dshs/f2ws03esaapps/stars/newsarchive.asp  FreeBSD</em></p>
<script type="text/javascript">
  addthis_url    = 'http%3A%2F%2Fwww.ddosed.com%2F2007%2F01%2F27%2Fus-goverment-websites-get-hacked-and-defaced-every-month%2F';
  addthis_title  = 'US+Government+Websites+Get+Hacked+And+Defaced+Every+Month';
  addthis_pub    = 'dpan';
</script><script type="text/javascript" src="http://s7.addthis.com/js/addthis_widget.php?v=12" ></script>
]]></content:encoded>
			<wfw:commentRss>http://www.ddosed.com/2007/01/27/us-goverment-websites-get-hacked-and-defaced-every-month/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Website Defacements And Hacktivism + Question</title>
		<link>http://www.ddosed.com/2007/01/05/website-defacements-and-hacktivism-question/</link>
		<comments>http://www.ddosed.com/2007/01/05/website-defacements-and-hacktivism-question/#comments</comments>
		<pubDate>Fri, 05 Jan 2007 15:07:28 +0000</pubDate>
		<dc:creator>D1m</dc:creator>
				<category><![CDATA[Defacements]]></category>
		<category><![CDATA[Hacktivism]]></category>
		<category><![CDATA[Security Articles]]></category>

		<guid isPermaLink="false">http://www.ddosed.com/2007/01/21/website-defacements-and-hacktivism-question/</guid>
		<description><![CDATA[In less than 200 words, I compiled very interesting information on the subjects of website defacing and hacktivism. Enough information is provided to you in order to answer my question which follows at the end. I would like to know your personal views.
Website defacement [2] is the substitution of an original home page by a [...]]]></description>
			<content:encoded><![CDATA[<p align="justify">In less than 200 words, I compiled very interesting information on the subjects of website defacing and hacktivism. Enough information is provided to you in order to answer my question which follows at the end. I would like to know your personal views.</p>
<p align="justify"><a href="http://www.zone-h.org" title="Zone-H.org - Independent observatory of server-side cybercrimes." target="_blank">Website defacement</a> [2] is the substitution of an original home page by a system cracker/hacker.  It is illegal in most countries as is considered an unauthorized computer access, data modification and denial of service.  Crackers/hackers are usually defacing websites to spread messages and beliefs.  Some of them are politically, socially and religiously motivated &#8211; given the term hacktivists &#8211; and some other just deface for the thrill.</p>
<p align="justify">A website defacement can create serious problems for companies as it they affects negatively their public image on the internet and in general.  Victim companies may stop their transactions in order to repair the affected computer systems and thus lose money. It can also make their existing customers or potential future customers to lose faith in the company as it is evidence that their web server was broken into due to lack of security.</p>
<p><span id="more-10"></span> <span lang="EN"></span></p>
<p align="justify"><span lang="EN">Hacktivism [1]</span> is the act of hacking, or breaking into computer systems (including website defacements), usually to promote <a href="http://en.wikipedia.org/wiki/Political_ideology" title="Political ideology">political, social and religious ideology</a> &#8211; promoting expressive <a href="http://en.wikipedia.org/wiki/Politics" title="Politics">politics</a>, <a href="http://en.wikipedia.org/wiki/Free_speech" title="Free speech">free speech</a>, <a href="http://en.wikipedia.org/wiki/Human_rights" title="Human rights">human rights</a>, or information <a href="http://en.wikipedia.org/wiki/Ethics" title="Ethics">ethics</a> &#8211; and is not specifically motivated by malicious, curious or criminal intents.</p>
<p><span lang="EN">What are your views on hacktivism with respect to website defacing? </span><span lang="EN"> (Generally and legislationwise)</span></p>
<p>Sources:</p>
<p>[1] <a href="http://en.wikipedia.org/wiki/Hacktivism">http://en.wikipedia.org/wiki/Hacktivism</a></p>
<p>[2] <a href="http://en.wikipedia.org/wiki/Website_defacement" target="_blank">http://en.wikipedia.org/wiki/Website_defacement </a></p>
<script type="text/javascript">
  addthis_url    = 'http%3A%2F%2Fwww.ddosed.com%2F2007%2F01%2F05%2Fwebsite-defacements-and-hacktivism-question%2F';
  addthis_title  = 'Website+Defacements+And+Hacktivism+%2B+Question';
  addthis_pub    = 'dpan';
</script><script type="text/javascript" src="http://s7.addthis.com/js/addthis_widget.php?v=12" ></script>
]]></content:encoded>
			<wfw:commentRss>http://www.ddosed.com/2007/01/05/website-defacements-and-hacktivism-question/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>
