- Visitors can check out the Forum FAQ by clicking this link. You have to register before you can post: click the REGISTER link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below. View our Forum Privacy Policy.
- Want to receive the latest contracting news and advice straight to your inbox? Sign up to the ContractorUK newsletter here. Every sign up will also be entered into a draw to WIN £100 Amazon vouchers!
The Sun Reporting Murdock Dead
Collapse
X
-
-
-
Could be an inside job, or security details passed on, if any techies have recently been laid off.Work in the public sector? Read the IR35 FAQ hereComment
-
Nah, just crap / non-existant security.Originally posted by OwlHoot View PostCould be an inside job, or security details passed on, if any techies have recently been laid off.
Never attribute to Malice that which can be explain by stupidity.
"Being nice costs nothing and sometimes gets you extra bacon" - Pondlife.Comment
-
Thats an extreemly big If.Originally posted by Zippy View Post... at one of Her Majesty's less salubrious establishments, if they get caught. If only there were more Met officers available to investigate ...
The impressive thing about these guys is not so much what they have done, most of it is down to lapses / incompetence on the part of the site owners in not fixing known vulnerabilities, it's the fact that they havn't been caught.
So far they have managed to evade the security services and law enforment agencies of at least 2 countries for several months, and maintain a high public profile while doing it. That's the impressive bit."Being nice costs nothing and sometimes gets you extra bacon" - Pondlife.Comment
-
Grauniad: How the hack was done
Oops #1
Oops # 2However as far back as 2009 a weakness was found in the "Contact us" form of the Sun's site that meant that it could be used to attack the database holding emails for the system.
NI should really have taken "new-times.co.uk" offline once they were done with it.The server hosted the outdated "new-times.co.uk" site put up when the Times was building its paywall.Last edited by Sysman; 19 July 2011, 10:45.Behold the warranty -- the bold print giveth and the fine print taketh away.Comment
-
How was the hack achieved ? It was not a straight forward file system hack because the home page would show for about 5 seconds before a redirect happened. Was it a XSS attack ?Vote Corbyn ! Save this country !Comment
-
Nope, from the Grauniad article there were fundamental flaws in the new-times.co.uk website that allowed them to carry out an SQL injection and File Inclusion attack that gave them control of the server and from there into the CMS used to maintain the Sun website. From there it was trivial to add a redirect on the home page. The delay was probably just down to server lag due to the volume of traffic hitting it once the hack went public.Originally posted by fullyautomatix View PostHow was the hack achieved ? It was not a straight forward file system hack because the home page would show for about 5 seconds before a redirect happened. Was it a XSS attack ?
Trivial stuff in terms of complexity of the hack and entirly due to stupidity/negligence on behalf of NI techies."Being nice costs nothing and sometimes gets you extra bacon" - Pondlife.Comment
-
If they treated the techies like the journalists then it wasn't stupidity/negligence.Originally posted by DaveB View Post
Trivial stuff in terms of complexity of the hack and entirly due to stupidity/negligence on behalf of NI techies.
"You’re just a bad memory who doesn’t know when to go away" JRComment
-
If it was such a complete control of the server/CMS/file system whatever, why didnt they just modify the home page of "Sun" and put the story up there ? Why a redirect? and why not a server side redirect rather than a client redirect ?Originally posted by DaveB View PostNope, from the Grauniad article there were fundamental flaws in the new-times.co.uk website that allowed them to carry out an SQL injection and File Inclusion attack that gave them control of the server and from there into the CMS used to maintain the Sun website. From there it was trivial to add a redirect on the home page. The delay was probably just down to server lag due to the volume of traffic hitting it once the hack went public.
Trivial stuff in terms of complexity of the hack and entirly due to stupidity/negligence on behalf of NI techies.Vote Corbyn ! Save this country !Comment
- Home
- News & Features
- First Timers
- IR35 / S660 / BN66
- Employee Benefit Trusts
- Agency Workers Regulations
- MSC Legislation
- Limited Companies
- Dividends
- Umbrella Company
- VAT / Flat Rate VAT
- Job News & Guides
- Money News & Guides
- Guide to Contracts
- Successful Contracting
- Contracting Overseas
- Contractor Calculators
- MVL
- Contractor Expenses
Advertisers
Contractor Services
CUK News
- Business expenses: What IT contractors can and cannot claim from HMRC Today 08:44
- April’s umbrella PAYE risk: how contractors’ end-clients are prepping Yesterday 05:45
- How EV tax changes of 2025-2028 add up for contractor limited company directors Jan 28 08:11
- Under the terms he was shackled by, Ray McCann’s Loan Charge Review probably is a fair resolution Jan 27 08:41
- Contractors, a £25million crackdown on rogue company directors is coming Jan 26 05:02
- How to run a contractor limited company — efficiently. Part one: software Jan 22 23:31
- Forget February as an MSC contractor seeking clarity, and maybe forget fairness altogether Jan 22 19:57
- What contractors should take from Honest Payroll Ltd’s failure Jan 21 07:05
- HMRC tax avoidance list ‘proves promoters’ nothing-to-lose mentality’ Jan 20 09:17
- Digital ID won’t be required for Right To Work, but more compulsion looms Jan 19 07:41

Comment