Welcome,
Guest
.
Please
login
or
register
.
Did you miss your
activation email
?
News:
Bug reports and fixes
.
Home
Help
Login
Register
Elxis CMS Forum
»
Support
»
Security
»
Hackers Jack Thousands of Sites, Including UN Domains
« previous
next »
Print
Pages: [
1
]
Author
Topic: Hackers Jack Thousands of Sites, Including UN Domains (Read 8213 times)
CREATIVE Options
Authorized Elxis Professional
Elxis Community
Hero Member
Posts: 2334
Professional services for Elxis CMS
Hackers Jack Thousands of Sites, Including UN Domains
«
on:
April 24, 2008, 20:00:01 »
April 24, 2008
Hackers Jack Thousands of Sites, Including UN Domains
Large numbers of legitimate websites, including government sites in the UK and some operated by the United Nations, have been hacked and are serving up malware, says a security researcher, as massive JavaScript attacks last detected in March resume.
"They're using the same techniques as last month, of an SQL injection of some sort," said Dan Hubbard, vice president of security research at Websense, referring to large-scale attacks that have plagued the internet since January.
Among the sites hacked, said Websense, were several affiliated with either the UN or UK government agencies.
The exact number of sites that have been compromised is unknown, said Hubbard. He estimated that it's similar to the March attacks, which at their height infected more than 100,000 URLs, including prominent domains such as MSNBC.com.
"The attackers have now switched over to a new domain as their hub for hosting the malicious payload in this attack,"
Websense said in an alert
posted yesterday to its website. "We have no doubt that the two attacks are related."
Although the malware-hosting domain has changed, it's located at a Chinese IP (Internet Protocol) address, just like the one used in March, Hubbard said. "It also looks like they're using just the one [hosting] site, but changing the link within the JavaScript," he added, talking about an obfuscation tactic that the attackers have used before.
When a visitor reaches one of the hacked sites, the malicious JavaScript loads a file from the malware-hosting server, then redirects the browser to a different page, also hosted on the Chinese server.
"Once loaded, the file attempts eight different exploits," noted the Websense warning, including one that hits a vulnerability in
Internet Explorer's handling of Vector Markup Language (VML)
that was patched in January 2007.
Another security researcher, Giorgio Maone, who also develops the Firefox add-on "
NoScript
", said late on Wednesday that although the UK-based sites appeared to have been cleansed of the malicious JavaScript, the UN sites had not.
Maone also said "
I told you so
" in his blog post yesterday. In an August 2007 entry, he had said that rather than fixing the underlying security problems on the UN site, the agency had simply deployed a "pretty useless" firewall that masked the most obvious attack surface.
Even the disinfected sites, however, could fall victim again, Maone maintained. "The sad truth, though, is that even those 'clean' sites are still vulnerable, hence they could be reinfected at any time," he said.
"Website owners have to start securing their code," Hubbard agreed.
Source:
www.computerworld.co.nz
Notice
, you don't have to be unsure if your Elxis CMS system are secure if you follow all the instructions of the Elxis Team, Elxis Installer, Elxis Defender & of course the tips that you can find inside our forum.
Logged
datahell
Elxis Team
Hero Member
Posts: 10353
Re: Hackers Jack Thousands of Sites, Including UN Domains
«
Reply #1 on:
April 24, 2008, 23:13:57 »
Thousands of web sites get hacked every day, just enter in any hacker portal and see their the daily scores... I think that there is no need to frighten users with such posts. Of course we must always have in mind that security is a very important aspect of our web site. Better post how to strengthen security...
Logged
Elxis Team
|
Is Open Source
|
IOS Rentals | IOS AERO
CREATIVE Options
Authorized Elxis Professional
Elxis Community
Hero Member
Posts: 2334
Professional services for Elxis CMS
Re: Hackers Jack Thousands of Sites, Including UN Domains
«
Reply #2 on:
April 24, 2008, 23:49:31 »
Quote from: datahell on April 24, 2008, 23:13:57
Better post how to strengthen security...
I will write a guide, as soon as possible.
Logged
Print
Pages: [
1
]
« previous
next »
Elxis CMS Forum
»
Support
»
Security
»
Hackers Jack Thousands of Sites, Including UN Domains