As a consumer and a taxpayer, it's assumed that government websites are the most secure in the nation. After all, if hackers can gain access and plant malware for viewers to download, then the nation really isn't that all secure on the cyber frontier, right? Unfortunately, that's apparently what has happened to three websites belonging to the U.S. Department of the Treasury. How safe and secure do you feel now?
Roger Thompson of AVG discovered the infestation on Monday. The urls involved include bep.gov (Bureau of Engraving and Printing), bep.treas.gov, and moneyfactory.gov. All three sites were "script injected" with a line of code that linked back to a now-dead grepad.com. At first Thompson thought the government admins had resolved the issue, however later Monday evening he discovered that the sites still remain infected, and warned web surfers to steer clear until until the issue is resolved.
By Tuesday morning, the websites administrators had taken the three websites offline.
PC World adds to the report after contacting Thompson directly. The injected iframe HTML code redirected visitors to the grepad.com website located in the Ukraine. Naturally this website was loaded down with malware, specifically a commercially available attack-kit called the Eleonore Exploit pack. Previous attacks on other websites by grepad.com have been known to infiltrate viewers through PDFs and other software bugs.
It may be possible that the attack on the U.S. Department of the Treasury stems from the introduction of the newly redesigned $100 bill, a retaliation against the governments attempts to thwart money launderers.
May 5, 2010
U.S. Treasury Sites Hacked
Labels:
OTHERS
Bookmark this post:blogger tutorials
Social Bookmarking Blogger Widget |
Subscribe to:
Post Comments (Atom)
No comments:
Post a Comment