Microsoft Hack: Uncovering the Details of a Critical Security Incident
A hacker used the QAZ Trojan program to infiltrate Microsoft's corporate network by exploiting an employee's home computer connected to the company's internal network. This incident raised concerns about the security of Microsoft's systems and the potential risk of source code exposure. The intruder created new accounts, gained access to parts of the network, and may have seen the source code for a non-core software project, but it is unlikely that they downloaded or copied it.
Key Takeaways:
- The hacker gained access to Microsoft's network through an employee's home computer connected to the company's internal network.
- The QAZ Trojan program was used to create a back door on the infected computer, allowing the intruder easy access to the machine.
- The intruder created new accounts with varying permissions and accessed parts of the network, but it is unlikely that they downloaded or copied source code.
- Microsoft's internal security procedures were followed, and the company blocked access to the accounts and notified law enforcement authorities.
- The intruder may have had access to the victim's computer before October 17, but the security offices would not have raised alarms until the new accounts were created.
- Microsoft's corporate security officer, Howard A. Schmidt, said that the company had dealt with routine computer virus incidents in September and could not be certain if these incidents were related to the break-in.
- The company shut down all the intruder's accounts and alerted law enforcement officials, and federal law enforcement officials are continuing to investigate the break-in.
Statistics:
- The incident occurred over a period of approximately one week, from October 17 to October 24.
- The intruder created new accounts and accessed parts of the network multiple times, but the exact number of attempts is not specified.
- Microsoft's internal network is protected by a firewall, but a firewall alone cannot prevent a connection from an authorized user's machine that has been taken over by an unauthorized third party.
- The source code for a non-core software project was accessed by the intruder, but it is unlikely that they downloaded or copied it.
Sources:
- Microsoft Corp. (Oct. 25)
- The New York Times (Oct. 25)