“Apple Computer’s Korean online store has been defaced by an intruder. The attack, apparently carried out by someone working under the name ‘Dinam,’ who claimed in his online posting to be Turkish, was brought to the attention of Silicon.com last Thursday,” Dan Ilett reports for CNET News. “The defacement was removed from Apple’s Web site shortly after Silicon.com alerted the company, which has subsequently declined to comment on the matter. Jason Hart, CEO of security company Whitehat UK, told Silicon.com: ‘The defacer has managed to get administrator access to the Web server.'”
“The defacement–which took the form of a dozen lines of code posted to the Apple.co.kr home page–was documented on Zone-h.org. The hacker forum said Dinam had attacked a Mac OS X server running Apache,” Ilett reports.
Full article here.
MacDailyNews Note: Today, another attacker documented by Zone-H, “D.O.M.,” put up the old 6-color Apple logo and the slogan “Think Different” at the domain http://mail.apple.co.kr. See the defacement here.
Advertisements:
• Get the new iMac with Intel Core Duo for as low as $31 A MONTH with Free shipping!
• Get the MacBook Pro with Intel Core Duo for as low as $47 A MONTH with Free Shipping!
• Apple’s new Mac mini. Intel Core, up to 4 times faster. Starting at just $599. Free shipping.
• Apple’s brand new iPod Hi-Fi speaker system. Home stereo. Reinvented. Available now for $349 with free shipping.
• iPod. 15,000 songs. 25,000 photos. 150 hours of video. The new iPod. 30GB and 60GB models start at just $299. Free shipping.
• Connect iPod to your television set with the iPod AV Cable. Just $19.
• iPod Radio Remote. Listen to FM radio on your iPod and control everything with a convenient wired remote. Just $49.
beuller?
HA HA HA HA HA HA. ROTFLMAO
“OSX has better security” my ass.
HA HA HA HA HA HA. ROTFLMAO
Things are heating up. I like it!
MUCH of ‘hacking’ is knowing some non-technical things about the system. The hacker could have slept with a sys-admin last night and poked around their home computer while they were in the shower.
Apple isn’t doing anything new by using Apache as a web server. Would not Apache vulnerabilities exist cross platform (Linux adn Windws)?
for any OS.
And even IF it’s not that–if it’s an actual flaw in Apache–that won’t help your Mac get compromised: Apache isn’t even turned on by default.
[Chanting]
Aaayayayayayayaya Aaayayayayayaayaayaay Aayaayaayaayayayaayaya …
[/Chanting]
Apache.
Ron’s intellect is dizzying, He seems to forget those 117,000 Windows viruses and 0 for Mac OS X.
I
Moron Ron, the security fault lies in Apache, not OS X. Now go get your f*cking shinebox…
Hi kids! I’m a douchebag.
Can you say ‘douchebag’?
Yaah, I knew you could.
Bite me, Ron!
My 17″ iMac has been running without fail for nearly 4 years straight. No virii, no malware, NO NOTHING JACKHOLE!
I CAN’T TAKE IT ANYMORE!! I LIVE WITH DOZE DAILY!! I KNOW MORE ABOUT IT THAT I EVER WANTED TO!! TEN FREAKIN’ YEARS WITH THAT STEAMING PILE OF SHITE!!!
RON, AND ALL THE OTHERS LIKE HIM, HAVE CLEARLY NEVER LIVED WITH OS X.
SO STFU ALREADY AND GO SOMEWHERE ELSE!!!
Or maybe I will. OS X on top of Vista?!?!
@($*&^)($&^()#@&$^@&
Apache is part of Mac OS X.
It comes installed on every Mac, is updated via Software Update, is included in retail copies of both the Client & Server versions of the OS. No, Apple does not author it, but it is part of the OS.
Get over it.
Serious now. Can’t you guys just follow suite to 90% of the market and dump your open source linux or Apple OSX server?
Advertisement:
for a complete, safe and secure solution go to: http://www.microsoft.com/windowsserversystem/default.mspx
It’s Part of OS X
Click on the link and get yourself educated. From Apple’s own website.
http://www.apple.com/macosx/features/websharing/
Ron,
Uh, nope. Guess not. Why do you need us too so badly?
If we ALL jump off the cliff and end up dead at the bottom, will you be somehow LESS DEAD with our fresh bodies on top?
Seek professional help. Please.
Apache is open source, it isn’t Apple software moron.
As for this hack, let’s see them hack Apple.com itself, then I’ll be impressed…
This is funny… There is a image of an Apple iBook corner in the previous microsoft link
” width=”19″ height=”19″ alt=”wink” style=”border:0;” />
For those of you that mistakenly think Apache is Apple software, here you go…
http://en.wikipedia.org/wiki/Apache_Software_Foundation
How would using a microsoft server put you in line with 90% of the server market? If you are going to claim such things you really should do your research before you come across as a total fool. As of April 2006, Apache has around 63%of the server market while Microsoft has a tiny 25%. So, please enlighten us where this mystical 90% came from? Perhaps it’s one of those made up numbers that people like to use when they have no real facts to backup their claims. Try using this site, http://news.netcraft.com/archives/web_server_survey.html, as a reference before you walk around with egg all over your face next time. We have no problem entering into a debate with you but we are big fans of facts on the mac side of things. Just so you know, we aren’t the ones that look foolish here.
Jaakko’s right. That’s awesome!
Most Microsoft Certifiable Techs know nothing but Windoze and think that because everybody like them use it, everybody does. The world runs on UNIX & LINUX, especially mission critical systems.
If you go to:
http://news.netcraft.com/
and do a webserver search on microsoft.com
look at what these guys trust for their server needs.
I like the comments of “me” who stated hacking is often a less than technical proceedure.
Probably a Koren temp. who looked on the web workers open KeyChain, or as most people often do (for shame) looked in the paper-clip drawer where web guys sticky notes of passwords was.
With that “hacking ability” I could do this too, which isn’t saying much.
I doubt this will happen again any time soon. If it does, it could imply someone is a great Apache hacker, but more than likely it will completely stop, as the passwords have all been changed, and thus this person’s access is no longer valid.
war says:” We have no problem entering into a debate with you but we are big fans of facts on the mac side of things”.
Fact: Apple Korea web site got defaced by hacker.
Fact: Apple is running Apache software.
Fact: Apple is only sitting at 2% market share.
fact: MS is sitting at 90% market share.
fact: Apple is only used in publishing and marketing, hence the pic of an iBook on MS web site.
Fact: you are all a bunch of pansies to believe that Apple is the best product, while Vista has not even out yet.
Fact: once Vista is out, Apple will be relegated to the brink of bankcruptcy again as noted by Michael Dell in 1996.
advertisement:how to migrate from apache to Microsoft server.
http://www.microsoft.com/technet/prodtechnol/windows2000serv/technologies/iis/deploy/rollout/lapa2iis.mspx
Just because web site is compromized does not mean apache was at fault. OSX, ftp, php or administrator (as suggested by others) may be at fault. I hope we find out how the web site was compromised. One thing I like to know is, was the firewall on the web server setup to block all ports except http? If not, why not?
“Serious now. Can’t you guys just follow suite to 90% of the market and dump your open source linux or Apple OSX server?
Advertisement:
for a complete, safe and secure solution go to: http://www.microsoft.com/windowsserversystem/default.mspx“
Yeah, that’s a good idea Ron. ‘Cause Microsoft products NEVER get hacked, right?
I believe their web site is defaced again… The apple logo for their education individual store link will probably get the Apple Record extreamly upset again (5/3/06 4:43PM CST).
Dear Ron,
Your facts are quite interesting. What is more interesting is that they are so vague that can interpreted any number of ways. For example, MS is sitting at 90% market share. Could you be a bit more specific? They have far from 90% market share in the server market. So, you are trying fudge your numbers a bit to try and have a relevant point. Again I will reiterate my statement that we don’t mind having a debate but we prefer to use facts. Furthermore, you seem to be rehashing old myths about Apple that haven’t been true in years. Also, Vista isn’t a “real” product until it hits the market. So, I could say that a 2020 BMW is better than your 2007 Mercedes using that logic. Sure, the year 2020 cars aren’t out yet but they will be eventually. Since you are on here trolling I am going to cast doubt on your claims as to the financial viability of Apple. No offense but you don’t come across as an expert in the way of economics.
I will concede that their Korean web site did get defaced and that Apple was using Apache server. However, Apple doesn’t make Apache server as it is an open source software package that MOST of the web servers out there use.
My last item I would like to address is, what thrill do you get from coming on here trying to start an argument? Seriously, if you are so sure of the windows platform wouldn’t you rather spend your time on sites that cater to fans of windows? What deep rooted psychological need are you trying to fulfill by coming on here in the first place? I am certain that there are many qualified therapists in your local area that can help you sort through these problems.
Best of luck to you. I hope the therapy helps.
Ron,
Fact: NSA won’t run anything other than OS X.
Fact: Some of the fastest supercompters runs OS X (and not for publishing or marketing)
Fact: Apple is sitting on 90% marketshare (sorry, you didn’t say for what, so I’ll be as ambiguous as you).
Fact: Vista isn’t out yet. So how much revenue/marketshare/etc. does it have?
Fact: Vista is a shadow of its intended self, so just must be better, right?
Fact: You’re a douchebag – you said so above.
OS X Hacked…Looks like OS X is not bullet proof
NSA would never reveal what os they run
Fact: once Vista is out, Apple will be relegated to the brink of bankcruptcy again as noted by Michael Dell in 1996.
You keep using that word, “fact.” I don’t think it means what you think it means.
Wow guys, i was just kidding
mac nerds take themselves way to seriously
everyone reading this needs to get a life
It’s Ron with the big “R”– for Rse, not me with the little “r’– for rn’t you wuvewy
The trolls are losing their minds, whatever’s left.
Hey, Ron:
It was a Windows Server that was hacked. HA HA right back at ya, bitch.
“As Michael Dell noted in 1996”??? Has Vista’s introduction been delayed since 1996?? Will Vista even be introduced in 2007?? We used to say Windows 95 is Mac 85. But was the first beta of OSX in about 2000 as immature as Vista will be? If we give Microsoft the benefit of the doubt, and say Vista will be as good as Jaguar, then we can say that Vista 2007 is Mac 2002. Hey, they have closed the gap! They’re only five years behind! Oh, but as for Michael Dell, Apple is now worth more than his company. I wonder if he predicted that in 1996??
rasterbator:
the article said “…Dinam had attacked a Mac OS X server running Apache”. if you click on http://mail.apple.co.kr you now get a “Forbidden” page, that clearly states that it’s running Apache.
even if it was running Windows server, don’t you think that’s kinda funny, an Apple site running on Windows?
big “huh?” from me…
i heart macdude: There it is again. There is no such word as “virii” (ferchrissake)
Second: ron is a troll. don’t you ultra-superior mac-heads know not to feed trolls by now? Sounds like we have some new converts…a disgusting sense of snobbery oozes from this site….it wasn’t alwasy this bad, when were the noble….now we are the crucifier, and it stinks.
I love seeing everyone here scrambling around making up ridiculous excuses for this. For example:
“The hacker could have slept with a sys-admin last night and poked around their home computer while they were in the shower.”
I think you have seen one to many movies.
Here is THE REAL reason this happened:
http://blog.washingtonpost.com/securityfix/2006/03/when_macs_attack.html
If that link breaks just C&P the link into your browser.
Here is an exerpt: “A large number of Web sites running vulnerable PHP applications on OS X systems are regularly defaced by hacker groups who replace the sites’ home pages with hacker screeds or even some political statements.”
This is a problem with PHP applications. Click this to see more defacements of OS X servers using PHP.
http://www.zone-h.org/en/defacements/filter/filter_system=MacOSX/
99% of Mac users have NOTHING to worry about here. You can sleep soundly. Your Mac is safe and secure.
Forgot to add this – PHP: http://en.wikipedia.org/wiki/PHP
Funny, no MDN take?
Apache is as part of OS X as it is ssh, postfix, webdav, ldap, tcsh, ksh bash, etc
IF next week someone finds an exploit on postfix, or ssh, then OS X is at fault? Get real.
Apache developers (and the entire open source community) will fix the flaw, release a patch and Apple will distribute it through Software Update. As often it happens, security patches from Apple do involve opens source Unix tools common to all *nix platforms.
So be it.
Guys – the whole frickin OS is open source, apart from the eye candy on top. Does that mean Apple is blameless for any security attack, other than something that stops the friggin’ widgets working? Get a life. Please.
RC, nope, Apple will be blamed for any security attack for code its developers are directly responsible for.
A security attack on, say, ssh, is not direct responsibility of Apple developers. A security attack on Darwin would be direct responsibility of Apple developers.
Not so difficult to understand. And the point is not to have Apple blameless but saying “Apache has a security flaw: AHAHAHAH Apple Mac OS X is a security joke” is blatantly moronic.
Same would go if the next security problem should arise from postfix, one of the shells, ssh, etc. What Apple has to do with those, vis-a-vis development. Apple could and would contribute, and sometimes their contributions make into the main repository, as for the changes to gcc.
Open source programs and sw does not mean that no-one is responsible or in charge of it. It simply means people could d/l and contribute if they feel so. Their contribution does not automatically become part of the code: the people in charge decide.
Same goes for Apache open source project: there are people in charge.
Open source is not software development anarchy. Or do you sincerely believe that open source means everyone can change the code and commit into the repository?
BTW, Apache is as well on Linux platform, BeOS, FreeBSD, and many others *nix OSes.
Why not then “Apache has a security problem: HAHAHAHAHA Mac OS X, Linux, FreeBSD, BeOS, this, that, whatever, younameit are security jokes”
Would be totally stupid. As is totally stupid to single out any one OS that uses Apache and blame the OS for being unsecure.
It is not taking the side of Apple, is simply saying that it is technically ignorant to pointing out a problem in a common component of many software distributions and say that the OS that uses it is to be blamed for it.
Whatever.
Is this Ron character SERIOUSLY suggesting that one use Windows…IIS…as a professional web server? Get real man – IIS is absolutely horrible (or you could add .NET or Java and be really slooooowwww…..).
What a tool…….
Nothing to see here people. Web-site hacks are common and frequently are simply the result of poorly configured web scripts, rather than a deeper security issue.
@Reality Check “Guys – the whole frickin OS is open source, apart from the eye candy on top. Does that mean Apple is blameless for any security attack, other than something that stops the friggin’ widgets working? Get a life. Please.”
No, Apple is NOT blameless for any security attack and should be held accountable – if it is indeed an underlying OS security faluire. In my post above, I just wanted to point out that OS X SERVERS and anyone running their machine as a “server” of some kind utilizing PHP are definitely vulnerable. As you can see by the second link I posted, MANY OS X servers/sites have and are being defaced/hacked using exploits in PHP. The vulnerabilities in PHP are MUCH worse than a simple defacing though (read the first link). You can actually be compromised and code can be loaded and run on your server. THIS is serious.
My other point still remains – 99% of all Mac users have NOTHING to worry about in THIS particullar case. They are not running as servers with PHP enabled.
To the people that are – you have a SERIOUS PROBLEM.
to iPlodder
>RC, nope, Apple will be blamed for any security attack for code its developers are directly responsible for.
Kidding right? do you think most people running OSX give a flying f**k who wrote the code.
If Apple chooses to distribute something bundled with the machine, in the selection process they should be taking on responsibility for it being secure whether they wrote it or not. After all, it is open source code. They could find and fix any security vunerabilities if they chose to.
>A security attack on, say, ssh, is not direct responsibility of Apple developers.
Again disagree, because they chose to incorporate an insecure component. That’s like saying 99% of Windows security issues are not a problem with the OS as such, but with the bundled apps running on top of it. That argument wouldn’t fly if made in the PC world. Shouldn’t fly in the Mac World either.
So Macs have the same types of security vunerabilities as other systems. Shouldn’t be news to anyone who didn’t come down in the last shower.
hepinize sıra gelecek
HERŞEY VATAN İÇİN http://www.starhack.org
This is cool that we can receive the loans and it opens up completely new possibilities.
No one who accomplish result does so without notice the assist of others. The wise and reliant recognize this assist with thanks. Our target is to facilitate peoples with their research paper writing.
When some students buy essays or buy custom writing about this good topic, that would be possible to receive really the best quality.
Thanks a lot that you finished the good enough theme connected with this post. But, to determine the really good writing service, all people should know just about custom written essay.
Do you know what college guys are focused on? They people are focused on high academic grades! But, to get high quality papers you must have somebody like custom essay writing services to assist you.
People require to write a lot to get the key issue of the write my paper issues. But if people can not write, it will be the best to buy research papers online. In such way it would be available to save time.
It’s well known that the law essays accomplishing process can be hard. Therefore, bright persons do not consume their chill out time and buy essays . Moreover, it is not a kind of cheating, I guess!
This demands very long period of time to add your top stuff like this topic by your own. So, article submit service and science article submission created for you and people can utilize it.
College students have to guess twice before they begin their good term paper writing, just because this will be more simple to buy custom essays from buy papers service. Furthermore, that would save time and money!
Specialists say that loan help a lot of people to live their own way, because they are able to feel free to buy necessary goods. Moreover, different banks present short term loan for young and old people.
No one in the world will assist you with academic assignments completing as effective, as professional custom writing firm will do. Therefore, it is normal if you buy college papers from the trustworthy company.
There are many several path ways to get know referring to this good topic . But I propose to buy essay and custom writing or buy a term paper choosing the perfect essay writing services.
I consider that it’s important to get know about this topic. Buy custom essay papers at the writing services just about this good post, because that’s important topic.
Our life is really difficult thing and sometime people must opt for one only stuff at one time, then you don’t have enough time to work on some else action. For example, some students have to select ‘tween job and humanities essays paper making. In that case, I recommend to notice the great custom essay writing service to purchase the research paper from.