Latest Comments
"My AVG WILL NOT UPDATE"
by James Downs | Dec 2, 2008 5:58 AM
 
"Concerned man's comments seem to intimate that if I'm using agents all will be well but the ..."
by Werner K | Nov 26, 2008 8:36 PM
 
"That will enhance Microsoft Office system, including SharePoint - good platform for enterprise ..."
by SGE | Nov 25, 2008 3:29 PM
 
"how many users allow per session? because the digital persona password manager allows only 10 ..."
by Daniel | Nov 25, 2008 12:14 AM
 
"security through obscurity...shows how detached HIPAA is from reality."
by priceOfFishInChina | Nov 20, 2008 1:19 PM
Web

Super Bowl blitz begins: Bogus game sites with malware popping up

  • Email a Friend
  • Print Page
By Jack Rogers
Jan 29, 2008 11:17 AM
Tags: "Super | Bowl" | | "super | bowl | hacker" | "malware | super | bowl" | "NFL" | "website | security"
Security researchers have warned that malware-laced bogus Super Bowl websites have begun appearing, the first wave of what is expected to be a major campaign of game-related cyberattacks.


TrendLabs reported on its blog that it has detected two malware-infected sites with similar sounding URLs to the official Super Bowl XLII game site.

According to TrendLabs, the two malware sites – including the words “www-superbowl.html" and “www-superbowlcom.html” in their URLs – were found in the servers of a Czech hosting provider believed to have been hacked. TrendLabs said in its blog posting that it contacted the Czech CERT and the Czech hosting provider after detecting the malicious code.

The two malware sites are turning up in search results when users google "Superbowl," TrendLabs said. 

Dan Hubbard, vice president of security research at Websense, told SCMagazineUS.com last week that the most likely form of attack to materialise in the run-up to the Feb. 3 clash between the New England Patriots and New York Giants will be botnet-generated phishing emails delivered in messages with Super Bowl-related subjects.

Hubbard also said that a number of domains with Super Bowl-related URLs have been registered, but the destination sites for these URLs have yet to materialise – raising the possibility that a number of malware-infused sites will pop up in the next few days hoping to snare fans googling myriad Super Bowl sites.

While Super Bowl-related phishing emails and bogus game sites containing malware may be inevitable, perhaps the ripest potential targets are the largest legitimate Super Bowl-related websites – like the official game site (www.superbowl.com) and the Patriots' website, which now are notching millions of visits per day.

Last year, the website for Dolphins Stadium, which hosted Super Bowl XLI, was victimised when a JavaScript-enabled trojan was inserted in the homepage for the site. Websense Security Labs was in the forefront of the discovery of last year's hack attack, which enabled hackers to steal information from visitors for several hours before detection.

Hubbard also told SCMagazineUS.com that the increased sophistication and interactive functionality of the major Super Bowl websites also may have increased the vulnerability of these sites.

“These official sites are constantly adding bells and whistles, including functions that encourage users to contribute content. These features are going up so quickly, essentially they are in beta and released at the same time,” he said, adding that Super Bowl site managers must be constantly vigilant in scanning their sites for vulnerabilities, keeping pace with would-be hackers who no doubt are doing the same thing.

See original article on scmagazineus.com

Secure Computing Magazine

 
Ads by Google
Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 
Tripwire - Click here to win an iTouch
 
 
Vulnerabilities & Exploits Whitepapers