Computerworld
Assault on United Nations Web site claims innocents
Visitors drafted for botnet army, exposed to identity theft and fraud
Darren Pauli  28 August, 2007 13:20

The United Nations (UN) is the latest victim in a string of hacking attacks aimed at identity and credit card theft, and building botnet hordes.

The attack on the UN Asia Pacific Web site is believed to originate from the same group responsible for attacks on the US-based Biotechnology Information Organization and the prominent Indian Syndicate Bank.

The financially-motivated incursions, launched from the same remote location, infected a server common to all three Web sites and downloaded a Trojan to visitor computers via drive-by attacks.

A keylogger and a Trojan were download to visitor computers, flagged by an online scanner as positive to multiple Microsoft vulnerabilities, via hidden Java iFrames which is an old trick to refer visitors to a compromised server.

The Trojan maintains a backdoor, allowing attackers to monitor and hijack user machines to steal valuable user data, and turn the computer into a zombie as part of a botnet horde.

Websense Australia and New Zealand country manager, Joel Camissar, said such attacks exploit remote servers with weak security and typically target common brand names to maximize exposure.

"The groups will target ISPs which don't have sufficient security, common brands of servers, and servers in locations without tight controls or law enforcement," Camissar said.

"Typical scanners [used in attacks] only scan for one vulnerability but this looked for multiple exploits.

"We informed the authorities who's job it is to pursue them, shut down their servers and bring them to justice."

The attack executed the malicious e.js JavaScript file to create two additional iframes, and did not trigger any Java or anti-virus alerts.

Websense discovered the attack on The United Nations Aids and HIV Web portal after scanning 600,000 Web pages as part of routine malware detection.

Camissar said it is unknown if the group is responsible for more attacks.

Computerworld Buyer's Guide - Vendors Matched to this Article

Comments

Post new comment

Login or register to link comments to your user profile, or you may also post a comment without being logged in.
The content of this field is kept private and will not be shown publicly.
Enter the fully qualified URL, eg. http://www.example.com/
  • Web page addresses and e-mail addresses turn into links automatically.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd>
  • Lines and paragraphs break automatically.

More information about formatting options

Add to Google
Computerworld Buyer's Guide - Vendors Matched to this Article
Zones
Zone logoZones provide focussed content from Computerworld and leading technology partners.
Newsletter Subscription
Newsletter Subscription
Sign up for our Computerworld newsletters!
Syndicate content
 

Computerworld Webinar

Thursday, June 11th, 2009
10:30am EST (Sydney, Australia)
Screening at your PC

Computerworld is hosting a 30 minute live webinar to help you to learn how unified communications can save you money, foster innovation and business agility by making it easier for people to find, reach and collaborate with one another.

Register Now

Computerworld Community Comments
Whitepaper

Master Data Management as “Plan B”: Why Your Data Warehouse, CRM, ETL and EII Solutions Are Better with MDM

The problems with corporate information extend beyond escalating data volumes. High-quality master data is reliable and effective when availed to enterprise business processes. Read more about how MDM provides new solutions to new problems.

Enterprise IT Buyer's Guide
Find Technology Vendors Fast
 
Find vendors by name | Find by category
Sponsored Links
 
Send Us E-mail | Privacy Policy
Features List | Media Kit | Advertising | Contact Us

Copyright 2009 IDG Communications. ABN 14 001 592 650. All rights reserved.
Reproduction in whole or in part in any form or medium without express written permission of IDG Communications is prohibited.