• Visitors can check out the Forum FAQ by clicking this link. You have to register before you can post: click the REGISTER link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below. View our Forum Privacy Policy.
  • Want to receive the latest contracting news and advice straight to your inbox? Sign up to the ContractorUK newsletter here. Every sign up will also be entered into a draw to WIN £100 Amazon vouchers!

The Sun Reporting Murdock Dead

Collapse
X
  •  
  • Filter
  • Time
  • Show
Clear All
new posts

    #21
    Originally posted by Clippy View Post
    They had, but:
    Thank you for the love tonight. I know we quit, but we couldn't sit by with our wine watching this walnut-faced Murdoch clowning around.

    Comment


      #22
      Originally posted by NickFitz View Post
      They had, but:
      Thank you for the love tonight. I know we quit, but we couldn't sit by with our wine watching this walnut-faced Murdoch clowning around.

      What's good for the goose.
      What happens in General, stays in General.
      You know what they say about assumptions!

      Comment


        #23
        Could be an inside job, or security details passed on, if any techies have recently been laid off.
        Work in the public sector? Read the IR35 FAQ here

        Comment


          #24
          Originally posted by OwlHoot View Post
          Could be an inside job, or security details passed on, if any techies have recently been laid off.
          Nah, just crap / non-existant security.

          Never attribute to Malice that which can be explain by stupidity.

          "Being nice costs nothing and sometimes gets you extra bacon" - Pondlife.

          Comment


            #25
            Originally posted by Zippy View Post
            ... at one of Her Majesty's less salubrious establishments, if they get caught. If only there were more Met officers available to investigate ...
            Thats an extreemly big If.

            The impressive thing about these guys is not so much what they have done, most of it is down to lapses / incompetence on the part of the site owners in not fixing known vulnerabilities, it's the fact that they havn't been caught.

            So far they have managed to evade the security services and law enforment agencies of at least 2 countries for several months, and maintain a high public profile while doing it. That's the impressive bit.
            "Being nice costs nothing and sometimes gets you extra bacon" - Pondlife.

            Comment


              #26
              Grauniad: How the hack was done

              Oops #1

              However as far back as 2009 a weakness was found in the "Contact us" form of the Sun's site that meant that it could be used to attack the database holding emails for the system.
              Oops # 2

              The server hosted the outdated "new-times.co.uk" site put up when the Times was building its paywall.
              NI should really have taken "new-times.co.uk" offline once they were done with it.
              Last edited by Sysman; 19 July 2011, 10:45.
              Behold the warranty -- the bold print giveth and the fine print taketh away.

              Comment


                #27
                How was the hack achieved ? It was not a straight forward file system hack because the home page would show for about 5 seconds before a redirect happened. Was it a XSS attack ?
                Vote Corbyn ! Save this country !

                Comment


                  #28
                  Originally posted by fullyautomatix View Post
                  How was the hack achieved ? It was not a straight forward file system hack because the home page would show for about 5 seconds before a redirect happened. Was it a XSS attack ?
                  Nope, from the Grauniad article there were fundamental flaws in the new-times.co.uk website that allowed them to carry out an SQL injection and File Inclusion attack that gave them control of the server and from there into the CMS used to maintain the Sun website. From there it was trivial to add a redirect on the home page. The delay was probably just down to server lag due to the volume of traffic hitting it once the hack went public.

                  Trivial stuff in terms of complexity of the hack and entirly due to stupidity/negligence on behalf of NI techies.
                  "Being nice costs nothing and sometimes gets you extra bacon" - Pondlife.

                  Comment


                    #29
                    Originally posted by DaveB View Post

                    Trivial stuff in terms of complexity of the hack and entirly due to stupidity/negligence on behalf of NI techies.
                    If they treated the techies like the journalists then it wasn't stupidity/negligence.
                    "You’re just a bad memory who doesn’t know when to go away" JR

                    Comment


                      #30
                      Originally posted by DaveB View Post
                      Nope, from the Grauniad article there were fundamental flaws in the new-times.co.uk website that allowed them to carry out an SQL injection and File Inclusion attack that gave them control of the server and from there into the CMS used to maintain the Sun website. From there it was trivial to add a redirect on the home page. The delay was probably just down to server lag due to the volume of traffic hitting it once the hack went public.

                      Trivial stuff in terms of complexity of the hack and entirly due to stupidity/negligence on behalf of NI techies.
                      If it was such a complete control of the server/CMS/file system whatever, why didnt they just modify the home page of "Sun" and put the story up there ? Why a redirect? and why not a server side redirect rather than a client redirect ?
                      Vote Corbyn ! Save this country !

                      Comment

                      Working...
                      X