Fuel protestor hacks 168 websites

A hacker has successfully attacked more than a hundred corporate websites to post a message in support of demonstrators protesting against high fuel taxes in the UK.

Ian Lynch

A hacker has successfully attacked more than a hundred corporate websites to post a message in support of demonstrators protesting against high fuel taxes in the UK.

Herbless, who defaced nine local government web agencies last month and the Legoland.co.uk website last week, yesterday posted the pro-petrol protest on the front pages of 168 corporate websites.

Advertisement

It follows a similar attack earlier this week by a different hacker, who added a message protesting against oil prices to the website of the Organisation of Petroleum Exporting Countries (Opec).

Herbless posted his message on websites as diverse as specsavers.com, jobs.co.uk, itforhire.co.uk, travelfocus.co.uk and brand experts brandimage.co.uk among others.

The message has since been removed from the majority of the affected websites, but could still be seen at bobbybrowns.co.uk as of 4pm (BST) Thursday.

The text of the message claimed that 72 per cent of the price of petrol in the UK is tax, that production costs are one of the cheapest in Europe, and retail pricing the most expensive in Europe.

Herbless explained that: "This web page has been hacked as a public protest against government greed. I urge you to help the protest using any non-violent, non-abusive means possible."

His message ended by exhorting the public to support those on the picket lines. "If you live near a picket line, go and give your support. Applaud the lorry drivers. Make cups of tea and sandwiches for the picketers. Write to your MP pledging your support," wrote Herbless.

The hack appears to have used the same method deployed to post anti-smoking messages on the websites of a number of local government and government agency websites last month and a rant supporting DVD cracking software on the Legoland.co.uk website last week.

"I can confirm it uses the same method," Paul Rogers, network security analyst at MIS Corporate Defence Solutions, told vnunet.com.

When SQL server is set up there is a simple default password for the SQL administrator. Unless the system is being used on a trusted network, which the company owns entirely, Microsoft recommends this password be changed. In an unchanged configuration hacks can take place.

"We think he [Herbless] has performed a mass scan over a large range of sites checking for the MS SQL admin port, flagging insecure websites to be used in a masses hack. The hack itself was noticeable for the sheer number of websites involved," said Rogers.

Microsoft has said that the vulnerability exploited was a result of administrators not following basic instructions on configuring the software, rather than an intrinsic problem with its SQL server product.

  • Have your say
  • Send to a friend
  • Print
  • Digg
  • Reddit
  • Share

Tags:

Do you agree?

Further reading

HSBC web host under fire over fuel hack

The external supplier believed to be responsible for managing the areas of HSBC's website vandalised by a hacker this week has been criticised in connection with the incident.

Herbless - five weeks of 'hacktivism'

From Sheffield City Council to Hong Kong and Shanghai Banking Corporation, via Legoland.

Fuel protest hacker Herbless quits

EXCLUSIVE: Herbless, the hacker who defaced the websites of HSBC, Legoland and 450 others as part of the fuel protest in the last month, has announced his sudden exit from the hacking scene.

Security attitudes in the firing line

Prepare for the worst with a security policy that defends your network against hacker attacks and malicious emails.

Related whitepapers

Related jobs

Most watched

eu flag

V3.co.uk weekly debrief, 6 Nov 09

This week, Europe decides what to do with illegal file sharers

Intel unveils its micro server platform

Small-enclosure systems take aim at hosting market

IT white papers

Search white papers

Top categories

Poll

Impact of Information Overload poll

Impact of Information Overload poll

What is the biggest problem your firm faces as a result of the data explosion?

View poll results

Advertisement

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Spotlight

Piracy, privacy and processing power set to be hot topics for V3.co.uk Summit

Have you got a burning desire to quiz experts from...

iPhone

World's first iPhone virus surfaces

Images of 80s icon Rick Astley spell trouble

Airvana HubBub

Airvana debuts 3G femtocell for offices

HubBub improves indoor network coverage for businesses

shopping key

E-commerce on brink of SaaS revolution

Figleaves founder argues platform-as-a-service vendor will emerge to shake up...

Primary Navigation