Microsoft Says Hackers Broke Into Its Network
October 28, 2000 - 0:0
LONDON Software giant Microsoft Corp. said on Thursday that hackers had broken into the company's computer system, in what a spokesman called a "deplorable act of industrial espionage".
Microsoft spokesman Rick Miller declined to comment on what specific areas of the computer network were breached, what the specific goals of the hackers were, or the possible motives.
The company had reported the break-in to the U.S. Federal Bureau of Investigation and was working with authorities to protect its intellectual property, Miller told Reuters.
Citing sources close to the situation, the Wall Street Journal reported that the hackers were believed to have stolen the blueprints to the latest versions of its flagship operating system Windows and its office software package.
Computer security experts told Reuters that hackers appeared to have used a "well-known worm" virus called Qaz, which first surfaced in China several months ago, to break into Microsoft's systems.
"This is very worrying (that Microsoft has been hit), because we have had detection for it for three months and we regard it only a medium threat" rather than a new, high risk virus, said Raimond Genes, European marketing vice president for Japan-based computer security company Trend Micro.
Miller declined to comment on what, if anything, had been stolen.
The FBI was not immediately available for comment.
"We recently became aware of attacks to our corporate network," Miller said.
"Microsoft is moving aggressively to isolate the problem and to secure our corporate network. We are confident that the integrity of our source code remains secure," he added.
Source code is the basic building block of all software programs.
The company became aware of the attacks "in the last couple of days". Asked if the attacks had stopped, Miller said: "We believe so." Source Code Transferred Microsoft's security employees discovered the break-in after they detected passwords being remotely sent to an E-mail account in St. Petersburg, Russia, the Wall Street Journal reported.
The company interpreted electronic logs as showing that those internal passwords were used to transfer source code outside the Microsoft campus, it said.
Mikko Hypponen, a security expert at Finnish-based data protection specialists F-Secure, said this was typical of the way a worm virus would operate.
A worm is a distinct type of computer virus that makes copies of itself across multiple systems. This particular virus is believed to have entered Microsoft's headquarters on the back of an inconspicuous looking document, which would also make it a so-called Trojan virus.
Named after the Greek myth of the Trojan Horse, the insidious worm hides inside a file and once opened, a damaging program is installed on the computer that starts sending copies of itself to other computers. Once the software is installed, hackers can gain easy access to the information on that computer.
"It's very effective. A hacker doesn't need to hack into a computer himself. The worm does it for him and then reports back," Hypponen said.
The fact that the worm had infected programers' computers was not unusual because programers usually disable virus protection software which slows down computers, Hypponen said.
(Reuter)
Microsoft spokesman Rick Miller declined to comment on what specific areas of the computer network were breached, what the specific goals of the hackers were, or the possible motives.
The company had reported the break-in to the U.S. Federal Bureau of Investigation and was working with authorities to protect its intellectual property, Miller told Reuters.
Citing sources close to the situation, the Wall Street Journal reported that the hackers were believed to have stolen the blueprints to the latest versions of its flagship operating system Windows and its office software package.
Computer security experts told Reuters that hackers appeared to have used a "well-known worm" virus called Qaz, which first surfaced in China several months ago, to break into Microsoft's systems.
"This is very worrying (that Microsoft has been hit), because we have had detection for it for three months and we regard it only a medium threat" rather than a new, high risk virus, said Raimond Genes, European marketing vice president for Japan-based computer security company Trend Micro.
Miller declined to comment on what, if anything, had been stolen.
The FBI was not immediately available for comment.
"We recently became aware of attacks to our corporate network," Miller said.
"Microsoft is moving aggressively to isolate the problem and to secure our corporate network. We are confident that the integrity of our source code remains secure," he added.
Source code is the basic building block of all software programs.
The company became aware of the attacks "in the last couple of days". Asked if the attacks had stopped, Miller said: "We believe so." Source Code Transferred Microsoft's security employees discovered the break-in after they detected passwords being remotely sent to an E-mail account in St. Petersburg, Russia, the Wall Street Journal reported.
The company interpreted electronic logs as showing that those internal passwords were used to transfer source code outside the Microsoft campus, it said.
Mikko Hypponen, a security expert at Finnish-based data protection specialists F-Secure, said this was typical of the way a worm virus would operate.
A worm is a distinct type of computer virus that makes copies of itself across multiple systems. This particular virus is believed to have entered Microsoft's headquarters on the back of an inconspicuous looking document, which would also make it a so-called Trojan virus.
Named after the Greek myth of the Trojan Horse, the insidious worm hides inside a file and once opened, a damaging program is installed on the computer that starts sending copies of itself to other computers. Once the software is installed, hackers can gain easy access to the information on that computer.
"It's very effective. A hacker doesn't need to hack into a computer himself. The worm does it for him and then reports back," Hypponen said.
The fact that the worm had infected programers' computers was not unusual because programers usually disable virus protection software which slows down computers, Hypponen said.
(Reuter)