@2, SQL Injection - a defacement, but not an exploit of the server.
The code is ancient and we have no source, but we have been working this about every day for over a year. The site is attacked each and every day and some days we lose. The servers/network have not been compromised, but the way the site was coded ignored the rules.
Today we added some new work around the site - again. Last week is was shell code to make sure the older anon sites like xbox, required log ins... next week, it will be something else.
I think we have shut this latest crew down - at least as concerns the attacks they have been using, but they'll be back again soon, I am sure. We're doing some other things, too - won't say what they are, but they are not passive. These guys hit multiple MS Sites, the UN, PC World, UNICEF, McDonalds... the list is endless.
We won't let them win though and soon enough, we'll launch the new site and I am sure the same day, idiots will attack it. I miss the old days when we treated terrorists like phking cockroaches - they could not hide from our kung fu for long and when found, it'd be quick and ended. This world needs to take the gloves off and get absolutely Roman on these guys. It won't though and not to long from now, it'll be in the streets in front of our own homes. Sorry for the downer, but I've seen it and seen what they do.
|