Newsletters
News & Information for Technology Purchasers NewsFactor Sites:       NewsFactor.com     Enterprise Security Today     CRM Daily     Business Report     Sci-Tech Today  
   
This ad will display for the next 20 seconds. Click for more information, or
Home Enterprise I.T. Cloud Computing Applications Hardware More Topics...
Microsoft/Windows
DDoS Protection Powered By Verisign
Average Rating:
Rate this article:  
Syrian Electronic Army Hacks Microsoft -- Again
Syrian Electronic Army Hacks Microsoft -- Again

By Jennifer LeClaire
January 21, 2014 1:37PM

    Bookmark and Share
The attacks against Microsoft by the Syrian Electronic Army aren’t particularly sophisticated or novel. In going after Microsoft, the Syrian Electronic Army has used well-known breaching tactics. But the fact that the hacktivist group is continually successful shows that the industry needs to do a better job guarding against these tactics.
 


One particular hacktivist group seems to have a bone to pick with mighty Microsoft. First, the Syrian Electronic Army (SEA) hijacked a few of Redmond’s Twitter accounts. Next, the group invaded the company’s official blog. Now, the SEA has hacked into Microsoft’s Office Blogs site.

The hackers took to Twitter with proof positive in the form of a screenshot of the Microsoft Office Blog site. The SEA article was titled “Hacked by the Syrian Electronic Army” and was placed next to “Office 15-Minute Webinars” and “Top 5 Reasons to attend Sharepoint Conference 2014” on the blog’s home page.

Microsoft was quick to take down the article, but Google searchers can still find the cached image. The attack comes as Microsoft rolled out a new design for its Office Blog site -- complete with a new content management system (CMS) -- on Monday and the SEA’s Twitter message reads, “Dear @Microsoft, Changing the CMS will not help you if your employees are hacked and they don’t know about that.”

Breaking the Pattern

“A targeted cyberattack temporarily affected the Microsoft Office blog,” the company said in a statement. “The account was quickly reset and we can confirm that no customer information was compromised.”

We caught up with Ken Pickering, director of Engineering at CORE Security, to get his take on the Microsoft attacks. He told us the attacks aren’t particularly sophisticated or novel. The SEA, he noted, uses well-known breaching tactics and the fact that they are continually successful shows that the industry needs to do a better job guarding against these tactics.

“How do we break this pattern? Here’s the methodology I always advise: In order to prevent attacks, you need to think like an attacker. Consider how the ‘bad guys’ will try to break into your account and/or network, and counteract those tactics,” Pickering said. “We, as an industry, get hung up on testing for compliances and following 'best practices,' while losing sight of the ever-present battle with which IT and security personnel are consistently embroiled.”

Layered Defense Needed

Like Anonymous, the SEA has made quite a name for itself in the hacker world. The hacktivist group has targeted many media sites, including the New York Times, the Washington Post, the Financial Times, the Associated Press, The Guardian, Twitter and Twing, over the past year.

Kevin O'Brien, enterprise solution architect at CloudLock, told us these attacks are one more example of why companies need to implement properly layered defense strategies. Again, the issue with the DNS compromise was that a single point of failure -- the domain record company hacked, in this case -- resulted in "real-world" damages.

"Any time a single point of failure exists, one should assume that it will be the target of concerted effort on the behalf of criminals who wish to exploit, destroy, or compromise an organization," O'Brien said. "The coming days will tell for certain, but it's probably safe to assume that the Gray Lady's staff had not considered whether or not their DNS host was properly auditing and securing their environment. In turn, the DNS host was probably not doing the same for their resellers."
 

Tell Us What You Think
Comment:

Name:



Salesforce.com is the market and technology leader in Software-as-a-Service. Its award-winning CRM solution helps 82,400 customers worldwide manage and share business information over the Internet. Experience CRM success. Click here for a FREE 30-day trial.


 Microsoft/Windows
1.   BBM Now Available on Windows Phone
2.   Microsoft Spreads Cortana Abroad
3.   China Puts Microsoft Under the Lens
4.   Win Phone 8.1 Update Already on Way
5.   Yammer Moved to Office 365


advertisement
China Puts Microsoft Under the Lens
Official anti-monopoly probe launched.
Average Rating:
Microsoft CEO Sees 'Bold' Plan Ahead
With unified Windows for all platforms.
Average Rating:
Design Central to Microsoft Future
New ethos a break from functional past.
Average Rating:
Product Information and Resources for Technology You Can Use To Boost Your Business

Network Security Spotlight
Ruling Against Microsoft Raises E-Mail Privacy Concern
Microsoft has been ordered to hand over e-mails to law enforcers in the United States as part of a criminal investigation, even though the e-mail is stored at a data center in Dublin,Ireland.
 
Twitter Buys Password Manager Startup Mitro
Following on the heels of another acquisition earlier this week, Twitter is adding to its fold a password-manager security startup called Mitro, which in turn is releasing its code as open source.
 
Government Requests for Customer Data Skyrocket
Requests for customer data from the government jumped 50 percent in the first half of 2014, according to Twitter, which received more than 2,000 requests for user info from gov't agencies.
 

Navigation
NewsFactor Network
Home/Top News | Enterprise I.T. | Cloud Computing | Applications | Hardware | Mobile Tech | Big Data | Communications
World Wide Web | Network Security | Data Storage | CRM Systems | Microsoft/Windows | Apple/Mac | Linux/Open Source | Personal Tech
Press Releases
NewsFactor Network Enterprise I.T. Sites
NewsFactor Technology News | Enterprise Security Today | CRM Daily

NewsFactor Business and Innovation Sites
Sci-Tech Today | NewsFactor Business Report

NewsFactor Services
FreeNewsFeed | Free Newsletters

About NewsFactor Network | How To Contact Us | Article Reprints | Careers @ NewsFactor | Services for PR Pros | Top Tech Wire | How To Advertise

Privacy Policy | Terms of Service
© Copyright 2000-2014 NewsFactor Network. All rights reserved. Article rating technology by Blogowogo. Member of Accuserve Ad Network.