PC Week heeft een verslag gepost van het hack-m'n-Linux-of-NT-doos contest dat zij enkele weken geleden uitschreven. Uiteindelijk werd de Linux bak als eerste plat gelegd, maar dat lag niet zozeer aan gebrekkige beveiliging in Linux als wel aan een exploit in een commercieel CGI script:
The hack that felled www.hackpcweek.com teaches a very important lesson: Security doesn't stop at the operating system. (See related story.)
PC Week Labs went to great lengths to take the same security measures on the Linux and Windows NT servers running the site that any IT manager worth his or her salt would implement. The successful hacker, known as Jfs, bypassed the firewall, the intrusion detection system and a locked-down server to exploit a hole in a CGI script on the Linux server, which was running Red Hat Linux 6.0.
The successful attack against our Linux server was a methodical assailment by a hacker with intimate knowledge of C, PERL and The Home Office-Online's PhotoAds classified-ad engine application. PhotoAds is publicly available (at www.hoffice.com), as is information on its known security holes and fixes. Companies that don't keep on top of application fixes will be at the mercy of hackers who do.