Skip to main content

How The Murdoch Email And Website Hacks Could Happen To You

creepy hacker

This week News Corp. execs James and Rupert Murdoch were dragged before a investigatory committee of Parliament over the U.K.'s phone-hacking scandal. Meanwhile hacktivists LulzSec decided to take matters into their own hands, and targeted the website of News Corp. paper The Sun, replacing its homepage with a faked edition. Shortly afterward, LulzSec said it had also acquired a huge amount of corporate emails from the Murdochs. They've since pledged not to release them, lest they compromise ongoing legal cases against News Corp. and its executives, but the Murdochs may still face having their email dirty laundry aired in the future.

How is this kind of hack pulled off? We spoke to our expert adviser, Nick Percoco of Trustwave's Spiderlabs, to gain an insight, based on his expertise as an ethical hacker--hired to pull off these kinds of attack by companies themselves.

The Website Hack, Simply Done

Website redirects are pretty common nowadays--it's a relatively low-grade kind of hack, and the other large online hacktivist group Anonymous was itself a victim of a website hack this week.

One redirect involves gaining access to the Domain Name Server infrastructure--the code and hardware that directs a visiting web surfer's browser to an IP address when you type in a web URL to a browser address bar (because servers call themselves a relatively boring set of numbers rather than companynameX.com). Hackers can do this by either a frontal password-cracking assault on the domain account at the relevant third party Domain Name managing company, or by pulling off a social engineering trick.

As Nick points out to us, it's relatively easy to call up a company like this, acting all frustrated and pretending to be a power user from News Corp. (or whatever the target is, picking something newsy) and say "this is related to the phone hacking scandal and we need to make some DNS changes and blah blah...I need to reset my password." If you're lucky, the person you're speaking to will be fairly junior in the company, and probably in their career, and with chutzpah you get the passwords and then access. 

Percoco highlights how powerful this attack is: "If I were to gain access to someone's DNS system, I could redirect the website in probably 30 seconds." Because once you're in, it's just a question of filling in a webform, or editing a file, clicking "save" and then anyone visiting companynameX.com is redirected to a different IP address, where you have your alternative web page.

The Website Hack, Done More Cleverly

A more sophisticated attack on a target, Percoco says, involves "trying to hack into their infrastructure directly"--more like the hacking you see in the movies. In his work, Percoco's worked with larger companies that have thousands of sites in their infrastructure. Some may be old, set up for something like a marketing campaign that has since ended. 

This is the hacker's in-point, because a site that's been sitting online for several years, without being upgraded or checked from a security standpoint, is bound to have vulnerabilities. This is because the cutting edge of cybersecurity and attacks will have moved on long since, but the old site hasn't been maintained to keep up. A very similar method was actually used by the LulzSec to access the Sun's online presence, through a "retired" server that was used to manage the Sun's micro website content.

A third way in, especially with a site like the Sun, is through its Content Management System, the code that organizes how stories are published to its website. By hacking into this, via a known exploit or simply by cracking a user password (such as may be used by a journalist working remotely, to gain access to their account), hackers can then gain access to the published web content on a target's website directly, and chaos will ensue. It's not always tricky to do this, because we are all pretty bad at using secure passwords. An attack like this is roughly what hit Gawker Media earlier this year

The Email Hack

LulzSec's attack on News Corp.'s email system has potentially more damaging implications. It's easy to restore your website, but there's possibly plenty of compromising, or at least private, data in a high-profile user's email account.

If LulzSec gained access to News Corp.'s web servers and other systems, presumably they could also gain access to other accounts, says Percoco, perhaps even an IP administrator's account or someone else who has access to mail servers. Via these sources, hackers could gain direct access to the company email account. 

"Firstly I'd try to see if they had any external web-based mail system, like a Microsoft Active Sync system," says Percoco, and then it's a game of working out a user name and guessing a user's weak password (and hoping the system lets you try a large number of times without locking the account).

Or, assuming you've gained access to the company's network via a website hack, you may be able to work out where user-account data is kept and then extract it. When you crack it, offline, you'd have a list of usernames and passwords directly. Then it would be as simple as pretending to be a new device like an iPhone syncing up to a perfectly normal user account, and you'd identify to the network as a real user--and then their whole email history is synced to your device. This likely wouldn't raise red flags with IT since it's exactly what happens when a genuine user connects to a real account.

What You Can Do To Protect Yourself

News Corp. was pretty aggressively penetrated by hackers, who seem to have carried out a coordinated and sophisticated assault. But many companies are similarly vulnerable and would have their business compromised if 4GB of executive email was sequestered and plopped onto a file-sharing website. The defenses are manyfold, but pretty straightforward: Keep your web properties well managed, and ensure that no old "appendix" webpages are left online with vulnerabilities ready to be infected. This plan could even involve making sure there's good information sharing among IT staff--who tend to have a pretty high churn rate. Companies can check their online systems repeatedly, and also hire white-hat hackers to detect loopholes on contract--before a hacker with malicious intent does it for you.

How The Murdoch Email And Website Hacks Could Happen To You
Kit Eaton
Fri, 22 Jul 2011 22:15:30 GMT

Comments

Popular posts from this blog

3 Questions to Ask Yourself Before Diving Into Becoming an Entrepreneur

This post originally appeared in Inc . The pursuit of an entrepreneurial venture feels a lot like jumping off a high cliff into deep water. It's scary at first and there's no going back once you leap, but after you muster up the courage, it is one of life's most exhilarating experiences. Before you hastily rush into a triple backflip dive, it is best to do some homework and prepare. Is the water deep enough to attempt a safe dive? Has anyone jumped from this point before (and survived)? After I jump, is there a way for me to get back to land safely? Is getting hurt worth the risk? Entrepreneurship is no different. Success is about more than just quitting your job and leaping head over heels into your venture. You first have to do your homework. It's hard to define the right time to begin a new endeavor, and the reality is no time is ever going to be perfect. But before you take the plunge, here are three questions to consider. 1) Are you personally a...

Stop Playing the Victim with Your Time

This post originally appeared in HBR "It’s just not fair. There’s always too much to do. Everyone just keeps piling more work on me. I feel so helpless." Sound familiar? If so, you’re not alone. Many people feel like they have a crushing number of requests coming at them from every side that make them a victim to their circumstances. They see forces outside themselves as the reason that they don’t have time to exercise, can’t leave work at a reasonable time, or just generally struggle to get everything done. Although there are occasionally situations that are outside of your control — that recent bout with the flu, for example — most aren’t. And even though it can feel gratifying in the short term to blame others for your situation, this attitude toward your  time investment will leave you truly powerless in the long run. When you play the victim with your time, everything around you suffers. You’re constantly on edge in your interactions with others because you f...

7 Ways to Build a Focused Team

This post originally appeared in Inc. Buzzing about which new startups will prosper and which will flop is a favorite pastime in Silicon Valley. But a new company's prospects aren't based on just what the company creates, says Stanford professor  Lindred Greer . They're also based on the people creating it and, more important, how they treat one another.  "Startup success is as much about managing the people as it is about creating the product," says Greer, an organizational behavior professor at Stanford Graduate School of Business. Based on her research on entrepreneurship and team dynamics, Greer will teach a new course at Stanford GSB this spring focusing on the unique team-dynamic challenges faced by early-stage startups. In a recent interview, she offered tips for managing startup teams. Be Aware of Culture in Early Stage Startups The culture of early stage startups forms the backbone of the culture the company will have in later years. Therefor...