Hacked website embarrasses Microsoft

Microsoft's popular MSN website in South Korea was taken off-line for nearly half a day after hackers booby-trapped it to try to steal passwords from visitors.

    Microsoft says its English-language websites are safer

    The company said it was unclear how many Internet users might have been victimised.

    Microsoft said it cleaned the website, www.msn.co.kr, on Thursday and removed the dangerous software code that unknown hackers had added earlier this week.

    A spokesman, Adam Sohn, said Microsoft was confident its English-language websites were not vulnerable to the same type of attack.

    South Korea is a leader in high-speed Internet users worldwide.

    Microsoft's MSN web properties - which offer news, financial advice, car- and home-buying information and more - are among the most popular across the Web.

    The affected Microsoft site in South Korea offers news and other information plus links to the company's free e-mail and search services.

    Its English-language equivalent is the default home Internet page for the newest versions of its flagship Windows software sold in the United States.

    The Korean site, unlike US versions, was operated by another company.

    Under investigation

    Microsoft's experts and Korean police authorities were investigating, but Microsoft thinks the computers were vulnerable because operators failed to apply necessary software patches, said Sohn, an MSN director.

    "Our preliminary opinion here was, this was the result of an unpatched operating system"

    Adam Sohn,
    MSN director

    "Our preliminary opinion here was, this was the result of an unpatched operating system," Sohn said. "When stuff is in our data centre, it's easier to control. We're pretty maniacal about getting servers patched and keeping our customers safe and protected."

    MSN Korea said the only site affected by the hacking was the MSN Korea news site (news.msn.co.kr).

    MSN Korea said the partner company that runs the server for the news site is Etimes.

    There were no notices on msn.co.kr or the Microsoft Korea homepage informing users of the incident.

    Latest embarrassment

    Microsoft's acknowledgment of the hacking incident was the latest embarrassment for the world's largest software company, which has spent hundreds of millions of dollars to improve security and promote consumer confidence in its products.

    Security researchers noticed the suspicious programming added to the Korean site and contacted the company on Tuesday.

    The site was taken offline for 10 hours on Thursday.

    Sohn said Microsoft didn't know how long the dangerous programming was present.

    In recent days, no customers have reported problems stemming from visits to the Web site, he said.

    The hacker programme scanned visitors' computers and tried to activate password-stealing software that was found separately to exist on some hacked Chinese Web sites.

    SOURCE: Agencies


    'We scoured for days without sleeping, just clothes on our backs'

    'We scoured for days without sleeping, just clothes on our backs'

    The Philippines’ Typhoon Haiyan was the strongest storm ever to make landfall. Five years on, we revisit this story.

    How Moscow lost Riyadh in 1938

    How Moscow lost Riyadh in 1938

    Russian-Saudi relations could be very different today, if Stalin hadn't killed the Soviet ambassador to Saudi Arabia.

    Unification: Saladin and the Fall of Jerusalem

    Unification: Saladin and the Fall of Jerusalem

    We explore how Salah Ed-Din unified the Muslim states and recaptured the holy city of Jerusalem from the crusaders.