Language Selection

English French German Italian Portuguese Spanish

MSN site hacking went undetected for days

Filed under
Microsoft
Web

Password-stealing software planted by hackers was active on Microsoft's popular MSN Web site in South Korea for days before the world's largest software company learned about the break-in and removed the computer code.

Police investigators and Microsoft specialists are continuing to search for clues to the culprits behind this week's high-profile computer break-in. More details emerged Friday about the hacking, which targeted subscribers of an online game called "Lineage" that is popular in Asia.

Microsoft Corp. said it had cleaned the Web site, www.msn.co.kr, and removed the software code that had been planted on its news page. It said another company that operates the MSN Korea site apparently failed to apply necessary software patches, leaving its server computers vulnerable.

Security researchers at San Diego-based Websense Inc. discovered the break-in late Sunday during routine scans it makes against more than 250 million Web sites each week looking for sources of viruses and other infections.

A previous inspection by Websense of the MSN Korea site the evening of May 27 did not detect the dangerous software.

"Our alarms went off (Sunday). We noticed it was infected," said Dan Hubbard, its senior security director.

Hubbard said Websense researchers investigated further and quickly updated protective software to keep its own corporate customers safe. It did not successfully reach Microsoft officials to warn them about the break-in until midday Tuesday, a day after the Memorial Day holiday weekend.

Microsoft said it removed the password-stealing software from the MSN site hours later.

The chronology suggests the hackers could have harvested stolen passwords from visitors to the MSN site for up to three days. But their target -- passwords to game accounts -- lessened the significance of the break-in since the hacker software appeared not to collect any network or banking passwords.

The Lineage game and its successor boast more than 4 million subscribers, mostly in Asia, who pay about $15 each month, said Mike Crouch, a spokesman for the U.S. subsidiary of South Korea-based NCSoft Corp. Crouch said he was unaware of any significant increase in complaints by subscribers about stolen passwords tied to the Microsoft break-in.

South Korea is a leader in high-speed Internet users worldwide. Microsoft's MSN Web properties -- which offer news, financial advice, car- and home-buying information and more -- are among the most popular across the Web.

A Microsoft spokesman, Adam Sohn, said the company was confident its English-language Web sites were not vulnerable to the same type of attack.

Microsoft shares fell 36 cents to close at $25.43 on the Nasdaq Stock Market. They have traded in a range of $23.82 to $30.70 over the past 52 weeks.

Associated Press

More in Tux Machines

Librem 5 Phone Progress Report

  • Librem 5 Phone Progress Report – The First of Many More to Come!
    First, let me apologize for the silence. It was not because we went into hibernation for the winter, but because we were so busy in the initial preparation and planning of a totally new product while orienting an entirely new development team. Since we are more settled into place now, we want to change this pattern of silence and provide regular updates. Purism will be giving weekly news update posts every Tuesday, rotating between progress on phone development from a technology viewpoint (the hardware, kernel, OS, etc.) and an art of design viewpoint (UI/UX from GNOME/GTK to KDE/Plasma). To kickoff this new update process, this post will discus the technological progress of the Librem 5 since November of 2017.
  • Purism Eyeing The i.MX8M For The Librem 5 Smartphone, Issues First Status Update
    If you have been curious about the state of Purism's Librem 5 smartphone project since its successful crowdfunding last year and expedited plans to begin shipping this Linux smartphone in early 2019, the company has issued their first status update.

Benchmarking Retpoline-Enabled GCC 8 With -mindirect-branch=thunk

We have looked several times already at the performance impact of Retpoline support in the Linux kernel, but what about building user-space packages with -mindirect-branch=thunk? Here is the performance cost to building some performance tests in user-space with -mindirect-branch=thunk and -mindirect-branch=thunk-inline. Read more

An introduction to Inkscape for absolute beginners

Inkscape is a powerful, open source desktop application for creating two-dimensional scalable vector graphics. Although it's primarily an illustration tool, Inkscape is used for a wide range of computer graphic tasks. The variety of what can be done with Inkscape is vast and sometimes surprising. It is used to make diagrams, logos, programmatic marketing materials, web graphics, and even for paper scrapbooking. People also draw game sprites, produce banners, posters, and brochures. Others use Inkscape to draft web design mockups, detail layouts for printed circuit boards, or produce outline files to send to laser cutting equipment. Read more

Behind the scenes with Pop!_OS Linux

In October, Linux PC maker System76 released its homegrown version of Linux, Pop!_OS, giving users the choice between its legacy Ubuntu operating system or the new Pop!_OS flavor of Linux. Recently Opensource.com gave away a System76 laptop with Pop!_OS installed, which made me curious about the company and this new version of Linux, so I spoke with Cassidy James Blaede, Pop!_OS's user experience (UX) designer. Blaede joined System76 in 2014, fresh out of college at the University of Northern Iowa and marriage to his wife, Katie. While in college, he co-founded the elementary OS project and interned at UX consultancy Visual Logic, both of which influenced his work for System76. He started at System76 as a front-end developer and was later promoted to UX architect. Read more