Google Search

Showing posts with label websites. Show all posts
Showing posts with label websites. Show all posts

Monday, June 3, 2013

Fake Zendesk security notice spammed out, directs traffic to Canadian drug websites

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

I'm always on the lookout for breaking news about companies who might have had their systems hacked, so when I received the following email earlier today my interest was piqued.

Its subject line was "An important notice about security".

Fake security notice, pretending to be related to Zendesk breach

We recently learned that the vendor we use to answer support requests and other emails (Zendesk) experienced a security breach.

We're sending you this email because we received or answered a message from you using Zendesk. Unfortunately your name, email address and subject line of your message were improperly accessed during their security breach. To help keep your account secure, please:

* Don't share your password. We will never send you an email asking for your password. If you get an email like this, please let us know right away.

* Beware of suspicious emails. If you get any emails that look like they're from our Support Team but don't feel right, please let us know - especially if they include details about your support request.

* Use a strong password. If your password is weak, you can create a new one [LINK]

We're really sorry this happened, and we'll keep working with law enforcement and our vendors to ensure your information is protected.

Support Team

In a nutshell, the email claims to be from an online company which is using the Zendesk customer service portal to help it answer queries from customers.

ZendeskYou may even remember that Zendesk was hacked in February, and companies such as Tumblr, Twitter and Pinterest contacted some of their users to warn them that email addresses were possibly exposed.

What's different this time is that the body of the email doesn't really make clear *what* company is contacting me. Which seems strange.

Yes, the email mentions Zendesk - but just *who* is the company that was using Zendesk and has suffered as a result of the breach at Zendesk?

With no clear details in the email, the only way to find out is to click on the links... right?

Well, if you do that, you'll find your browser taken on a journey which ultimately (via some temporary redirects) leads you to a Canadian pharmacy website, trying to sell you Viagra and Cialis:

Canadian Pharmacy website

In short, the whole email is a campaign - using the disguise of an important security notice (complete with sensible advice to use strong passwords, and be wary of unsolicited emails!) to trick you into clicking on the link.

These cybercriminals certainly have some gall.

Of course, whoever is behind this campaign could easily change the redirects to point to a more malicious webpage, or a phishing site if they wished. Which would make it even worse.

Interestingly, this isn't the only way in which the spammers have been promoting this particular online drugs store.

Paul Baccas in SophosLabs uncovered for me that in the last 24 hours we have also had reports from customers who have received bogus Facebook notifications pointing to the same site.

Facebook-related spam message

We all probably know someone who is so addicted to Facebook, and stalking their friends' online activity, that they wouldn't hesitate from clicking on a link which they believed had come from the social network.

Remember to always practice safe computing online, including the rule about always being suspicious of unsolicited emails.

If you're not careful, you might not only be visiting spammers' websites - you could also potentially be putting your computer and its sensitive data in danger.

Follow @gcluley

View the original article here

Friday, March 15, 2013

Anatomy of a phish - how crooks hack legitimate websites to steal your details

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Old-school phishing is where cybercrooks lure you into logging in to your bank account on one of their websites.

When you enter your personally identifiable information (PII), as you would on the bank's real site, it gets uploaded to the crooks instead of to your bank.

The idea, of course, is that they then use the credentials they just stole to start draining your account.

So phishing is still worthwhile to the crooks, even though it doesn't seem to be quite as successful as it used to be. Many of us have learned to take great care when we're banking online, and to check for the "vital signs" of a scam before we trust a website with our usernames and passwords.

Nevertheless, the phishers are still giving it all they've got. By combining simplicity with accuracy, they're creating banking scams that are much more believable than the crude and misspelled emails and websites that were common a few years ago.

If you pick your moment, or just get lucky, there's still money to be made.

In Australia, for example, today (at least in Sydney) has been a very wet and gloomy public holiday.

Just the sort of morning to loaf on the couch with your laptop or your iPad and goof off online, where you might have received an email like this one:

Many banks now have a closed cloud-style email service built into their internet banking sites. The idea is that you'll get into the habit of logging in securely to read important messages, rather than believing what arrives in insecure emails.

The bank still sends you emails, but they don't contain any detail - they just give you an overview (e.g. "your statement is ready"), and advise you to read the full message on the secure site. A bit like the message here, in fact.

But what your bank won't do is to invite you to click a link to get to the secure site. They rightly leave you (indeed, they urge you) to find your own way to the banking portal, so you're not at the mercy of the URL embedded in the email.

So the link here is certainly phishy - it shouldn't be present at all - but it doesn't look like the sort of obvious phishing nonsense you often see.

You probably know what I mean: weird and unlikely domains such as really.your.bank.wefljdrsecxr.example.org that are an instant giveaway of bogosity.

In fact, this phish links to a government website in .cn (that the People's Republic of China, or PRC):

The government site seems to have had a security lapse, allowing the crooks to add a small and simple web page called nabau.html.

This page silently redirects your browser elsewhere by using this HTML:

The redirect takes you off to another hacked site, specified in the URL as an IP number rather than as a domain name.

This presents you with a bogus login page hosted on a web server (it looks like part of the Computer Science department) at a Colombian university:

Ironically, this bogus page helpfully advises you to keep up to date with anti-virus, firewall software and the latest patches, and urges you to report phishing scams to NAB.

When you click Login to submit the form, the POST request (HTTP's name for an upload) goes to yet another hacked web property. This one is a student vacation site in the USA, apparently with some insecure plugins in its blogging subdirectories.

You never get to see the site's main page, which is unexceptional:

Instead, the web upload that is linked to from from the Colombian university page gives the crooks their first page of login data.

Then you're shuffled back to the server in Colombia to face a request for another page of PII:

The POST request on this page uploads your formful of data to the same place as before: the US student vacation site.

This time, the vacation site bounces you back to Australia, rounding off the phishers' journey.

You end up unremarkably on National Australia Bank's own site, albeit that you're on the regular main page, not amongst the internet banking pages:

Let me be quick to say that you ought not to fall for this sort of phish:

NAB wouldn't have put a link in the email, so you ought not to have clicked it.None of the so-called banking sites referenced a nab.com.au URL.None of them used secure HTTP, also known as HTTPS.

(HTTPS is the protocol that puts a tiny padlock in the address bar at the top of your browser's screen.)

Nevertheless, this phish didn't take you to any sites that would have stood out, under normal circumstances, as part of the cybercriminal underworld.

It relied on three unremarkable and legitimate servers, owned by legitimate organisations and operated by unsuspecting sysadmins, in three different countries: PRC, Colombia and the USA.

That's why even self-proclaimed "safe surfers" - people who back themselves not to wander off into obviously-shady parts of the web - should consider themselves at risk.

Be careful out there. And that applies whether you're browsing or running an online business.

The crooks want to redirect your browser into harm's way, and they want to use your servers to help them do so.

Follow @duckblog

Running a web server at home?

Why not try out the free Sophos UTM Home Edition?

You get web and email filtering, web application firewall, IPS, VPN and more for up to 50 IP addresses. You can also protect up to 12 Windows PCs on your network with Sophos Anti-Virus!

(Note: registration required.)


View the original article here

Saturday, February 16, 2013

Internet Explorer zero-day exploit found on more websites. Fingers point towards Elderwood Project

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Paul Baccas, a researcher at SophosLabs, has uncovered two new sites which have been hit by the recently-discovered Internet Explorer zero-day remote code execution vulnerability.

The attacks bear all the hallmarks of previous infections spread by the so-called Elderwood Project.

First up is a website serving the Uyghur people of East Turkestan:

Uyghur website

A folder called "netyanus" had been created on the website, containing the following files:

Helps.htmldeployJava.jsnews.htmlrobots.txttoday.swfxsainfo.jpg

The website has since been cleaned-up of its malware infection, but clearly whoever infected it had an interest in infecting anyone who visited the site.

Sophos products detect the HTML files as Exp/20124792-B.

Alert. Image courtesy of ShutterstockThe file news.html (detected as Exp/20124792-B) decodes the obfuscated zero-day exploit code inside robots.txt, and executes it.

Sophos products detect the SWF file as Troj/SWFExp-BF, the remaining HTML file as Exp/20124792-B, and the obfuscated code hidden inside xsainfo.jpg as the Troj/Agent-ZMC Trojan horse.

As there is currently no proper patch for the Internet Explorer security vulnerability, chances are that a good proportion of people visiting the Uyghur site could have ended up with their computers becoming infected.

If you weren't aware, the Uyghur people of East Turkestan have, like the inhabitants of Tibet, long campaigned for independence from the People's Republic of China and complained about persecution.

At the same time, SophosLabs discovered another infected website - this time, it's the website of an Iranian oil company, based in Tehran.

Infected Iranian oil website

At the time of writing, the Iranian website is still carrying an infection so we have obscured some of its details in the image above.

On this occasion, the files implanted by hackers code take the following form:

deployJava.jsexploit.htmlnews.htmlrobots.txttoday.swfxsainfo.jpg

Hopefully, if you have been paying attention, some of those filenames will look familiar to you.

You may not be in the habit of visiting websites associated with the Uyghur people, or checking out the websites of Iranian oil firms... but clearly some people and organisations may visit such sites, and could be at risk of having their computers silently infected as a result.

All the same, until a proper patch is pushed out by Microsoft, Internet Explorer users are potentially at risk from attacks which exploit this vulnerability and should take care to ensure that they have layered defences in place to minimise the risk.

Follow @gcluley

Alert image courtesy of Shutterstock.


View the original article here

Tuesday, January 1, 2013

Man charged over attack on UK police, Oxbridge university websites

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Radcliffe Camera, Oxford. Image from ShutterstockA 20-year-old British man will appear in court next month, charged with attempting to bring down the websites of Oxford and Cambridge universities.

Lewys Martin, from Kent, faces a total of 17 counts following an investigation by Kent Police's Special Branch investigations team, and the Kent Police Digital Forensic Unit.

The charges brought against the 20-year-old relate to denial-of-service attacks on various websites, including a website belonging to the Kent police force, theft of personal data and failure to disclose passwords for encrypted computer equipment.

Martin is scheduled to appear at Maidstone Magistrates Court on December 20th in relation to the charges.

This feels like an appropriate time to remind all readers that denial-of-service attacks are against the law in many countries around the world, and can lead to a jail sentence.

Lewys Martin is currently serving a sentence in prison, after writing malware disguised as a patch for the "Call of Duty" video game, and attempting to break into local colleges to steal computer equipment.

Follow @gcluley

Radcliffe Camera, Oxford image from Shutterstock.


View the original article here

Wednesday, November 28, 2012

"Im getting paid!" - Websites hosted on WordPress hacked due to users' poor password security

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

WordpressMillions of blogs hosted on WordPress.com can breathe a sigh of relief - although a hacker did manage to break into thousands of sites and publish a make-money-fast advert, it wasn't because of any vulnerability on the WordPress.com site itself.

Instead, it seems users had simply been careless with their password security.

The alert was initially raised by The Hacker News (THN) and Sucuri, after some blog owners received messages from WordPress.com telling them that their passwords had been reset.

One affected WordPress.com user told THN that he had discovered hackers had published a page containing a money-making advertisement (pictured below).

Hacked page on a WordPress.com website

A Google search for

site:wordpress.com "Im getting paid!"

finds evidence of thousands of sites that suddenly found they had unwittingly published "Im getting paid!" webpages.

Compromised accounts

Although some theorised that the hacker may have exploited a vulnerability on WordPress.com (which would be a very serious problem as the WordPress.com infrastructure is used by many of the world's most popular blogs and news sites), the truth seems to be rather more pedestrian.

Barry Abrahamson from Automattic (the company which runs WordPress.com) told Naked Security that there was no compromise of the WordPress.com servers, and that rather than vulnerability the most likely cause of the problem was "people sharing the same password across multiple services."

According to the firm, it spotted the problem quickly, notified affected users and reset passwords.

It's good news that the sites hosted on WordPress.com weren't hacked due to a vulnerability. After all, many blogs choose to host on WordPress.com in order to avoid the headache of managing their own security and updates on self-hosted WordPress installations.

So, remember folks - please use different passwords for different websites. If you use the same password in multiple places, it only requires your password to be stolen in one place for it to have an unpleasant impact on your other online activities.

Follow @gcluley

View the original article here

Thursday, November 15, 2012

Facebook scans private messages to inflate the "Like" counter on websites

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Like buttonFacebook has confirmed that it's scanning private Facebook messages to boost "Like" counters on third party websites.

Killswitch.me, described by The Next Web as a "Polish startup", on Thursday posted a since-deleted YouTube video on Hacker News that showed that sending a link to a website via a private Facebook message increased that website's Facebook Like counter by two likes.

And then by another two. And then another, and another, causing the Likes to steadily balloon.

In fact, one poster on Hacker News testified that people could pump it up by 1,800 Likes per hour.

The video, removed from YouTube, can still be viewed on Vimeo (possibly not safe for work).

When TNW's Emil Protalinski checked with Facebook, company spokespeople confirmed that they had discovered a bug affecting Like counts.

But the bug didn't relate to the actual private-message peeping.

Rather, the bug concerned inflating page counts by two Likes instead of one, as a spokesperson told TNW:

We did recently find a bug with our social plugins where at times the count for the Share or Like goes up by two, and we are working on [a] fix to solve the issue now. To be clear, this only affects social plugins off of Facebook and is not related to Facebook Page likes. This bug does not impact the user experience with messages or what appears on their timelines.

The fact that this is function is baked into Facebook code as opposed to being a potential fluke of privacy transgression is confirmed, as Protalinski noted, on the Facebook Developers page, which states that a websites' number of Likes is the sum of:

* The number of likes of this URL

* The number of shares of this URL (this includes copy/pasting a link back to Facebook)

* The number of likes and comments on stories on Facebook about this URL

*The number of inbox messages containing this URL as an attachment.

Facebook message

Facebook's scanning of private messages isn't new.

The power of the social media mammoth's data mining technology when applied to private messages came to light in March, when Facebook was credited with quashing potential child molestation between a 13-year-old girl and a man in his 30s who were having a private Facebook conversation about sex.

As Facebook described it at the time, its data mining technology scans postings and chats for criminal activity, analyzing relationships to find suspicious conversations between unlikely pairings: i.e., between people of widely varying ages who only have loose and/or newly formed relationships.

Private stamp, courtesy of ShutterstockEmail providers such as Gmail also have a long-standing practice of reviewing messages to weed out spam and to target ads.

Those are reasonable uses of data mining technology, but it's disconcerting to find what might be yet more intrusive forays into allegedly private messages.

Thus, it's a bit of a relief to learn that Facebook later clarified the privacy issue, saying that "absolutely no private information" is exposed in the private-message-derived Like inflation:

Absolutely no private information has been exposed and Facebook is not automatically Liking any Facebook Pages on a user's behalf.

Many websites that use Facebook’s 'Like', 'Recommend', or 'Share' buttons also carry a counter next to them. This counter reflects the number of times people have clicked those buttons and also the number of times people have shared that page's link on Facebook. When the count is increased via shares over private messages, no user information is exchanged, and privacy settings of content are unaffected. Links shared through messages do not affect the Like count on Facebook Pages.

At any rate, the integrity of the Facebook Like counter has been in question for a while.

It came up again last week, when well-Liked pages began to sag as Facebook swept out bogus Likes gained via malware, compromised accounts, duped users or purchased bulk Likes.

Unfortunately,the fact that Facebook registers URLs shared in private messages means that we're now all potentially contributors of unintended likes.

It means that sharing a link that outrages, disgusts or appalls the sender will result in that website's Facebook Like counter going up.

Researching hate groups? Discussing corporate malfeasance?

Be prepared to add to your subjects' Facebook counter glow, whether you want to or not, if you send URLs via private Facebook conversations.

If you're on Facebook, and want to learn more about security and privacy issues on the social network, consider joining the Naked Security Facebook page.

Follow @LisaVaas
Follow @NakedSecurity

Private stamp, courtesy of Shutterstock


View the original article here

Tuesday, July 3, 2012

Father's Day spam floods in, pointing to gambling websites

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

SophosLabs has intercepted a large number of "Buy your dad a cigar" spam messages, currently being spread across the internet in the run-up to Father's Day this weekend.

Cigar spam for Father's day

If you click on links in the email you will typically end up on gambling websites.

Presumably the spammers are hoping to earn affiliate commission by driving traffic to the websites, and hope that the thought of buying a cigar at the last-minute for Father's Day will be enough to get folks to click.

That or the bad guys have goofed up their attempt to earn cash pointing to cigar websites, and are pointing to other websites by mistake.

The truth is hard to determine, but one thing is clear. You shouldn't click on links in unsolicited emails, and you should never consider purchasing products promoted to you via spam messages.

If you're a father, I hope you have a good weekend - and receive a more pleasant gift than an unsolicited spam email.

http://twitter.com/gcluley

View the original article here

Wednesday, May 2, 2012

36 websites selling credit card details shut down [VIDEO]

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Cybercrime is big business these days, in fact it's an industry. So it's not a surprise to find that criminals are embracing ecommerce. But I'm sure some will be surprised to discover just how professional and legitimate criminal websites can appear.

For instance, watch the following video to see footage of a website that was selling stolen credit card details.


(Enjoy this video? Check out more on the SophosLabs YouTube channel.)

The UK's Serious Organised Crime Agency (SOCA), working alongside the FBI and the US Department of Justice, has announced that it has seized the domain names of 36 websites used to sell stolen credit card information.

Searching for stolen credit card details

The websites use advanced e-commerce Automated Vending Cart (AVC) platforms to allow them to sell large numbers of credit card and bank details.

Visitors to the websites are now greeted by a message from the authorities:

Law enforcement message

According to a SOCA statement, two men were arrested early yesterday morning suspected of making large scale purchases of compromised data from websites such as those described above.

In addition, the UK’s Dedicated Cheque & Plastic Crime Unit (DCPCU) has seized a number of computers suspected of being used to facilitate Fraud Act offences, and an AVC operator based in Macedonia has been arrested by the Macedonian Ministry of Interior Cyber Crime Unit.

We should all be grateful that the authorities are taking action against those who are turning cybercrime into such a significant underground industry.

http://twitter.com/gcluley

View the original article here

Thursday, January 5, 2012

Large percentage of websites vulnerable to HashDoS denial of service attack

Over 100,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

28c3 logoResearchers presented information on a long standing vulnerability in most web application frameworks at today's 28c3 (28th Chaos Communication Congress) security conference in Berlin, Germany, Earth, Milky Way.

Alexander “alech” Klink and Julian “zeri” Wälde delivered a demonstration and lecture titled "Efficient Denial of Service Attacks on Web Application Platforms". In their lecture they explained in detail how most web programming languages utilize hashes and manage collisions.

The type of hashing used by PHP, Java, Python and JavaScript in this attack is not a cryptographic hash, it is a simple mathematical hash used to speed up storing and retrieving data posted to web pages.

Collisions in these hashes are expected and managed by the programming framework in a reliable way when not being abused.

It is known that an attacker who understands the values used in your hashing algorithm could pre-compute a set of values that result in all hashes being the same. Comparing these hashes becomes a quadratic function which can create a very heavy load on the web server.

An example given showed how submitting approximately two megabytes of values that all compute to the same hash causes the web server to do more than 40 billion string comparisons.

During the talk they performed a denial of service attack against an Apache Tomcat server, which is a commonly used java servlet container for hosting web pages.

They sent the server some pre-computed hash collisions and showed how it used 100% of their processor for the entire talk.

They explained that the proper solution to the problem is for the developers of the vulnerable programming languages to randomize the key used when computing hashes. This would prevent an attacker from being able to pre-compute the collisions.

Perl was updated to fix this problem in version 5.8.1, which was released in September of 2003. For some reason most of the other languages did not take the cue from Perl and are still vulnerable to these attacks.

Web application technologies slide

Without fixing the hashing functions in the languages themselves there are three mitigation techniques available to website operators.

Reduce the length of parameters that can posted.Reduce the number of parameters accepted by the web application framework.Limit the amount of CPU time that any given thread is allowed to run.

Microsoft has released an advisory for ASP.NET customers with advice on mitigation until they are able to ship a more permanent fix.

It may be possible to configure web application firewalls and other network security devices to limit the impact of an attack as well, it would certainly be worth your time to consult with your security vendors to see if they can help.

Update: Microsoft have released a fix less than 24 hours after disclosure. ASP.NET admins can download patch MS11-100 to protect their IIS web assets. More information is available on the Microsoft SRD blog.

MS11-100 also fixes three other privately disclosed vulnerabilities, including one which could allow arbitrary code execution and elevation of privilege. Microsoft considers this update as critical, and I concur.

Follow @chetwisniewski

Tags: 28c3, asp.net, ccc, CVE-2011-3414, denial of service, DOS, Hashes, IT, Java, MS11-100, PHP, python, vulnerability


View the original article here

Monday, January 2, 2012

'PrivateX' hackers target more gov't websites

MANILA, Philippines - Hackers who defaced the website of Vice President Jejomar Binay and at least 5 other sites have warned that they will attack more government websites.
Posts made in the past few days on the Facebook page of the PrivateX hackers' group mentioned several other government agencies.
"Expect us," said a December 29 message, with an attached article from the Department of of Social Welfare and Development.

The hacker group's founder, in an email to abs-cbnNEWS.com, said one of their members identified as "Blackrain" will answer questions about the hacking incidents soon.

The group's latest post on Monday made fun of the Department of Health by creating a page with an ASCII art showing a large nuclear explosion.

"Anonymous #OccupyPhilippines ProjectX PrivateX Philker," the message below the image said. "We are Anonymous, We are legion, We don't forgive, We don't forget."

Other government websites mentioned by the group in the page are those belonging to the Optical Media Board, the Philippine National Radiation Institute, the Senate Electoral Tribunal, the Commission on Appointments, the Philippine Racing Commission, and sites owned by the local governments of Libon, Camiguin, and Manaoag.

Some of the websites remained defaced Monday afternoon.

OVP admits website hacked

Meanwhile, the Office of the Vice President's (OVP) website has been fixed.

Joselito Salgado, head of the OVP's media affairs division, said the website has hacked by the PrivateX group around 4 p.m. on Sunday and was down for more than 15 hours.

He said the OVP's website is being hosted by the Advanced Science and Techology Institute (ASTI), an agency under the Department of Science and Technology (DOST).

"We have been informed that ASTI is looking into the incident and will put in place the needed safeguards," Salgado said.

"The OVP website provides information on the programs, projects and services of the Office of the Vice President. It also provides the public the opportunity to bring their concerns to the attention of VP Binay. Unfortunately, the hacking incident has deprived the public, particularly our Overseas Filipino Workers with a channel to communicate with the Vice President," he said.

PrivateX, in a statement, said it does not seek to taunt the OVP website's administrator "but to point out that transferring to a paid hosting doesn't mean that you are secured."

"We did not delete any file on the server but we created an index.html and redirected the index.php to index.html (Deface page)," they added.


View the original article here

Wednesday, September 28, 2011

Hackers hit Syrian government websites

**FILE** Syrian President Bashar Assad (Associated Press)**FILE** Syrian President Bashar Assad (Associated Press)

Hackers supporting Syria’s anti-government protesters attacked 10 websites belonging to central or local government ministries, spreading the six month-long bloody rebellion against the dictatorship of Bashar al-Assad into cyberspace over the weekend.

They replaced the websites’ home pages with caricatures of Mr. Assad, videos of protesters, an interactive map showing the names of protesters killed by the Syrian military and links to a page with tips on how to avoid online surveillance by Syria’s intelligence agencies.

“These were beautifully done, skillful hacks,” Jillian C. York, director for international freedom of expression at the Electronic Frontier Foundation, told The Washington Times.

The home pages of the Syrian labor and transportation ministries were replaced by a caricature of Mr. Assad, with a snakelike neck and the caption in Arabic:

“Don’t let Bashar monitor you online.”

The page also contained a link to a set of tips for protesters on avoiding online surveillance by the regime.

Caricatures of Mr. Assad - like most forms of political expression - are illegal under Syria’s emergency law.

The home page of the Ministry of Culture on Sunday showed amateur videos, including one of a popular singer with his throat cut, and another of a respected political cartoonist whose hands were broken. Both attacks were reportedly carried out by pro-government thugs.

The home pages of the seven largest municipalities in Syria were all replaced with an interactive map with the names of more than 2,300 protesters reportedly killed by the regime since the protests began in March.

By Monday afternoon, the central government websites had been repaired and the municipal ones taken off-line altogether.

Ms. York said that, because of the “impeccable English” and high levels of technical skills used by the hackers, “I strongly suspect they had coordinated support from outside Syria.”

“They were definitely executed with more sophistication” than similar hacks on Tunisian government sites earlier this year during the protest wave in that country, she said.

She added that the Syrian attacks looked to her like the work of “people skilled in graphic design, not just hacking.”

The hacks, carried out Sunday, were claimed by the online collective known as Anonymous. Members of the group are being hunted by the FBI and European law enforcement agencies for their illegal hacking activities.

Last year, for instance, the group launched online hacking campaigns in support of the anti-secrecy group WikiLeaks, targeting financial and government websites in Europe and the United States.

Story Continues ?

View Entire Story © Copyright 2011 The Washington Times, LLC. Click here for reprint permission.

Shaun Waterman

Shaun Waterman is an award-winning reporter for the Washington Times, covering foreign affairs, defense and cybersecurity. He was a senior editor and correspondent for United Press International for nearly a decade, and has covered the Department of Homeland Security since 2003. His reporting on the Sept. 11 Commission and the tortuous process by which some of its recommendations finally became ...


View the original article here