DNforum.com - Domain Sales, Domain Forum, Domain Appraisals
 
Register Now! Welcome to Dnforum.com You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast and simple so please, join our community today! If you have any problems with the registration process or your account login, please contact us.
Go Back   DNForum - Domain Sales, Domain Forum, Domain Appraisals, Domain Registrars > Domain News, Beginners Guides and Legal Stuff! > Domain News
Reply
 
LinkBack Thread Tools Display Modes
Old 04-26-2008, 08:02 PM   #1 (permalink)
 
Rockefeller's Avatar
 
Name: Justin Godfrey
Last Online: Today 05:07 PM
iTrader: (279)
Join Date: Apr 2005
Posts: 6,400
DNF$: 2,931
Location: Milwaukee, WI
Country:


Exclamation Department of Homeland Security website hacked!

The sophisticated mass infection that's injecting attack code into hundreds of thousands of reputable web pages is growing and even infiltrated the website of the Department of Homeland Security.

While so-called SQL injections are nothing new, this latest attack, which we we reported earlier, is notable for its ability to infect huge numbers of pages using only a single string of text. At time of writing, Google searches here, here and here showed almost 520,000 pages containing the infection string, though the exact number changes almost constantly. As the screenshot below shows, even the DHS, which is responsible for protecting US infrastructure against cyber attacks, wasn't immune. Other hacked sites include those belonging to the United Nations and the UK Civil Service.

The attack causes infected sites to redirect visitors to destinations that attempt to install malware on vulnerable machines. At time of writing, the malicious payloads attacked vulnerabilities that already have been patched. And in any case all three of the redirection sites were down, possibly because they were unable to handle the demand. But should the attackers get their hands on a newer exploit - say, one targeting a zero-day vulnerability in QuickTime - it would be relatively easy for them to swap out the payload.

One reason the infection has spread so widely is the attackers have managed to find a single attack string that seems to work on tens of thousands of different sites. Most web applications are custom -built for a particular site, so attackers likewise have to custom design attack parameters to exploit weakness. Not so here.

"These guys look like they've found a methodology to get a successful SQL injection generically across [many] websites," said Jeremiah Grossman, CTO of WhiteHat Security, which helps companies secure web applications. "That right there is like a skeleton key."

The script is also notable for its ability to slip past web application defenses. The SQL query is mostly made up of HEX code, allowing it to obscure itself, at least to apps that use Microsoft SQL. MySQL and PostgreSQL are less easily fooled, according to researcher Ronald van den Heetkamp.

Sites are getting pwned because they fail to sanitize user supplied data. DHS security pros scrubbed the page clean the same day it got infected and took steps to make sure the same attack couldn't succeed against other parts of the DHS website, spokeswoman Amy Kudwa said.

"We're well aware of the fact that intrusions happen all the time and that's why we are doing all that we are to secure the .gov domain," she said.

In a recent interview with The Register, Greg Garcia, the DHS's assistant secretary for cybersecurity and telecommunications said: "our networks really are only as strong as the weakest link and because we are so interconnected, if there are companies that are not doing what they need to do to protect their networks, that in turn may be jeopardizing the security of companies that very well may be doing the right thing." (For the full interview, click here.)

While the number of pages that have been infected is high, not all are able to launch an attack once a user visits them, according to Roger Thompson, chief research officer of anti-virus provider AVG.

"Very often they're on a page but the stuff doesn't actually fire when you get there," he said. "This is not a cunning, premeditated task; it's just a blast. They're just planting the stuff where they can and the result is a lot of pages [that] don't do anything."

But webmasters should not be complacent about removing the injected code from their sites and fixing buggy web apps to make sure more don't spring up.

"It's the cleanup effort that's just going to be monstrous," said Grossman, who said affected companies will have to either remove each overwritten table record one at a time, or revert to a recent backup. "Either way, it's going to take forever."

Security workers better get cracking. ®

Source
__________________
Shoulda, Coulda, Woulda
Rockefeller is online now   Reply With Quote
Old 04-26-2008, 08:04 PM   #2 (permalink)
DNF Addict
 
Last Online: Today 03:49 PM
iTrader: (11)
Join Date: Oct 2002
Posts: 2,480
DNF$: 9,728
Location: Cali
Country:


Ruh roh
Poker is offline   Reply With Quote
Old 04-26-2008, 08:12 PM   #3 (permalink)
DN Coyote
 
draggar's Avatar
 
Name: Ed
Last Online: Today 05:10 PM
iTrader: (13)
Join Date: Dec 2007
Posts: 2,453
DNF$: 100
Location: South Florida
Country:


Wow, that's one hell of an attack.
__________________
Ask me about my Domain Management Tool! Only $5!
What's on Draggar's mind?
draggar is online now   Reply With Quote
Old 04-26-2008, 08:50 PM   #4 (permalink)
Platinum Lifetime Member
 
Name: chris
Last Online: Today 09:47 AM
iTrader: (20)
Join Date: Jan 2008
Posts: 396
DNF$: 1,500
Location: Connecticut
Country:


Quote:
Originally Posted by Rockefeller View Post
Sites are getting pwned
LOL have only seen that word for gaming
__________________
My Sedo Names
ddaybofb is offline   Reply With Quote
Old 04-26-2008, 09:07 PM   #5 (permalink)
Evolve your business
 
Acroplex's Avatar
 
Last Online: Today 05:32 PM
iTrader: (352)
Join Date: Feb 2004
Posts: 17,582
DNF$: 10,091
Location: Universal Citizen
Country:


Hacking? You mean, script kiddies at work.
__________________

Acroplex.com Professional Web & Graphics development
Acroplex is online now   Reply With Quote
Old 04-26-2008, 11:28 PM   #6 (permalink)
Platinum Lifetime Member
 
Last Online: 06-12-2008 10:36 PM
iTrader: (6)
Join Date: Jun 2003
Posts: 792
DNF$: 3,134
Location: www.adsenseforums.com
Country:


Speaking of DHS, G. Garcia gave a great one on one meeting in Montreal lately - thanks for that news bit Justin.

Rob
__________________
GEO ? Puebla.org - yes Puebla - 5.8M+ people Mexican City/State!
Also: defamation.org / defamatory.org / burglary.org / controversial.org / constituent.org / poutine.org / duos.org
RTM.net is offline   Reply With Quote
Old 04-26-2008, 11:56 PM   #7 (permalink)
Platinum Lifetime Member
 
south's Avatar
 
Name: Scott
Last Online: Today 12:56 PM
iTrader: (39)
Join Date: Dec 2006
Posts: 609
DNF$: 850
Location: Miami Fl/Dexter ME
Country:


Quote:
Originally Posted by Acroplex View Post
Hacking? You mean, script kiddies at work.
Exactly...

mod_security works well...
south is offline   Reply With Quote
Old 04-27-2008, 04:35 AM   #8 (permalink)
 
VirtualT's Avatar
 
Name: Kris
Last Online: Today 12:26 PM
iTrader: (72)
Join Date: Aug 2006
Posts: 2,064
DNF$: 292
Location: Lossless.com
Country:


how does this work, it looks to me like its just injected the url containing the malicious code into the title tag of the page
VirtualT is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules

Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -4. The time now is 05:32 PM.
Copyright @2001-2008 DNForum.com

Learn Domains
Promote Domains
Research Domains
Buy Domains
Resell Domains
Park Domains
Sell Domains
Build Domains
Host Domains
Trademark Domains
Domain Domains
manage Domains
Appraise Domains