Hackers gained access to NASDAQ’s web-based Directors Desk tool. The tool is a custom solution for allowing the boards of businesses to communicate in a supposedly secure manner. If they managed to put files on a server HD, then that means they either had admin or ftp access to the box, or the site allows file uploads via the web interface. If that’s true, then they could have grabbed all sorts of data. Exploiting a bug on the IIS server, exploiting a bug (code injection) on a site hosted on IIS.”]
Source: https://gizmodo.com/nasdaq-confirms-hack-company-director-chat-service-comp-5753696

