Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security

May 4th, 2010, 14:29 GMT · By

Department of the Treasury Website Rigged to Exploit Visitors

SHARE:

Adjust text size:


Bureau of Engraving and Printing website compromised
Enlarge picture
The website of the U.S. Department of Treasury Bureau of Engraving and Printing (BEP) was compromised by unknown attackers, who rigged it to infect visitors with malware. A malicious IFrame loading exploits from a third-party domain was injected into the index page.

The hack was discovered sometime on Sunday evening, but the affected website remained accessible for most of yesterday. While it was still online, the website could have been reached via three separate URLs: bep.treas.gov, bep.gov and moneyfactory.gov.

AVG was one of the first security vendors to report the compromise, through the voice of its Chief Research Officer, Roger Thompson, who revealed that a malicious IFrame was injected into the government website. "This iframe is used to silently load one of the elenore exploit kits main URL’s, which in turn determines what’s the best available exploitation method for the browser accessing the site," security researchers from Panda Security, who also analyzed the attack, explain.

Malicious IFrame injected into Bureau of Engraving and Printing website
Enlarge picture
Users are taken through a series of redirects, which determine if vulnerable software is installed on their computers. The exploit pack is able to target vulnerability in popular applications such as Adobe Reader or Java Runtime Environment.

If exploitation is successful, websites displaying fake security scans are repeatedly opened in the browser to trick users into downloading and installing scareware. This is a generic name given to applications that masquerade as antivirus programs and try to scare people into paying a license fee by making false claims about alleged infections on their computers.

Panda analysts speculate that hackers used a common attack technique known as SQL injection, to compromise the U.S. Treasury website. However, other experts think the incident is related to the recent mass compromise at Network Solutions, where the website is hosted. This possibility is enforced by the use of the malicious grepad.com domain in both attacks.

TELL US WHAT YOU THINK:

2,277 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Websites Hosted at Network Solutions Targeted in Mass Injection Attack

WordPress Design Flaw Blamed for Recent Mass Blog Compromise

Dirty Attack Cripples Hundreds of WordPress Blogs

Hundreds of Websites Hosted at Network Solutions Defaced

Over One Hundred Thousand Websites Infected in New Attack

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM