Apple’s Korean online store defaced

“Apple Computer’s Korean online store has been defaced by an intruder. The attack, apparently carried out by someone working under the name ‘Dinam,’ who claimed in his online posting to be Turkish, was brought to the attention of Silicon.com last Thursday,” Dan Ilett reports for CNET News. “The defacement was removed from Apple’s Web site shortly after Silicon.com alerted the company, which has subsequently declined to comment on the matter. Jason Hart, CEO of security company Whitehat UK, told Silicon.com: ‘The defacer has managed to get administrator access to the Web server.'”

“The defacement–which took the form of a dozen lines of code posted to the Apple.co.kr home page–was documented on Zone-h.org. The hacker forum said Dinam had attacked a Mac OS X server running Apache,” Ilett reports.

Full article here.

MacDailyNews Note: Today, another attacker documented by Zone-H, “D.O.M.,” put up the old 6-color Apple logo and the slogan “Think Different” at the domain http://mail.apple.co.kr. See the defacement here.

Advertisements:
Get the new iMac with Intel Core Duo for as low as $31 A MONTH with Free shipping!
Get the MacBook Pro with Intel Core Duo for as low as $47 A MONTH with Free Shipping!
Apple’s new Mac mini. Intel Core, up to 4 times faster. Starting at just $599. Free shipping.
Apple’s brand new iPod Hi-Fi speaker system. Home stereo. Reinvented. Available now for $349 with free shipping.
iPod. 15,000 songs. 25,000 photos. 150 hours of video. The new iPod. 30GB and 60GB models start at just $299. Free shipping.
Connect iPod to your television set with the iPod AV Cable. Just $19.
iPod Radio Remote. Listen to FM radio on your iPod and control everything with a convenient wired remote. Just $49.

63 Comments

  1. MUCH of ‘hacking’ is knowing some non-technical things about the system. The hacker could have slept with a sys-admin last night and poked around their home computer while they were in the shower.

    Apple isn’t doing anything new by using Apache as a web server. Would not Apache vulnerabilities exist cross platform (Linux adn Windws)?

  2. Bite me, Ron!

    My 17″ iMac has been running without fail for nearly 4 years straight. No virii, no malware, NO NOTHING JACKHOLE!

    I CAN’T TAKE IT ANYMORE!! I LIVE WITH DOZE DAILY!! I KNOW MORE ABOUT IT THAT I EVER WANTED TO!! TEN FREAKIN’ YEARS WITH THAT STEAMING PILE OF SHITE!!!

    RON, AND ALL THE OTHERS LIKE HIM, HAVE CLEARLY NEVER LIVED WITH OS X.

    SO STFU ALREADY AND GO SOMEWHERE ELSE!!!

    Or maybe I will. OS X on top of Vista?!?!

    @($*&^)($&^()#@&$^@&

  3. Apache is part of Mac OS X.

    It comes installed on every Mac, is updated via Software Update, is included in retail copies of both the Client & Server versions of the OS. No, Apple does not author it, but it is part of the OS.

    Get over it.

  4. How would using a microsoft server put you in line with 90% of the server market? If you are going to claim such things you really should do your research before you come across as a total fool. As of April 2006, Apache has around 63%of the server market while Microsoft has a tiny 25%. So, please enlighten us where this mystical 90% came from? Perhaps it’s one of those made up numbers that people like to use when they have no real facts to backup their claims. Try using this site, http://news.netcraft.com/archives/web_server_survey.html, as a reference before you walk around with egg all over your face next time. We have no problem entering into a debate with you but we are big fans of facts on the mac side of things. Just so you know, we aren’t the ones that look foolish here.

  5. I like the comments of “me” who stated hacking is often a less than technical proceedure.

    Probably a Koren temp. who looked on the web workers open KeyChain, or as most people often do (for shame) looked in the paper-clip drawer where web guys sticky notes of passwords was.

    With that “hacking ability” I could do this too, which isn’t saying much.

    I doubt this will happen again any time soon. If it does, it could imply someone is a great Apache hacker, but more than likely it will completely stop, as the passwords have all been changed, and thus this person’s access is no longer valid.

  6. war says:” We have no problem entering into a debate with you but we are big fans of facts on the mac side of things”.

    Fact: Apple Korea web site got defaced by hacker.
    Fact: Apple is running Apache software.
    Fact: Apple is only sitting at 2% market share.
    fact: MS is sitting at 90% market share.
    fact: Apple is only used in publishing and marketing, hence the pic of an iBook on MS web site.
    Fact: you are all a bunch of pansies to believe that Apple is the best product, while Vista has not even out yet.
    Fact: once Vista is out, Apple will be relegated to the brink of bankcruptcy again as noted by Michael Dell in 1996.

    advertisement:how to migrate from apache to Microsoft server.
    http://www.microsoft.com/technet/prodtechnol/windows2000serv/technologies/iis/deploy/rollout/lapa2iis.mspx

  7. Just because web site is compromized does not mean apache was at fault. OSX, ftp, php or administrator (as suggested by others) may be at fault. I hope we find out how the web site was compromised. One thing I like to know is, was the firewall on the web server setup to block all ports except http? If not, why not?

Reader Feedback

This site uses Akismet to reduce spam. Learn how your comment data is processed.