Newsletters
Customer Relationship Management News NewsFactor Sites:       NewsFactor.com     Enterprise Security Today     CRM Daily     Business Report     Sci-Tech Today  
   
Home CRM Systems Customer Service Business Intelligence Sales & Marketing More Topics...
Vblock™ Systems:
Advanced converged infrastructure
increases productivity & lowers costs.

www.vce.com
Computing
Real-time info services with Neustar
Average Rating:
Rate this article:  
Syrian Electronic Army Hacks Microsoft -- Again
Syrian Electronic Army Hacks Microsoft -- Again

By Jennifer LeClaire
January 21, 2014 1:37PM

Bookmark and Share
The attacks against Microsoft by the Syrian Electronic Army aren’t particularly sophisticated or novel. In going after Microsoft, the Syrian Electronic Army has used well-known breaching tactics. But the fact that the hacktivist group is continually successful shows that the industry needs to do a better job guarding against these tactics.
 


One particular hacktivist group seems to have a bone to pick with mighty Microsoft. First, the Syrian Electronic Army (SEA) hijacked a few of Redmond’s Twitter accounts. Next, the group invaded the company’s official blog. Now, the SEA has hacked into Microsoft’s Office Blogs site.

The hackers took to Twitter with proof positive in the form of a screenshot of the Microsoft Office Blog site. The SEA article was titled “Hacked by the Syrian Electronic Army” and was placed next to “Office 15-Minute Webinars” and “Top 5 Reasons to attend Sharepoint Conference 2014” on the blog’s home page.

Microsoft was quick to take down the article, but Google searchers can still find the cached image. The attack comes as Microsoft rolled out a new design for its Office Blog site -- complete with a new content management system (CMS) -- on Monday and the SEA’s Twitter message reads, “Dear @Microsoft, Changing the CMS will not help you if your employees are hacked and they don’t know about that.”

Breaking the Pattern

“A targeted cyberattack temporarily affected the Microsoft Office blog,” the company said in a statement. “The account was quickly reset and we can confirm that no customer information was compromised.”

We caught up with Ken Pickering, director of Engineering at CORE Security, to get his take on the Microsoft attacks. He told us the attacks aren’t particularly sophisticated or novel. The SEA, he noted, uses well-known breaching tactics and the fact that they are continually successful shows that the industry needs to do a better job guarding against these tactics.

“How do we break this pattern? Here’s the methodology I always advise: In order to prevent attacks, you need to think like an attacker. Consider how the ‘bad guys’ will try to break into your account and/or network, and counteract those tactics,” Pickering said. “We, as an industry, get hung up on testing for compliances and following 'best practices,' while losing sight of the ever-present battle with which IT and security personnel are consistently embroiled.”

Layered Defense Needed

Like Anonymous, the SEA has made quite a name for itself in the hacker world. The hacktivist group has targeted many media sites, including the New York Times, the Washington Post, the Financial Times, the Associated Press, The Guardian, Twitter and Twing, over the past year.

Kevin O'Brien, enterprise solution architect at CloudLock, told us these attacks are one more example of why companies need to implement properly layered defense strategies. Again, the issue with the DNS compromise was that a single point of failure -- the domain record company hacked, in this case -- resulted in "real-world" damages.

"Any time a single point of failure exists, one should assume that it will be the target of concerted effort on the behalf of criminals who wish to exploit, destroy, or compromise an organization," O'Brien said. "The coming days will tell for certain, but it's probably safe to assume that the Gray Lady's staff had not considered whether or not their DNS host was properly auditing and securing their environment. In turn, the DNS host was probably not doing the same for their resellers."
 

Tell Us What You Think
Comment:

Name:



Your Next Generation Data Center Is Here! Vblock™ Systems: the world's most advanced converged infrastructure are built on the Cisco Unified Computing System with Intel® Xeon® processors. Vblock™ Systems deliver extraordinary time to market, ROI and TCO, and flexibility to meet your continually changing demands with 5X faster deployment, 96% less downtime, and 1/2 the cost. Click here to learn more.


 Computing
1.   Google Street View Unravels CAPTCHAs
2.   Android Gets Chrome Remote Desktop
3.   IBM Adds Disaster Recovery to SoftLayer
4.   Mark Hurd's 5 Keys to Market Success
5.   How To Beat the Heartbleed Bug


advertisement
Don't Reset Passwords for Heartbleed?
Added caution needed to ensure security.
Average Rating:
Last Fixes Tuesday for XP, Office 2003
Microsoft closing out support for two.
Average Rating:
Tech 101: What Is Open Source?
Foundation of countless applications.
Average Rating:
Product Information and Resources for Technology You Can Use To Boost Your Business

Network Security Spotlight
Google's Street View Software Unravels CAPTCHAs
The latest software Google uses for its Street View cars to read street numbers in images for Google Maps works so well that it also solves CAPTCHAs, those puzzles designed to defeat bots.
 
Canadian Teen Arrested for Heartbleed Hack
One week after the OpenSSL Heartbleed vulnerability was unveiled, Canadian authorities have made the first arrest -- a London, Ontario teenager -- connected to exploiting the security hole.
 
IBM Offers Security, Disaster Recovery as SoftLayer Service
New disaster recovery and security services for SoftLayer clients are being added by IBM. Big Blue said the new capabilities will speed cloud adoption by alleviating concern over business continuity.
 

Enterprise Hardware Spotlight
Vaio Fit 11A Battery Danger Forces Recall by Sony
Using a Sony Vaio Fit 11A laptop? It's time to send it back to Sony. In fact, Sony is encouraging people to stop using the laptop after several reports of its Panasonic battery overheating.
 
Continued Drop in Global PC Shipments Slows
Worldwide shipments of PCs fell during the first three months of the year, but the global slump in PC demand may be easing, with a considerable slowdown from last year's drops.
 
Google Glass Finds a Home in Medical Education, Practice
Google Glass may find its first markets in verticals in which hands-free access to data is a boon. Medicine is among the most prominent of those, as seen in a number of Glass experiments under way.
 

Mobile Technology Spotlight
Google Releases Chrome Remote Desktop App for Android
You're out on a sales call, and use your Android mobile device to grab a file you have back at the office on your desktop. That's a bit easier now with Google's Chrome Remote Desktop app for Android.
 
Amazon 3D Smartphone Pics Leaked
E-commerce giant Amazon is reportedly set to launch a smartphone after years of development. Photos of the phone, which may feature a unique 3D interface, were leaked by tech pub BGR.
 
Zebra Tech Buys Motorola Enterprise for $3.45B
Weeks after Lenovo bought Motorola Mobility’s assets from Google for $2.91 billion, Zebra Technologies is throwing down $3.45 billion for Motorola’s Enterprise business in an all-cash deal.
 

Navigation
CRM Daily
Home/Top News | CRM Systems | Customer Service | Business Intelligence | Sales & Marketing | Contact Centers | Customer Data | CRM Press Releases
NewsFactor Network Enterprise I.T. Sites
NewsFactor Technology News | Enterprise Security Today | CRM Daily

NewsFactor Business and Innovation Sites
Sci-Tech Today | NewsFactor Business Report

NewsFactor Services
FreeNewsFeed | Free Newsletters | XML/RSS Feed

About NewsFactor Network | How To Contact Us | Article Reprints | Careers @ NewsFactor | Services for PR Pros | Top Tech Wire | How To Advertise

Privacy Policy | Terms of Service
© Copyright 2000-2014 NewsFactor Network. All rights reserved. Article rating technology by Blogowogo. Member of Accuserve Ad Network.