AOL communities hacked again

AOL's ICQ servers have been hacked for the second time this year.

The ICQ homepage was defaced by the hacking group Innocent Boys, while a separate server ICQgroup01.icq.com was simultaneously attacked by the notorious Men in Hack (MiH) crackers who added a defaced page to the community page.

The free peer-to-peer ICQ software uses the Microsoft IIS Web server. "This has more holes than Swiss cheese," said Mark Read, systems security analyst for computer security company MIS Corporate Defence Solutions. "It seems that Microsoft doesn't understand the terms of bounds checking -- I strongly suspect that within the next couple of weeks another hack of this system will be found."

The two main vulnerability exploits of IIS that crackers are targeting at the moment are the index server buffer overflow for which no official patch has yet been released, and the IIS 5 remote printer overflow, said Read. "Microsoft has released patches for known exploits, but people install servers and don't install the patches or subscribe to any bugtraq mailing lists," he said.

AOL said that the electronic defacement vulnerability was quickly patched, and that no customer details were accessed. But Read argues that it is difficult for AOL to be certain of this. "When you do a search on ICQ, you don't know if this is directing you to another server, or carrying out the search on the screen being defaced where data could be compromised," he said.

Last week, the UK Web site of the fast food chain Burger King was defaced for the third time this year, this time by a cracker operating under the nickname of MrAgent. The flash-enabled site was hacked using a similar IIS buffer-overflow vulnerability.

Advertisement

Talkback 0 comments

Latest Videos

Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • Suzanne Tindal Sick of broken tender sites
    Some of the state governments desperately need to invest in more user-friendly tender sites so that looking for information on government tenders doesn't have to be a game of blind man's bluff.
  • Array Cyberwar: What is it good for?
    In this week's episode, Cyberwar. What is Australia's place in the world of digital warfare? What are the implications for the NBN?
  • Array Is wholesale-only backhaul just a pipedream?
    The potential acquisition of Pipe Networks by SP Telemedia has raised the question about whether vertically integrated backhaul providers will mean higher wholesale prices for ISP customers.
  • More blogs »

Tags

Back to top

Featured