On CBS MoneyWatch: 5 Things You Should Buy at Walmart
BNET Business Network:
BNET
TechRepublic
ZDNet

June 2nd, 2008

Phoenix Mars Lander's mission site hacked

Posted by Dancho Danchev @ 8:48 am

Categories: Black Hat

Tags: Phoenix Mars Mission, Security, Hacking, SQL Injection, Web Site Defacement, Dancho Danchev

With the world’s eyes on the latest multimedia streaming straight from Mars, during the weekend the Phoenix MarsPhoenix Mars Lander mission hacked Mission’s site got hit twice, first by an Ukrainian web site defacer who posted a message at the site’s blog, and hours later, the Turkish “sql loverz crew 2008″ redirected the official mission’s site, as well as the Lunar and Planetary Laboratory site to a third-part location serving the defaced page. The Phoenix Mars Lander mission’s security staff are aware of the issue, and seem to have fixed it already, right before making an announcement - Hacker changes Phoenix Mars Lander Web site

A spokeswoman for the Phoenix Mars Lander mission says a hacker took over the mission’s public Web site during the night and changed its lead news story. Spokeswoman Sara Hammond says a mission update posted Friday was replaced with a hacker’s signature and a link redirecting visitors to an overseas Web site. Hammond says the site hosted by the University of Arizona has been taken off line while computer experts work to correct the problem.

Meet the latest group of script kiddies empowered by publicly obtainable remote SQL injection scanners, that each andPhoenix Mars Lander mission hacked every site that’s been affected in the past could have downloaded, and self-audited itself. The perspective that if you don’t take care of your site’s web application vulnerabilities, someone else would, fully applies here. No malware, or false information was distributed despite that the defacer linked to what looks like his homepage and therefore could have embedded malicious links or directly pointed the surfer to them.

And while this doesn’t seem to be what them wanted to achieve, in three of the most recent web site defacement incidents, we have defacers fully abusing the access they have. Last month for instance, Russian nuclear power websites were attacked and nuclear accident rumors spread using them, the Pro-Serbian hacktivists attacking Albanian web sites to spread propaganda messages, as well as a fake rumor for upcoming earthquake spread on the site of a Chinese seismological bureau.

Dancho DanchevDancho Danchev is an independent security consultant and cyber threats analyst, with extensive experience in open source intelligence gathering, malware and cybercrime incident response. He's been an active security blogger since 2007, and maintains a popular security blog. See his full profile and disclosure of his industry affiliations.

Email Dancho Danchev

Subscribe to Zero Day via Email alerts or RSS.

Related Discussions on TechRepublic

Did you know you can take part in these discussions with your ZDNet membership?

  • Talkback
  • Most Recent of 13 Talkback(s)
What's the point?
I don't get this kind of stuff. Surely there's something else these morons could direct their energies toward.... (Read the rest)
Posted by: djchandler Posted on: 06/04/08 You are currently: a Guest | | Terms of Use
RE: Phoenix Mars Lander's mission site hacked  VitaSigns_CSI@... | 06/02/08
RE: Phoenix Mars Lander's mission site hacked  VitaSigns_CSI@... | 06/02/08
thanks for the clarification  penno2 | 06/02/08
RE: Phoenix Mars Lander's mission site hacked  ParkerFairfield | 06/02/08
RE: Phoenix Mars Lander's mission site hacked  dlarmeir | 06/02/08
'Foreign governments use our systems to test penetration techniques.'  mhenriday | 06/03/08
Fiind them, Jail Them.  BitTwiddler | 06/03/08
RE: Phoenix Mars Lander's mission site hacked  bill_stanley@... | 06/03/08
RE: Phoenix Mars Lander's mission site hacked  bill_stanley@... | 06/03/08
RE: Phoenix Mars Lander's mission site hacked  phatkat | 06/03/08
RE: Phoenix Mars Lander's mission site hacked  twaynesdomain | 06/03/08
ask them  aravinthan | 06/04/08
What's the point?  djchandler | 06/04/08

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement
Click Here

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here