Newsletter:

Skip Navigation LinksHome > News > Security > Web site defacement risk debated

Web site defacement risk debated

1 January 2000 12:00AM
Tags: web | site | defacement | risk | debated

Australian security advisory body AusCERT has written off a warning about a Web site defacement contest for hackers, arguing that there is only a negligible increase in threat.

Security companies and government advisory agencies yesterday warned that computer crackers were coordinating a mass Web site defacement attack for July 6 (US time).

The so-called "Defacer's Challenge” aims to deface up to 6,000 Web sites over the course of six hours, according to warnings from the US Department of Homeland Security.

However, Brisbane-based security advisory body AusCERT said that there was “only a negligible increase in the threat arising from this challenge”.

“This does not mean the threat from Web site defacement itself is negligible; this threat is pre-existing and is assessed to be medium to high under most circumstances,” AusCERT stated.

According to the advisory body, this threat is one of the most common activities undertaken by hackers. It could include conducting scans of broad IP address ranges to identify vulnerabilities in Web servers, which can enable an attacker to deface or gain privileged access to Web server data and possibly other network systems.

“Web site defacements around the globe, including within Australia and New Zealand, are a common occurrence for these reasons," AusCERT stated in an advisory. "The most reliable indicator of whether an organisation's Web site will be defaced or otherwise compromised is if the organisation's Web server is not appropriately secured, or if it exhibits known vulnerabilities which can be exploited.”

AusCERT expects most servers to be compromised prior to the date, but defaced during the competition.

The organisation urged administrators to check systems for signs of compromise. It also reminded network security administrators of standard best practices for minimising the chances of defacement. These include ensuring system and server software is kept up to date to avoid previously identified vulnerabilities; and disabling unnecessary network services and ports.

In related news, the hacker Web site used to advertise the Defacers Challenge was reportedly removed from the Web by the site's hosting service, Affinity Internet in the US.

   


Ads by Google


Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 




Product Reviews

Star Rating
Blink is an endpoint security product that functions as a network protector.
Star Rating
EndPointSecurity installs a small footprint agent on the machine.
Star Rating
GuardianEdge Device Control is a component of the more robust GuardianEdge Data Protection Platform.
Star Rating
Lumension offers a pair of products, Sanctuary Application Control and Sanctuary Device Control, that work in...
Star Rating
First, it is important to note that unlike previous versions of ZENworks, Novell ZENworks Endpoint Security...
Product Reviews now available on iTnews.com.au

TopTopics
(3544) -  telstra
(2556) -  broadband
(2526) -  network
(2271) -  microsoft
(1889) -  apple
(1540) -  security
(1427) -  television
(1356) -  mobile
(1288) -  intel
(1270) -  researchers
(1191) -  samsung
(1190) -  led
(1186) -  vmware
(1116) -  iphone
(1099) -  nbn