Strewth! Aussie hacker on the rampage

Australian web servers have been getting a proper grilling from a defacer who seems bent on bringing poor security policies to the attention of the masses.

James Middleton

Australian web servers have been getting a proper grilling from a defacer who seems bent on bringing poor security policies to the attention of the masses.

Since the defacer known as L4m4 began his campaign at the end of last month, he has notched up 48 .au defacements.

Starting off with moloneyandpartners.com.au on 28 June, he left a message reading: "This is the first example of the lack of company focus in Australian IT security. Why is it that sys admins so often practise security by obsecurity?"

He continued: "I ask the Australian business community to step up their focus in their security procedures, or you will be next. No, your IT guy who you have trusted for so many years has no idea when they tell you that your web server is, 'safe as houses, mate' [sic]." He signed the message L4m4 Haxor and added the slightly cryptic, "WAKE UP WE ARE ALREADY BEHIND", which may imply that L4m4 is an Aussie himself.

Over the last seven days L4m4 has hit a further 47 Australian sites, the latest being duplex.com.au, which was defaced yesterday with the message: "0wned by L4m4. Once again really BAD Australian server security!! Your Security is only as good as your staff. L4m4."

All the targeted sites are running Windows NT and IIS webserver and some don't appear to have been fixed yet.

Although a number of the sites attacked seem to be patched against the notorious Unicode flaw, there have been a number of vulnerabilities recently which administrators have obviously not guarded against.

  • Have your say
  • Send to a friend
  • Print
  • Digg
  • Reddit
  • Share

Tags:

Do you agree?

Further reading

Microsoft warns of new IIS flaw

Microsoft yesterday released an advisory about another flaw discovered in its IIS web server software, a buffer overrun vulnerability that could allow an attacker to gain complete control of an affected web server.

Script kiddies target Microsoft IIS

Hot on the heels of Microsoft's announcement that there is a serious vulnerability inherent in its IIS 5 web server software, a tool which allows script kiddies to easily exploit the flaw is circulating on the internet.

Related white papers

Related jobs

Most watched

Black Hat: Speaking with Cisco CSO John Stewart

Security chief reflects on changes to the industry

Nuance Dragon 11

Nuance Dragon 11 video demo

We get a look at the speech recognition software in action

Analysis and Reports

MessageLabs intelligence report June 2010
In June, MessageLabs identified an average of 1,598 websites each day harbouring malware and other potentially harmful programs.

Six steps to data protection for SMEs
Today's data protection challenges pose substantial risks to companies of all sizes, but they pose the greatest risk to small and midsize businesses.

Poll

Gary McKinnon poll

Gary McKinnon poll

Should Gary McKinnon serve a prison sentence in the UK?

View poll results

White paper library

Attachmate

Smartstream

Keep up to date with the latest products, services and technologies from the world's leading IT companies; IThound.com brings you thousands of white papers, case studies and analyst reports.

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Spotlight

Steve Ballmer

Ballmer confirms Microsoft working on iPad rival

Windows 7-based slate device is top priority, says chief exec

Black Hat: Speaking with Cisco CSO John Stewart

Security chief reflects on changes to the industry

Facebook

Top 10 articles: Facebook pros and cons, and IPv4 warnings

V3.co.uk readers' most popular stories this week

Motorola Flipout hands on

The Motorola Flipout looks like a strange device with its...

Primary Navigation