Follow Slashdot blog updates by subscribing to our blog RSS feed


Forgot your password?

Hack IIS6 Contest 545

ThePurpleBuffalo writes "This just came in across a BugTraq mailing list from Roger Grimes: 'Starting May 2nd and going until June 8th, the server located at will welcome hackers to attack it. If you can deface the web site or capture the "hidden" document, you win an X-box! Read contest rules for what does and doesn't constitute a successful hack. We've tried to be as realistic as possible in what constitutes a successful hack, and in mimicking a basic HTML and ASP.NET web site. ' "
This discussion has been archived. No new comments can be posted.

Hack IIS6 Contest

Comments Filter:
  • How long (Score:4, Insightful)

    by ceswiedler ( 165311 ) * <> on Thursday May 05, 2005 @03:11PM (#12444322)
    If they leave it up permanently, I'm sure it will be hacked once the next exploit is available. It's not impossible to secure a system like IIS, but it's much more difficult to make it secure permanently, as new exploits are found.

    If this is a test of IIS's security (for example as opposed to Apache) they should make it an ongoing test, and measure it not by whether it was hacked within a certain short time period, but how many times it is hacked over a long period of time.
  • by grazzy ( 56382 ) <> on Thursday May 05, 2005 @03:11PM (#12444326) Homepage Journal
    I sure as hell wouldn't give that knowledge away for a Xbox...
  • 18+ (Score:2, Insightful)

    by Anonymous Coward on Thursday May 05, 2005 @03:15PM (#12444379)
    Rules say you have to 18 or older. That pretty much garentees they won't be hacked. :)
  • by bigtallmofo ( 695287 ) on Thursday May 05, 2005 @03:15PM (#12444384)
    "Come to our site, give us free publicity, do something that likely you are the only one in the world that knows how to do and then teach us how to do it. If you do, there's a console game in it for you! Wouldn't you rather have a console game than the tens of thousands of dollars you could sell this information for?"

  • Lab rats (Score:3, Insightful)

    by clump ( 60191 ) on Thursday May 05, 2005 @03:17PM (#12444413)
    Let Microsoft do their own research. We don't need to spend our time testing for them. Focus instead on making Apache better.
  • by ozric99 ( 162412 ) on Thursday May 05, 2005 @03:18PM (#12444432) Journal
    I hear this all the time, mainly from high-school kids or the kind of immature person who thinks they're a computer guru because they use IRC or download "warez". So.. If this is so easy, go ahead. You said 15 minutes but to be fair I'll wait a couple of hours. If I don't see a message like "hacked by prof666" on the front page I'll assume you're a karma-whoring troll with about as much tech-savvy as my young, "guru" relatives.

    I may have migrated our web servers from IIS4 on NT4 to apache on debian as soon as I got the chance but that doesn't mean I'm not able to call bullshit on typical wannabe geeks slating MS software with no real knowledge of why they're slating it.
  • by drsmack1 ( 698392 ) * on Thursday May 05, 2005 @03:19PM (#12444443)
    If a zombied computer wins; who gets the xBox? The person that owns the computer? The zombie "author"?

    This needs to be resolved!
  • Re:How long (Score:5, Insightful)

    by PhoenixK7 ( 244984 ) on Thursday May 05, 2005 @03:20PM (#12444464)
    Yeah, frankly I don't really see the value in this. If someone doesn't hack it, it means nothing, this isn't a real-world test where the machine is only up for what, a week? This proves zero besides the machine was constantly being patched up and no new exploits were found that weren't patched during that time. What would be impressive would be if they left it up UNTIL someone cracked it. If that machine could stay up for a few months, say, maybe a year before being hacked, that would be much more useful as a statement about the security of the system.

    This is really just a publicity game. If makes MS look good if it makes it through the week, but it doesn't really prove that their software is secure.

    On the other hand, if they DO get hacked, that would look pretty bad. But.. who'se to say they haven't totally locked that thing down to the point where it's both not really representative of a "normal" server.

  • Re:How long (Score:2, Insightful)

    by weopenlatest ( 748393 ) on Thursday May 05, 2005 @03:22PM (#12444476)
    It's not impossible to secure a system like IIS, but it's much more difficult to make it secure permanently, as new exploits are found.
    Just because exploits aren't found, doesn't mean they're not there. You can't say a system is secure just because it's not vulnerable to known bugs. If a bug is posted tomorrow that makes all IIS servers vulnerable, it doesn't just mean that those servers are vulnerable tomorrow. They're also vulnerable today.
  • by CausticPuppy ( 82139 ) on Thursday May 05, 2005 @03:24PM (#12444500) Homepage
    duh hack IIS...well that challenge will take all of 15 mins then...

    Apparently not.
  • by Anonymous Coward on Thursday May 05, 2005 @03:30PM (#12444563)
    "that if someone did hack it, the admins will reset it quickly and block the particular method?"

    That's what MS would do if they were offering a $100,000 prize.

    That's not what an IT magazing would do for a $100 game console
  • Re:How long (Score:5, Insightful)

    by Momoru ( 837801 ) on Thursday May 05, 2005 @03:32PM (#12444599) Homepage Journal
    >>It's not impossible to secure a system like IIS, but it's much more difficult to make it secure permanently

    What makes IIS inherently more difficult to secure then Apache or any other web server? Besides the generic "ITS TEH MICRO$OFT!!!!"
  • Re:How long (Score:2, Insightful)

    by Anonymous Coward on Thursday May 05, 2005 @03:36PM (#12444638)
    The value is to prove to slashbot idiots that it can be secure and like they say, most hacks are a result of not following sound security procedures. This would obvously include applying patches. You need to patch linux and apache too right?

    A "normal" server on any semi high profile site will be locked down whether its apache or IIS. You think slashdot, redhat, or whoever else just forgets about any premise of security because they run the magical unix OS and/or apache?

  • by Saxerman ( 253676 ) * on Thursday May 05, 2005 @03:38PM (#12444661) Homepage
    If I could hack IIS6... I sure as hell wouldn't give that knowledge away for a Xbox...

    The point of these cute little contests with their cracker jack box prizes isn't to find out if there are exploits floating around in the wild. The point is to find out if any exploits have become so prevalent that someone would cash them in for a secret decoder ring. If not, they can hang their shingle saying, "Challenge still unhacked after foo months!" while those of us in the trenches scoff and continue our due diligence.

    Security is a state of mind, not a state of being.

  • "Watch for an upcoming issue of Windows IT Pro magazine to see Roger's recap of the contest, where he shares the secrets of creating an impenetrable IIS environment." Anyone else find it curious that they are "secrets" to securing IIS. One would think that it would be a little more available...
  • Re:Physical Access (Score:2, Insightful)

    by stedo ( 855834 ) on Thursday May 05, 2005 @03:43PM (#12444715) Homepage
    Fair point, but encrypting doesn't protect your data. It stops others from reading it, but not from randomly messing it up
  • by I_Love_Pocky! ( 751171 ) on Thursday May 05, 2005 @03:45PM (#12444737)

    this "informaiton" that would simply be used to deface websites?

    If you have the sort of access that would allow you to deface a website, you likely have access to do a whole lot more. We are talking about compromising a system. The same exploit could potentially be used for any number of other things.

  • Re:How long (Score:3, Insightful)

    by DarkOx ( 621550 ) on Thursday May 05, 2005 @03:48PM (#12444762) Journal
    That and the site is not exactly the most complex thing in the world. Sure there is some basic ASP and its far beyond some simple static html page but its exactly are large ECOM site or anything like that. I hope the admins and windowsITpro can configure an IIS box to be pretty solid doing somehting so basic. Doing something simple like this does not say much about the basic security characteristics of the platform. People do this with other platforms all the time too and then draw wild concludtions like see platform X is unhackable, well yes provided you run next no services. Trouble is to run a business you generally have to allow some traffic past your firewall, and often need to run mail servers, and gasp... cgi that takes input form users and acts on it.
  • by Safety Cap ( 253500 ) on Thursday May 05, 2005 @03:53PM (#12444813) Homepage Journal

    Someone should've hit the progenitors of this little "contest" upside the head with the Garfinkle book [] before they decided to go ahead with it.

    If said book had impacted the morans' cranium, they would've realized that such contests are useless for determining a system's hardness. Or they'd be dead. End results are about the same. So, let us review the possible results:

    1. The box is hacked. Oh man, it is pwned! Guess the system wasn't so strong after all.
    2. (more likely) The system isn't hacked.

    Does the latter scenario PROOF that the system is hacker-proof? Is it? Nope, sorry, it isn't.

    To prove that a system is unhackable, I have to demonstrate that in every case the security will not fail. If you have a random testing plan (i.e., a "contest"), then you'll never be sure you touched all the scenarios or even the most likely ones.

    To prove that a system is hackable, I just have to find one situation where it can be hacked. Finito; sayonara; have a nice day.

    The latter is relatively easy to do. The former is very hard (and sometimes impossible) to accomplish. It is much easier to hold a "contest," declare yourself the winner ("UNBREAKABLE, BABY! w00t!") and then go sell a bunch of units to the PHBs [].

  • Re:How long (Score:2, Insightful)

    by AndyCadley ( 865916 ) on Thursday May 05, 2005 @03:54PM (#12444816)
    IIS 6.0 would win by a country mile. There has only been one fix for it since its release and that was for WebDAV which isn't installed by default. Apache, by contrast, has had a a lot of patches in the last year.
  • by east coast ( 590680 ) on Thursday May 05, 2005 @03:54PM (#12444817)
    Why does someone who asks questions that are answered in the linked article get modded "Interesting" or "Insightful"?

    My guess is because most meta modderators are too afraid to hit the "unfair" option when these things come up.

    I think too many people think that meta modding is meant to weed out the trolls and they seem to take pity on the clueless.

    I'm not afraid of the unfair button. Only the meek fear the unfair button.
  • Re:How long (Score:5, Insightful)

    by captain_craptacular ( 580116 ) on Thursday May 05, 2005 @04:05PM (#12444959)
    I'm so tired of hearing crap like that.

    Real admins who work anywhere in the private sector do the best they can with the small amount of resources they have. They don't do anything like "verify the rest of the code" whatever the fuck that means. Real admins have 2 hours to get a new box up and running before they have to go put someone elses totally unrelated fire out. They install the OS image that they run on every other server which almost certainly has some things running that don't need to be because it's a general purpose image. Other than that they try their best to run a decent firewall in the 5 minutes a week that they have time to work on it, keep the patches as up to date as they can and hope the next time they get hit it's not too bad.

    Just because you have 40 hours of unemployment related free time a week to keep your killer 3 linux box home network/server farm uber secure and updated doesn't mean people in the real world do any such thing.

    You want a real test of who has the more secure product? Install IIS/ & Apache/php using as close to the default settings as possible and see which one gets hacked first. Because I guaruntee you that 80% of the time strapped overworked sysadmins out there are going to do exactly that, simply because they don't have time to do anything else. /end rant
  • Re:and done. (Score:2, Insightful)

    by X0563511 ( 793323 ) * on Thursday May 05, 2005 @04:06PM (#12444971) Homepage Journal
    Why does this sound like a trap?

    The prize for the first successful hack, if there is one, is a Microsoft Xbox console package. In order for prize to be awarded, the hacker must send an email with the details of the hack to and include the following:
    • Date and time of hack success
    • Legal name of hacker and/or team
    • Email address of contact person
    • Description of hack sufficient to verify that it took place
    • Description of how hack was accomplished

    Emphasis mine.
  • Re:and done. (Score:3, Insightful)

    by clem ( 5683 ) on Thursday May 05, 2005 @04:09PM (#12445012) Homepage
    Would you rather they leave the X-Box in the middle of the desert and stow the GPS coordinates in a protected directory on the web server?
  • by CustomDesigned ( 250089 ) <> on Thursday May 05, 2005 @04:14PM (#12445075) Homepage Journal
    If the bounty is an Xbox, that means that IIS6 security is robust enough to protect assets worth up to about $200.
  • Re:Lab rats (Score:2, Insightful)

    by Knightfall ( 558914 ) on Thursday May 05, 2005 @04:21PM (#12445172)
    Riiiiiiiiight .... let's not focus on making something that a significant portion of the web-world uses safer. GREAT plan. Yeah, maybe Apache still has a bigger market share, but IIS is not exactly a bit player either. Come on, safer sites, across the board, are a GOOD thing and deserve our attention.

    Slashdot groupthink may now mod me to oblivion.
  • Re:and done. (Score:3, Insightful)

    by MrAnnoyanceToYou ( 654053 ) <(dylan) (at) (> on Thursday May 05, 2005 @04:30PM (#12445264) Homepage Journal
    Go mess with a commerce site, screw the X-Box. Unless you're a saint, what you REALLY get out of this contest is a, "Give M$ one where the sun don't shine" card and not a free X-box. Anyone interested enough in computers to do this and capable of doing it is not going to enjoy the X-Box as much as the knowledge that they stabbed Microsoft in the toe.
  • by LibertineR ( 591918 ) on Thursday May 05, 2005 @04:39PM (#12445361)
    "Real admins have 2 hours to get a new box up and running before they have to go put someone elses totally unrelated fire out."

    Any admin that deserves to keep their job, keeps a pristine image of a locked down server, and can build a machine automatically with about 5 minutes of hands on labor. Put in the ghost boot, set it up, walk away. CIOs, if your folks dont do this, fire them. You should have a pristine image of every important server on your network. Taking the time to load an OS from scratch today is ridiculous.

  • by TheCabal ( 215908 ) on Thursday May 05, 2005 @05:02PM (#12445641) Journal
    You're assuming that 1) the admin in question has the time to build a "pristine, locked down image", and 2) has the time to constantly update said image and all the other hosts that have to be updated as well. If he had that kind of time, he wouldn't have to have a "pristine, locked down image" to begin with.
  • by Anonymous Coward on Thursday May 05, 2005 @05:05PM (#12445665)
    Its not that I want to support iis, but I hate the idea of the contest ending without a winner, and Roger Grimes getting to "share the secrets of how he created an impenetrable IIS environment."
  • Re:Several things (Score:4, Insightful)

    by Sylver Dragon ( 445237 ) on Thursday May 05, 2005 @05:22PM (#12445828) Journal
    Apache requires you to read the documentation and crack the httpd.conf with a text editor in order to change stuff. This ensures that you are at least one evolutionary level above blind, one-armed chimp, which is the only required level to use the mouse and click-click-click on the Internets MMC configurator for IIS. At a minimum, Apache web admins are *slightly* more talented than IIS admins

    Um, bullshit.
    I've been trying to teach myself more about Linux and Apache. And, honestly, I haven't a clue about half the stuff in the httpd.conf file. I'm getting there, but that still hasn't stopped me from getting a web server functioning, nor has it stopped me from getting apache-ssl up and running, with squirrel mail. Is my server anywhere near secure? I highly doubt it. Truth is, the Win2K server with IIS5 I had running beforehand was probably more secure, simply because I had a clue about what I was doing in those clicky "Internets MMC configurator for IIS".
    As the old axiom goes, "it's a poor carpenter who blames his tools". Yes, the Linux/Apache setup is more secure by default, but when it's setup by someone with little to no clue what they are doing, it's very likely to end up unsecure. Once I am a little more knowledgeable about running and securing Linux/Apache, I'll probably reformat the box, start over, and do a better job about it. Until then, I just assume the box is going to be hacked. And, no, I don't think I am above the evolutionary level of blind one-armed chimp when it comes to running Apache. Hoestly, comming in blind the online manuals sucked.

  • by typhoonius ( 611834 ) on Thursday May 05, 2005 @05:35PM (#12445965)

    RTFA []:

    Why a Hacking Contest?

    To have fun! We know there will be critics who say sponsoring a hacking contest proves nothing. If the IIS server remains unbroken, it still doesn't mean that IIS is really "secure." True, and if I weren't the contest's team leader, I'd probably be the first one to say so. Hacking contests rarely prove something is secure, although it only takes a single successful hack to prove something is not secure.

    So why do it? There are very few places on the Internet where hackers, good and bad, can hack legally. Windows IT Pro thought the contest would be a fun way to interact with the hacker community (they realize most hackers have good intentions) and provide a practical way for readers of Windows IT Pro to learn about security (of course, the magazine will disavow all responsibility and blame me solely if the server gets hacked) *grin*.

    So, welcome to the contest! Hack away. If the IIS server goes unhacked during the extended time period, it might not mean that IIS is "unhackable", but if the site does survive the contest it might convince a few people that that you can implement a relatively secure Web server platform with IIS if you follow best practices and take reasonable precautions. After all, over 20 percent of the Internet relies on IIS, including some of the largest Web sites in the world.

    I know IIS is an "M$" product so the moderators will eat up any and all defamation, but would it kill anyone to actually read the site before divining its intentions?

  • Re:How long (Score:3, Insightful)

    by Cromac ( 610264 ) on Thursday May 05, 2005 @08:14PM (#12447251)
    I disagree. The goal is to test if IIS is secure, not if the web application is secure. A large complex ecommerce site is more likely to have a bug in it's code that can be exploited than a simple basic site that does some minor database queries. The simple site would, in theory, leave fewer security holes to exploit leaving only IIS vulnerabilities.
  • Why not just have one semi-retired DHCP/TFTP/FTP server sitting in a corner with a CAT5 cable hanging out?

    Anything you plug into that and boot gets KickStarted through an install. Come back later to find it showing the new root password and a short list of questions about what it should be running. Answer questions, watch it shut down, drop it in its new home and fire it up.

    Use URPMI, apt or whatever to keep the packages up to date so your installs are automatically fresh/secure and you only need do anything drastic to your installer box about annually.

    Images, my ass. Too inflexible. We've got all of this fabulous technology for dynamically automating stuff, why not use it? Then you don't need every machine to be hardwarily identical, and you don't need to keep (a) separate clean machine(s) running to do the updates on.

    If you need to image several distinct types of machine and it's too hard to do with a short list of questions, add a network card and a different coloured cable for each. Red cable makes a server, orange cable makes a desktop, green cable makes a laptop and so on.
  • by Anonymous Coward on Friday May 06, 2005 @11:18AM (#12451265)
    As much as I hate IIS, Microsoft, etc, you have to admit to one thing:

    The guy said he put up an "environment" and not just a web server.

    Working in corporate America I realize the environment is more than just one machine. The enviroment is a collection of machines, gateways, routers, switches, software, library paths, libraries included, etc, that either make or break a particular piece of software (in this case, a web server). Having a firewall in front of it, regardless of its OS origins, is just common good practice for corporate security.

    Does this mean the contest is invalid? No, it makes it more difficult. As someone has mentioned in another post, IIS obviously isn't open source, so it will take some luck stumbling across a bug in IIS that will cause a buffer overflow and/or give user account information.

Outside of a dog, a book is man's best friend. Inside of a dog, it is too dark to read.