Wednesday December 3, 2008 2:55 AM AEST
Latest Comments
"I feel it with you guys. These irritating interruptions on privacy MUST be stopped. It is a ..."
by Jan Wilmans | Dec 2, 2008 7:11 PM
 
"My AVG WILL NOT UPDATE"
by James Downs | Dec 2, 2008 5:58 AM
 
"Concerned man's comments seem to intimate that if I'm using agents all will be well but the ..."
by Werner K | Nov 26, 2008 8:36 PM
 
"That will enhance Microsoft Office system, including SharePoint - good platform for enterprise ..."
by SGE | Nov 25, 2008 3:29 PM
 
"how many users allow per session? because the digital persona password manager allows only 10 ..."
by Daniel | Nov 25, 2008 12:14 AM
Web

'Times of India' site cleaned of malware

  • Email a Friend
  • Print Page
'Times of India' site cleaned of malware
By Dan Kaplan
Nov 13, 2007 4:08 PM
Tags: "times | of | india" | "times | of | india | security | breach" | "virus | on | times | of | india"
The Times of India's website was hammered with a Web 2.0-style attack in which the malware writers compromised several pages with malicious scripts. The scripts pointed to a remote site containing IFRAMEs, which pointed to two other malicious sites.

"That would start this automatic chain of exploit, and all of it was invisible to the user," Mary Landesman, senior security researcher at ScanSafe, one of the first security firms to detect the attack, told SCMagazineUS.com today.

She said that at least two of the exploits took advantage of a Microsoft vulnerability, patched last year, involving Data Access Components. Mark Miller, director of security response for Microsoft, told SCMagazineUS.com today in an email that none of the software giant's customers or partners have reported being affected by this attack.

But she is unsure of the origin of some nine other exploits that ScanSafe researchers identified in the attack, although it is likely they were created using the Metasploit Framework, an open-source framework for developing exploit code.

Infection began when a trojan was installed on the victim's machine, Landesman said. That initiated the dropping of more than 430 unique files, including binaries, cookies, Flash and web files.

"This is sort of reminiscent of the adware sieges we saw a few months back," she said. "Most of the malware we see tends to be much more surreptitious. Whoever these attackers were, I would have to characterise them as clumsy.

While I said that the visitor to the site who may have been victimised may not have been aware of any downloads, certainly the performance on their system would have been impacted."

The situation was exacerbated because traditional security solutions did little to deter the attacks.

"Detection of this was extremely low by anti-virus vendors," Landesman said.

This is the second major website compromise to hit India in recent months. In September, the Bank of India website was disabled for four days after hackers embedded malware on its home page.

Experts said the site was distributing 30 types of malware, which served as the payload for two types of previously patched Windows vulnerabilities.

The Times of India is an English-language site that has global reach. Alexa ranks the site as the world's 481st most trafficked site.

See original article on SC Magazine US

Secure Computing Magazine

 
Ads by Google
Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 
Tripwire - Click here to win an iTouch
 
 
Vulnerabilities & Exploits Whitepapers