Microsoft Yanks Security Site Poisoned With Porn
CWmike writes "Microsoft disabled the search tool on its Safety & Security Center on Saturday after attackers poisoned results with links to pornographic URLs. The company restored the website's search field early Monday afternoon ET. Alex Eckelberry, the general manager of GFI Software's security group and CEO of Sunbelt Software, said search poisoning is not unusual — but this is different. 'This is crafty,' Eckelberry said. 'This isn't normal search poisoning. It's poisoning the results with actual searches. Users were getting back a prior search as a search result.'"
That's not poisoning the results. That's a feature.
My postings are informational and does not constitute legal advice. Act on it at your risk.
Poisoned? Or made Better?
"I use a Mac because I'm just better than you are."
Better summary "Microsoft's own security web site hacked".
LOL
Was it safe sex, at least?
Well done.
If I were God, wouldn't I protect my churches from acts of me?
Microsoft security? since when?
This is a new feature created by Balmer (who's all for looking at porn, [have you seen him dance, sweat-stained armpits and all? I feel dirty just thinking of him going around shouting "Developers",]) and his lawyers (who are going to go after the ofender's website in an effort to collect advertising fees.)
MSBPodcast.com The opinions expressed here are my own. If you don't like 'em... Think up your own stuff.
searches using terms like "sex," "porn," "girl" and "streaming" on the Microsoft [Safety & Security Center] site were returning links to pornographic websites at or near the top of the results list
1. Put links to your porn site in MS' safety and security center search bar
2.Wait for people to search for porn in the safety and security center search bar
3.???
4. PROFIT!!!
I want to believe that this is just some automated process that searches the web for search bars and then tries to put in their own porn links. Alternatively, I want to believe that this is just a few porn marketers who are so dumb, they put links to their porn sites in a search field for MS safety and security. But I can't convince myself.
It's depressing to realize that there are actually people dumb enough to go to an antivirus website and start searching for porn.
"Dang! I musta gotten a virus! Don't know how, all I've been doing with this here computer is lookin up pictures of nekkid ladies. Well, better look for something to fix this from microsoft.... boring boring boring, I wanna see nekkid ladies! OOH! PORN!!"
I'm probably being stupid but if someone puts in a search like 'sex girl porn streaming' in some kind of search engine, how is it bad when the site returns pron links?
Korma: Good
'This isn't normal search poisoning. It's poisoning the results with actual searches. Users were getting back a prior search as a search result.'
If the code he writes is as clear as this, Microsoft is a hell to work at.
Don't even mention about his documentation.
http://it.slashdot.org/comments.pl?sid=2306598&cid=36701800
That others noted there in that exchange!
Plus, Microsoft's NOT going to get "suckered" by DoS, OR DDoS either as others have by LulzSec &/or Anonymous either:
http://www.networkworld.com/community/blog/microsoft-were-not-vulnerable-ddos-attacks
Simply because they "overbuilt their network" just as AMAZON has:
http://tech.slashdot.org/story/10/12/14/1851240/Why-Anonymous-Cant-Take-Down-Amazoncom
+ monitor it... & then turn it aside, accordingly!
(Thus, MS can see it coming a MILE away & compensate (by blocking the sources of attack @ the perimeter in firewalls, + even a botnet C&C server or bogus DNS server via DNSBL or even possibly HOSTS files))...
There's also a setting in modern MS IP stacks (BSD derived no less, best in the business) of:
SynAttackProtect
That helps mitigate DDoS attacks!
(That setting works in conjunction-combination with others parameters that set the "look aside/reject" amounts as the network admin sees fit too (they don't note that in the article above)).
APK
P.S.=> Like I said in my 1st link above? MS is performing LITERALLY, the BEST TEST there is, better than "pen testing" too!
(& THAT, is challenging hacker/cracker egos, to have THEM point out ANY POSSIBLE HASSLES IN YOUR NETWORK SECURITY (I did the same on IRC, decades ago circa 1994-2001 or thereabouts adminning the "Official Windows Help Channel" endorsed by no other/no less than K. Mardem Bey (creator of MIRC) himself!))...
... apk
Yanks withdraw porn site poisoned by Microsoft.
"You can lead a horse to water but a pencil must be lead!" - Stan Laurel
TRY do a DDoS on MS... why? It's Microsoft "Patch Tuesday", every 2nd Tuesday of the month... Because, that way??
Well - Any hacker/cracker's attempts @ doing DDoS would be amplified by the sheer # of people TRYING to get Windows updates as is, manually OR via Automatic Updates itself.
(Just a thought... not saying it's the right thing to do, but... perhaps a "bright-side" of it would be to TEST MS' claims & they might even appreciate it themselves, though I doubt it!)
APK
P.S.=> Not trying to give the likes of LulzSec, or Anonymous any ideas, or any like them (such as AntiSec either), but, that's how I'd do it... that would, probably FOR SURE, stress even MS' massive network setup, overbuilt as they are (like AMAZON's, with much excess capacity probably on fiber & OC3/OC12 setups & Full T1 @ a mininum), plus the SynAttackProtect setting in MS' BSD derived IP stack...
... apk