Welcome | Sign In
TechNewsWorld.com
Malware

Cyber-Vandals Scrawl Antiwar Message on UN Site

Print Version
E-Mail Article
Reprints
Cyber-Vandals Scrawl Antiwar Message on UN Site

Calling themselves "CyberProtest," a group of hackers initiated what security experts believe was a SQL injection exploit on the Web page of United Nations Secretary-General Ban Ki-Moon. The hackers changed some text in one of Ban's speeches to include text accusing the United States and Israel of killing children.


Crystal Reports - Discover the Latest Innovations.
Download a free trial, view real-time 'behind the scenes' functionality, and learn about new Crystal Reports Server trade in options! Learn more.

A group of hackers infiltrated the United Nations' Web site over the weekend, defacing the page of Secretary-General Ban Ki-Moon with antiwar political graffiti.

Hackers reportedly replaced portions of recent speeches made by Ban with accusations that the United States and Israel are killing children. An Italian software developer first reported the hacked Web site, which was out of commission for most of Sunday as the UN scrambled to scrub it of the insertion. By Monday it was operational again.

By all accounts, the attack appeared to have been a SQL injection exploit, allowing the hackers to add their own HTML code to the Web site. The graffiti on the Web site suggested that at least three hackers that use the name CyberProtest were involved.

The Next Step

Beyond some embarrassment, political graffiti does not cause much harm either in cyberspace or in the real world. However, the fact that hackers were able accomplish their goals could have deeper ramifications, Sophos security consultant Ron O'Brien told TechNewsWorld.

"The concern about the ability to hack public Web sites is increasing because in addition to defacing the Web site, it is also possible to embed malware," he commented.

No malware was embedded in the UN site during this attack, he added.

The Latest Vector

It is becoming increasingly clear that infecting public Web sites is the latest preferred vector for hackers, he said.

"We are asking everyone who owns or runs a Web site to make sure they are not vulnerable in that respect," O'Brien said.

The best way to ensure a Web site is free of malware is to scan it at the server level, he noted.

From 5,000 to 29,000

Over the last month there has been a huge surge in such attacks on Web sites, he added -- from 5,000 per day a month or so ago to an average of 29,000 per day now.

More worrisome is that some are legitimate and well-trafficked Web sites. Besides the UN, the IRS and the U.S. Department of Transportation have had their Web sites hacked recently, according to O'Brien.

The typical end goal for these attacks has been to establish armies of zombie computers that can be used in subsequent attacks.

More Than Just a Prank

Over the July 4 weekend, for example, a large malware campaign circulated using e-greeting cards.

"You clicked on the card and were redirected to the Web site that contained the malicious code," O'Brien said.

Last week, the cyberspace community saw the first fruits of that campaign: the largest spam cycle to date, according to O'Brien.

The attack helped further a pump-and-dump stock scheme that Sophos called one of the largest to date.


Print Version E-Mail Article Reprints More by Erika Morphy


Related News Alerts

Sophos Activate Alert | Search Archives

More by Erika Morphy

Windows 7 Flies Off the Shelves
November 06, 2009
Early sales figures on Windows 7 boxed software suggest a high level of consumer enthusiasm for the OS. Unit sales were a whopping 234 percent higher than Vista's out of the gate. The revenue haul was not as impressive, as Microsoft offered sharp discounts to spur presales. Also, sales of PCs with Windows 7 preinstalled have been lackluster -- but October is historically a weak month for PC sales.
Southwest Doesn't Fool Around
November 06, 2009
Either Southwest Airlines had better deals for my favorite route than its competitors or its superior Web site tools made it easier for me to ferret them out. Either way, kudos to Southwest. In the not-so-hot department were the airline's long list of what passengers weren't allowed to do and its very short list of what Southwest was obliged to do for them. Left me feeling a little chilly.
Commerce Search Puts Google Inside Retailers' Catalogs
November 05, 2009
Google has launched a new cloud-based search tool targeting enterprise-level e-commerce operations, just in time for the 2009 holiday selling season. Commerce Search provides a set of features designed to improve the relevance of results for consumers searching a retailer's own product catalog, while boosting cross-selling opportunities.
Don't miss a story -- sign up for our FREE e-mail newsletters and view the latest headlines at a glance.
Tech News Flash [ View Sample ]
E-Commerce Minute [ View Sample ]
ECT News Network Weekly Newsletter [ View Sample ]
Shortcuts
ECT News Network Information
Reader Services
Corporate
ECT News Network