15 Sep 2000
A hacker has successfully attacked more than a hundred corporate websites to post a message in support of demonstrators protesting against high fuel taxes in the UK.
Herbless, who defaced nine local government web agencies last month and the Legoland.co.uk website last week, yesterday posted the pro-petrol protest on the front pages of 168 corporate websites.
Further reading
It follows a similar attack earlier this week by a different hacker, who added a message protesting against oil prices to the website of the Organisation of Petroleum Exporting Countries (Opec).
Herbless posted his message on websites as diverse as specsavers.com, jobs.co.uk, itforhire.co.uk, travelfocus.co.uk and brand experts brandimage.co.uk among others.
The message has since been removed from the majority of the affected websites, but could still be seen at bobbybrowns.co.uk as of 4pm (BST) Thursday.
The text of the message claimed that 72 per cent of the price of petrol in the UK is tax, that production costs are one of the cheapest in Europe, and retail pricing the most expensive in Europe.
Herbless explained that: "This web page has been hacked as a public protest against government greed. I urge you to help the protest using any non-violent, non-abusive means possible."
His message ended by exhorting the public to support those on the picket lines. "If you live near a picket line, go and give your support. Applaud the lorry drivers. Make cups of tea and sandwiches for the picketers. Write to your MP pledging your support," wrote Herbless.
The hack appears to have used the same method deployed to post anti-smoking messages on the websites of a number of local government and government agency websites last month and a rant supporting DVD cracking software on the Legoland.co.uk website last week.
"I can confirm it uses the same method," Paul Rogers, network security analyst at MIS Corporate Defence Solutions, told vnunet.com.
When SQL server is set up there is a simple default password for the SQL administrator. Unless the system is being used on a trusted network, which the company owns entirely, Microsoft recommends this password be changed. In an unchanged configuration hacks can take place.
"We think he [Herbless] has performed a mass scan over a large range of sites checking for the MS SQL admin port, flagging insecure websites to be used in a masses hack. The hack itself was noticeable for the sheer number of websites involved," said Rogers.
Microsoft has said that the vulnerability exploited was a result of administrators not following basic instructions on configuring the software, rather than an intrinsic problem with its SQL server product.
Latest stories from Security
Related articles
Related jobs
Poll
What is the most important IT priority for your company this year?
Sneak peek at the forthcoming glass-based machine
Connect with V3.co.uk
This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes
Why good data management at all levels is essential in the modern business (video, 6mins)
Skills: Open Source, C, C++, Java, Python, SQL, Developer...
ActionScript 3, Flex, Javascript, HTML, CSS, XML My...
My client is a real-time advertising and content 'start...
C++, UNIX, Multithreading My client is a leading software...
Keep up to date with the latest products, services and technologies from the world's leading IT companies. IThound.com brings you over 2,000 white papers, case studies and analyst reports.
Do you agree?
Best con going
Looking for information on volume sales of petrol in the UK (don't think this includes diesel, but correct me if I'm wrong) I find the figure of 26 thousand million litres of petrol were sold in the UK in 2005. Presumably, that has increased since. Allowing a conservative estimate of the tax on that being about 70% or so, and allowing for an average price of arount 90p a litre over that yearly period, I guess that the government took around 70% of 234.000.000.000 (234 thousand million pounds) in 2005, and more each year since. Thats only on sales of fuel. In short, please tell me how we are not being conned and ripped off at every stage by an increasingly incompetent government. Stop bending over for them people, say no more now.
Posted by: John Nesbitt 01 Jul 2009