The Cache: Technology Expert's Forum
 
*
Welcome, Guest. Please login or register. February 12, 2012, 06:39:31 PM

Login with username, password and session length


Pages: [1]
  Print  
Author Topic: U.S. Treasury Web sites hacked, serving malware  (Read 282 times)
isthisthingon
Global Moderator
Lifer
*****
Offline Offline

Posts: 2868



View Profile
« on: May 04, 2010, 01:02:35 PM »

http://www.networkworld.com/news/2010/050410-us-treasury-web-sites-hacked.html?source=NWWNLE_nlt_daily_pm_2010-05-04

Quote
According to Thompson, hackers had added a small snippet of virtually undetectable iframe HTML code that redirected visitors to a Web site in the Ukraine that then launched a variety of Web-based attacks based on a commercially available attack-kit called the Eleonore Exploit pack.

 D'oh!
Logged

I would love to change the world, but they won't give me the source code.
vsloathe
vim ftw!
Global Moderator
Lifer
*****
Offline Offline

Posts: 1669



View Profile
« Reply #1 on: May 04, 2010, 01:06:25 PM »

Meh.

Simple XSS, possibly session jacking from a Confused Deputy vector (Barney Fife?!)

No one was really "hacked". Further, there's not a whole lot you can do to prevent it. XSS holes exist all over the web, it is SO DAMNED HARD to sanitize everything. You'll invariably not think of some clever vector of attack on a site that large.


EDIT: I said "not really news", when in fact it quite is news.
Logged

hai
isthisthingon
Global Moderator
Lifer
*****
Offline Offline

Posts: 2868



View Profile
« Reply #2 on: May 04, 2010, 01:12:14 PM »

I fall for that crap all the time.  Why in the world would anyone question a conflict of interest between the likes of AVG and elevating concerns for security Wink  http://thompson.blog.avg.com/2010/05/treasury-website-hacked.html

His blog sig says it all:

Quote
For a short while today a couple of treas.gov websites were hacked, and were reaching out to an attack site in Ukraine.

...
Keep safe folks,
Roger

Boo 
Logged

I would love to change the world, but they won't give me the source code.
Pages: [1]
  Print  
 
Jump to:  

Perkiset's Place Home   Best of The Cache   phpMyIDE: MySQL Stored Procedures, Functions & Triggers
Politics @ Perkiset's   Pinkhat's Perspective   
cache
mart
coder
programmers
ajax
php
javascript
Powered by MySQL Powered by PHP Powered by SMF 1.1.2 | SMF © 2006-2007, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks


Valid XHTML 1.0! Valid CSS!