Microsoft's India store hacked, usernames & passwords stolen

February 13, 2012
Hacj

New Delhi, February 13: Hackers, allegedly belonging to a Chinese group called Evil Shadow Team, struck at www.microsoftstore.co.in on Sunday night, stealing login ids and passwords of people who had used the website for shopping Microsoftproducts.

While it is troublesome that hackers were able to breach security at a website owned by one of the biggest IT companies in the world, it is more alarming that user details - login ids and passwords - were reportedly stored in plain text file, without any encryption.

Following the hack, the members of Evil Shadow Team, posted a message on the Microsoft website saying "unsafe system will be baptized". The story was first reported by www.wpsauce.com.

Later, the website seemed to have been taken offline by Microsoft. We advise the users at Microsoft India Store to change the password as soon the website comes online. Also, if they have used the same password or login id on any other web service, they should change it immediately.

Last year, hacker groups like Lulzsec had carried out several-profile high profile break-ins, putting focus on the security measures companies put in place. Sony allegedly suffered several security breaches and hackers stole user ids and passwords of customers from its network.

In a message posted on a website called Pastebin, Lulzsec claimed the group was bringing attention to the web security. "Do you think every hacker announces everything they've hacked? We certainly haven't, and we're damn sure others are playing the silent game. Do you feel safe with your Facebook accounts, your Google Mail accounts, your Skype accounts? What makes you think a hacker isn't silently sitting inside all of these right now," the group wrote.

But the incident at Microsoft Store on Sunday hints that lessons have not been learnt. Just like Sony, which later revealed that user ids and passwords were not encrypted at the time of security breach, Microsoft too seemed to have been casual about handling the user details by storing them in a plain text file. We have contacted Microsoft but company has so far not acknowledged or commented on the security breach.


Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
January 20,2020

Ahmedabad, Jan 20: Cops in Gandhinagar fell in a catch-22 situation when a state government employee approached them with a complaint that the 26-year-old woman class teacher of his 14-year-old son had gone missing taking his son in tow. The man, who works at Udyog Bhavan in Gandhinagar said the woman had seduced his teenage son, who studies in class VIII and taken him away with her. The boy had gone missing from 4pm on Friday, and the classteacher was also missing.

A police official said the woman teacher had been too intimate with the allegedly missing boy for around a year, and the school authorities had recently rebuked them. “As their relationship was unaccepted, they left their homes on Friday,” he said. It was rare to find a case of a woman teacher eloping with her teenage student, the official added.

An FIR for elopement under Section 363 IPC has been registered with Kalol city police in Gandhinagar district. The complaint stated the teacher is a resident of Darbari chawl in Kalol town.

“When I reached home at around 7pm, I found my son missing. My wife told me he had left home at around 4pm. We searched for him in the neighbourhood and among relatives, but couldn’t trace him,” claims the teenage boy’s father in the FIR. “I went to the teacher’s house but they were not there,” the man stated.

Inspector K K Desai of Kalol city police said the missing duo could not be traced as they were not carrying cellphones.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
Agencies
January 12,2020

Mumbai, Jan 12: At least eight persons were killed and several others injured when a massive blast followed by a fire ripped a chemical factory at Boisar in Palghar district, nearly 100 km north of Mumbai, on Saturday, officials said.

Top Palghar district administration, police and fire brigade officials have rushed to the spot for the rescue operation, while Fire Brigade teams from Boisar MIDC industrial area and Tarapur Atomic Power Station are engaged in dousing the flames.

As per local witnesses, the intensity of the explosion was so severe that it was audible in a 35-km range and one building in the factory collapsed.

Besides, many homes in the immediate vicinity were shaken and people ran outside thinking it was an earthquake, as power lines also failed.

The exact cause of the explosion-cum-blaze which occurred around 7 p.m. is not immediately available.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
June 7,2020

Bengaluru, Jun 7: A 27-year-old man was allegedly killed using deadly weapons by unidentified people here, police said.

The incident took place at deceased, Arvind's rented house in LBS Nagar inside HAL police station limits.

According to police, Arvind is an accused in a criminal case and recently walked out of jail on bail. 

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.