473,574 Members | 2,918 Online
Bytes | Software Development & Data Engineering Community
+ Post

Home Posts Topics Members FAQ

Hacker Problem

Hi,

I have a website hosted on MS IIS.

It has a news section fed by a database to allow the owners of the site the
ability to update the news pages themslves.

Last week a message was added by an Iranian hacker (see the end of this
post.)

What I don't understand is how they were able to do this.

The code checks for the existance of a session variable before alowing the
page to be displayed, so how could they create this variable?

Also, (from the log file,) they jumped right into the update page, not the
form where the message is created!

Any opinion would be greafully received, especially if a solution can be
suggested!!

Best reagrds

NEIL

Message:

H4cked By Mafia Hacking Team Black Hat - 16 September 2006 at 14:39

Iranian Hackers Are The Best---Darkl0rD Was Here---Fuck Pop---Only For
Islam

l_************* *@yahoo.com


Sep 25 '06 #1
2 1792

Neil wrote:
Hi,

I have a website hosted on MS IIS.

It has a news section fed by a database to allow the owners of the site the
ability to update the news pages themslves.

Last week a message was added by an Iranian hacker (see the end of this
post.)

What I don't understand is how they were able to do this.

The code checks for the existance of a session variable before alowing the
page to be displayed, so how could they create this variable?

Also, (from the log file,) they jumped right into the update page, not the
form where the message is created!

Any opinion would be greafully received, especially if a solution can be
suggested!!

Best reagrds

NEIL

Message:

H4cked By Mafia Hacking Team Black Hat - 16 September 2006 at 14:39

Iranian Hackers Are The Best---Darkl0rD Was Here---Fuck Pop---Only For
Islam

l_************* *@yahoo.com
He's been busy according to Google. And he seems to like ASP sites
that deliver stories in a file called news_item.asp and use the
querystring NewID. That's probably not all that you have in common.

http://www.hyannispoint.com/webdev/w...rabilities.asp

--
Mike Brind

Sep 25 '06 #2
>
He's been busy according to Google. And he seems to like ASP sites
that deliver stories in a file called news_item.asp and use the
querystring NewID. That's probably not all that you have in common.

http://www.hyannispoint.com/webdev/w...rabilities.asp

--
Mike Brind
Thanks Mike,

I will need to do some changes to prevent this from happening again.

Regards,

NEIL
Sep 26 '06 #3

This thread has been closed and replies have been disabled. Please start a new discussion.

Similar topics

3
2282
by: D E | last post by:
Hi. I am just curious how a hacker-type personality fits into a corporate lifestyle. I am only a student now. I have a govt. job now where i can go to school and work part time. I can take 2 hour lunches and as the stereotypical govt. worker goes about, work pseudo-deadline-less. However, with discussions from the contractors we hire...
13
3072
by: Aravind | last post by:
I would like to know in what manner dangling pointers affect the security of a application developed using C++.What are the loopholes that are created by dangling pointers and how they could be exploited by hackers?. Aravind
0
7753
by: Hystou | last post by:
Most computers default to English, but sometimes we require a different language, especially when relocating. Forgot to request a specific language before your computer shipped? No problem! You can effortlessly switch the default language on Windows 10 without reinstalling. I'll walk you through it. First, let's disable language...
0
8095
Oralloy
by: Oralloy | last post by:
Hello folks, I am unable to find appropriate documentation on the type promotion of bit-fields when using the generalised comparison operator "<=>". The problem is that using the GNU compilers, it seems that the internal comparison operator "<=>" tries to promote arguments from unsigned to signed. This is as boiled down as I can make it. ...
0
8265
jinu1996
by: jinu1996 | last post by:
In today's digital age, having a compelling online presence is paramount for businesses aiming to thrive in a competitive landscape. At the heart of this digital strategy lies an intricately woven tapestry of website design and digital marketing. It's not merely about having a website; it's about crafting an immersive digital experience that...
1
7847
by: Hystou | last post by:
Overview: Windows 11 and 10 have less user interface control over operating system update behaviour than previous versions of Windows. In Windows 11 and 10, there is no way to turn off the Windows Update option using the Control Panel or Settings app; it automatically checks for updates and installs any it finds, whether you like it or not. For...
0
8132
tracyyun
by: tracyyun | last post by:
Dear forum friends, With the development of smart home technology, a variety of wireless communication protocols have appeared on the market, such as Zigbee, Z-Wave, Wi-Fi, Bluetooth, etc. Each protocol has its own unique characteristics and advantages, but as a user who is planning to build a smart home system, I am a bit confused by the...
1
5645
isladogs
by: isladogs | last post by:
The next Access Europe User Group meeting will be on Wednesday 1 May 2024 starting at 18:00 UK time (6PM UTC+1) and finishing by 19:30 (7.30PM). In this session, we are pleased to welcome a new presenter, Adolph Dupré who will be discussing some powerful techniques for using class modules. He will explain when you may want to use classes...
0
5332
by: conductexam | last post by:
I have .net C# application in which I am extracting data from word file and save it in database particularly. To store word all data as it is I am converting the whole word file firstly in HTML and then checking html paragraph one by one. At the time of converting from word file to html my equations which are in the word document file was convert...
1
2265
by: 6302768590 | last post by:
Hai team i want code for transfer the data from one system to another through IP address by using C# our system has to for every 5mins then we have to update the data what the data is updated we have to send another system
0
1096
bsmnconsultancy
by: bsmnconsultancy | last post by:
In today's digital era, a well-designed website is crucial for businesses looking to succeed. Whether you're a small business owner or a large corporation in Toronto, having a strong online presence can significantly impact your brand's success. BSMN Consultancy, a leader in Website Development in Toronto offers valuable insights into creating...

By using Bytes.com and it's services, you agree to our Privacy Policy and Terms of Use.

To disable or enable advertisements and analytics tracking please visit the manage ads & tracking page.