Microsoft Programming Contest Hacked and Defaced
davidmwilliams writes "Microsoft followed their major annual Tech-Ed event in Australia with a week-long programming contest called 'DevSta,' to find 'star developers.' While the quantity and quality of submissions suggest a poor turnout, it certainly caught the attention of at least two hackers who left their mark. Here is the low-down on the contest, what happened, by whom, and screen shots for posterity in case it's been fixed by the time you read this. And unless the volume of submissions increase dramatically within the next few hours, someone may be awarded an Xbox for doing nothing more than rewriting the Windows calculator as a .NET app."
Nooo.
This isn't news. If it were, it'd carry a headline like "Microsoft Programming Contest Security Thwarts Hackers" and be about how Microsoft employed some effective security measures without subjecting all applicants to activity-monitoring rootkit DRM and attendees to cavity-searches.
Fool me once, shame on you. Fool me twice, watch it -- I'm huge!
Nobody wants an XBox that badly do they? :-)
If I had an Ass, I'd call it Fanny Bottom, then I could slap my Ass; Fanny Bottom, on the Arse.
So it's like all their other software then?
No folly is more costly than the folly of intolerant idealism. - Winston Churchill
Screenshots dont look too spectacular - how do we know they didnt just create a bunch of accounts and post shit on their website.
Or is that what passes off as hacking these days?
They really shouldn't be running HTTP daemons without SELinux running. Such services are just too popular a target.
"Thanks for all the money you paid to us. We've used it to buy off ISO among other things" -Microsoft
What about the guy who found a security hole on IIS and wrote and exploit for it? that sounds way cooler than rewriting calc.
--
Stay tuned for some shock and awe coming right up after this messages!
Interesting story but why not post the one about Microsoft releasing Mono 2.0? (Ars)
To me it would appear that someone submitted entries with an bogus title and accompanying description. Hacked? Hardly. What surprises me is that no one submitted Viagra programs with accompanying links in the description.
These aren't the droids you're looking for. Move along.
Anyone wonder why only some pissed off script kiddies are playing?
Engineering is the art of compromise.
If you want a prize, why not come up with a hack that releases OEMs from their contractual obligation to pre-load Windows? Or maybe a hack that dis-allows Microsoft from counting the sale of a Dell server with Linux installed as a sale of a Windows license. How about a hack that gives the ISO people a spine and some cojones?
Now, those would be worth a prize.
"Why don't they get a little more real... say MSDN subscription for life? Yeah, I suppose that is too much to give to a MS developer... sheesh"
Maybe because developers like to get away from WORK now and then.
Shai Schticks:"You don't make peace with friends, you make peace with enemies"
If I write an app for Apple's iPhone, I run the chance of being denied, but I could make lots of $$$. If I write an app for MS, I could get some lovely departing gifts. Tough choice.
Impetuous! Homeric!
Hacked would be a site defaced.
This looks like someone made some random submissions.
I speak from about 15 years experience at multiple companies and not bias that the more "Microsofty" the programmer is, the worse they are.
The current project I am on is full of the Microsoft way of doing things. And get this:
We have a Linux server and Windows client, and they designed a Windows Registry as an interface to the database on Linux. They are having piss-poor performance due to many design issues related to this thing. I should probably post it to Daily WTF. I mean WTF indeed.
Who wants to be a Microsoft Star!! Wooohoo!
1. Microsoft Programming Contest Hacked and Defaced.
2. Story posted to Slashdot and nobody cares.
3. Posting Anonymously to protect my kharma - priceless.
Since production started (of modern ABS bricks) it's estimated total production has only reached 350 billion.
:-)
Now put your $850 billion dollars in context, if it was in $1 bills, how long would it take to print the little buggers.
If I had an Ass, I'd call it Fanny Bottom, then I could slap my Ass; Fanny Bottom, on the Arse.
It's no Atari Computer Camp, that's for sure. For one thing, I heard there was actually a female applicant.
They are. And don't call me Shirley.
Cheers,
"What in the name of Fats Waller is that?"
"A four-foot prune."
The parent post warrants a +1 Funny more than a troll. :)
Cheers,
"What in the name of Fats Waller is that?"
"A four-foot prune."
> Cavity search is news to me. Where do I sign up?
Ask Mr. Goatse. I think there's a .NET version of it now, too!
I want to see the calculator wins, it would be damn funny if the STAR application is the calculator.
He clearly means Dentistry software. Manage the patient's records, search cavities...
My first Journal Entry ever, in 8 years! http://slashdot.org/journal/365947/aphelion-scifi-fantasy-horror-poetry-webzine
I'm using the INTERNETS!
Assume I was drunk when I posted this.
Microsoft probably just hired some hackers to deface the site to generate enough publicity to get it onto /. to attract some real talent so they could save face by getting a submission better than Windows calculator. Don't give in during the last few hours.
I had now idea this contest was going on. I'd have been happy to enter. Throwing together something small, but better than a .Net calculator, for a chance at a free XBox? Absolutely!
Way to go, Microsoft Marketing dept!
"Upon attaching the waterblock to my penis, I began to notice that I know nothing about computers." -- JRockway
Another cheesy reality tv contest coming to you soon.. "So you think you can hack ?"
In other news, Alanis Morissette is found posting on Slashdot under the name 'db32'.
It's about time that someone rewrote that damn calculator. Now can finally add it to the new naming scheme:
Windows Live Calculator
What happens next? ...
Profit!
The grand prize on offer includes airfare to Las Vegas, accommodation at the Venetian and tickets to the MIX09 Developer Conference in March next year, along with Visual Studio 2008, an Xbox 360 Elite console pack and a Samsung Omnia mobile phone. Runners up win various combinations of Visual Studio, Xbox 360 Elite packs and Wireless Entertainment Desktop 8000 keyboard and mouse combos.
It's not stupid. It's Advanced.
HACKED BY BENJYMOUSE HACKED BY BENJYMOUSE HACKED BY BENJYMOUSE There, now I "hacked" slashdot the very same way. The "hacked" and "defaced" site is nothing more than submissions (like comments on slashdot) with "HACKED BY OVERLORD" text. No JavaScript injection, no SQL injection, no nothing. Some medias will go to any length to capture traffic. sheesh.
Reading slashdot one-liner: (irm http://rss.slashdot.org/Slashdot/slashdot).rdf.item | fl title,desc*
The screenshots look like these "hackers" defaced the site by ...
*drum roll* ... posting to a forum!!!
OMG /. HACKED BY NARCBERRYHACKED BY NARCBERRYHACKED BY NARCBERRYHACKED BY NARCBERRY
Modding me -1 troll doesn't make me wrong.
Who the hell writes a metric clock without understanding the metric system?
Swatch, for one. And the Chinese before them.
My favorite submission was posted by Captain Obvious and his uber cool "windows media radio 4 windows mobile" application.
Description:
The past: Listening mp3s
The future: Listening streaming music.
Watch out Apple!
commodoresloat writes "Slashdot followed their major annual asteroid-collision article with an article called 'Microsoft Programming Contest Hacked and Defaced.' While the quantity and quality of posts suggest a poor turnout, it certainly caught the attention of a hacker named 'BENJYMOUSE' who left his mark. Here is the low-down on the slashdot post, what happened, by whom, and screen shots for posterity in case it's been fixed by the time you read this. And unless the quality of posts increase dramatically within the next few hours, someone may be awarded mod points for doing nothing more than rewriting the *BSD troll as an anti-M$ post."
Alanis Morisette is either very stupid (not a single line in her song is about irony) or very clever (for calling a song about sarcasm Ironic).
"Why don't they get a little more real... say MSDN subscription for life?"
A life sentence? Wouldn't 10 to 20 with chance of parole be more in line with a first offense of this nature?
Down With Slashdot BETA!!! I've been around the corner and seen the oliphant; you can only abuse me from your perspecti
"And unless the volume of submissions increase dramatically within the next few hours, someone may be awarded an Xbox for doing nothing more than rewriting the Windows calculator as a .NET app."
What's wrong with that? That's 'Innovation' in the post-Microsoft world. ;)
> When asked to comment on Gobi, one volunteer replied, "It is just like jumping out of an airplane with your parachute on fire!"
Fixed that for ya.
This is what we need in the programming world, more developers with an ego complex. "Star developers", way to go, when a part of skill lies deeply in being able to communicate and organize oneself in a community or company.
"Star developers" sounds like these people need three flatscreen monitors, a massage chair and a personal makeup assistant to be happy.
The reason why no serious programmers will turn up at this event is the same reason, why I'm not at this event: I am busy doing serious, real life code. I have no time for marketing shams.
Do not trust this signature.
If you are not good enough to get the best work enviroment possible, then well, that sucks for you.
I doubt you are even a decent developer anyway, flatscreen monitors? Hello? Can you even buy CRT's anymore that are cheaper then totally flat LCD's.
If your boss did a cost/benefit study he would quickly realize that a good chair and interface pays for itself. A good chair allows you to remain comfortably seated for longer. Same with a quiet office, more hours spend coding means more money made. Three screens isn't actually that expensive since they typically last several years. I personally only use dual screens and it saves me a lot of time, since I can have all windows I need open at once without switching and have all the info available at once. If I am on a laptop I notice a reduction in speed as I have to spend time tabbing between windows to get all the info I need.
The cost? About a 1000 euro more. Compared to my salery and general costs of employement, office space, parking space, insurance and everything else it is trivial. So a new decent computer for a developer costs say 4000 instead of a budget dell for 400. Big deal. Hiring a good developer costs FAR more. Loosing a good developer even more.
For fun I keep track of job offers, sadly most companies cannot even begin to afford me because they just don't value developers. We are NOT secretaries or accountants. We are skilled craftsmen and they expect the best and can get it if they got the balls.
MMO Quests are like orgasms:
You may solo them, I prefer them in a group.
HACKED BY OV3RLORDHACKED BY OV3RLORDHACKED BY OV3RLORDHACKED BY OV3RLORD...
It's good to be a DevSta!
Lame hack, but much more lame trying to pass this as news......
don'tcha think?
Had I known it were news, I'd have contacted local news media rather than the modest response of contacting my web hosting provider and asking that they patch the vulnerability in their SQL server.
~Mike (Titan_X)
So the moderator somehow thinks that hackers should be lauded?
The moderator is a troll.
http://www.itwire.com/content/view/21044/53/ Microsoft has responded with their side.
Common Sense isn't as Common as people think...
After working for Microsoft, I had a lowered respect for them, but now after this kind of chickenshit stuff, I have new found respect for them (unless its an inside job). Its creating thats challenging, destroying is easy. Most any engineer won't crack, because they create, not destroy, when in fact they can cause the most havoc, but its not worth it due to integrity, and the fact that its too easy.
I just installed VS2008 and IE8 beta, dragged the "Web Browser" control on to a form and threw in a quick back button.
Now where's my Xbox?
Well when you can buy one for $200 then factor it the hourly rate of a (good) programmer, it's not exactly a good time investment now is it?
More specifically, I think they posted a bunch of bogus entries to the contest. Wow. So original and daring. We should just quit the internet now.
write a bat script that wipes out windows and installs Linux. Offer it as a security patch.
Injecting ASP code into an user submission field? Don't make me laugh. These "hackers" are more like script kiddies trying to act cool.
I am not devoid of humor.
This isnt digg, my bad!
-taosk8r