Ongoing drive-by download campaign hijacked MIT server
- 04 November, 2011 00:25
- Comments
A server belonging to the Massachusetts Institute of Technology was commandeered by hackers who used it to launch attacks against other websites as part of a larger drive-by download campaign, according to antivirus vendor BitDefender.
"One MIT server (CSH-2.MIT.EDU) hosts a malicious script actively used by cyber-crooks to scan the web for vulnerable websites," the BitDefender researchers who spotted the attack said in a blog.
The rogue script hosted on the MIT server searched for vulnerable installations of phpMyAdmin, a popular Web-based database administration tool.
When the script finds a server with phpMyAdmin version 2.5.6 through 2.8.2, it exploits a vulnerability in the application and injects malicious code into the underlying databases.
This attack campaign started in June and resulted in over 100,000 compromised websites so far, said BitDefender spokeswoman Loredana Botezatu.
The company's researchers believe that the attacks are related to the Blackhole Exploit Pack, one of the most popular drive-by download toolkits currently used by cybercriminals.
Users visiting websites compromised in this campaign will be redirected to exploits for vulnerabilities in Java and other browser plug-ins, which try to install malware on their computers.
BitDefender said that it tried to alert MIT about the security breach on their server, but received no reply. The institution did not answer requests for comment sent by IDG.
As far as the BitDefender researchers could tell, the server is still online, but no longer attacking websites. Hackers prefer to abuse servers from large organizations because requests sent from them are more likely to pass network filters, according to the researchers.
The fact that these servers have considerable resources and bandwidth at their disposal is also appealing to cybercriminals and could cause problems for less powerful systems that find themselves attacked. The denial-of-service effect on the smaller systems can be easily mitigated by filtering traffic from the offending IP addresses. However, most of the time hackers don't care if that happens because they use a hit-and-run approach.
"Even if they are likely to be spotted and terminated, by the time the infected server is taken offline, it has yielded more victims than a regular bot-infected PC," the BitDefender spokeswoman said.
Webmasters are advised to remove old applications from their servers or keep them updated even if they are only rarely used. They should also review the server logs regularly for unusual requests that could be an indication of an attack in progress.
Drive-by downloads toolkits like Blackhole continue to be popular with cybercriminals because a large number of users do a poor job of keeping their operating systems, browsers and other Internet-facing software up to date.
Join the CIO Australia group on LinkedIn. The group is open to CIOs, IT Directors, COOs, CTOs and senior IT managers.
- Bookmark this page
- Share this article
- Got more on this story? Email CIO
- Follow CIO on twitter
- Setting a strategy for secure mobile printing
- Closing the print security gap - The market landscape for print security
- 10 Mobile Security Requirements for the Bring Your Own Device (BYOD) Enterprise
- Information Security Policies, Standards and Procedure
- Risk management: ensuring the security of your hosted information
-
Apple aims iPads at High Schools
-
Face Time - Interview with John Brennan and Robert DiStefano
-
Google Jumps Into Social Bookmarks Game
-
NBN build gaining momentum daily: Quigley
-
Face Time - Interview with John Brennan and Robert DiStefano
-
Unified Monitoring™ A Business Perspective
The enterprise computing landscape has changed dramatically. Virtualisation, outsourcing, SaaS, and cloud computing are creating fundamental changes, and ushering in an era in which enterprises distribute increasingly critical IT assets and applications across multiple service providers.This paper explores today’s computing trends and their monitoring implications in detail. In addition, it reveals how a new monitoring paradigm architecture, that uniquely addresses the monitoring realities of today’s and tomorrow’s enterprises—whether they rely on internal platforms, external service providers, or a combination of both. -
Process-Driven Master Data Management for Dummies
We wrote this book to introduce you to the subject of processdriven MDM. It’s a big topic, one that far outstrips the ability of a brief book to cover. However, our hope is that by reading this book you will gain a fundamental understanding of processdriven MDM, how it works, and what it takes to make it a success in your organisation. -
Avaya Deploys the Avaya Desktop Video Device with the Avaya Flare® Experience
A revolutionary new video collaboration device, the Avaya Desktop Video Device has been making waves in the communications industry ever since Avaya introduced the product in the fall of 2010. Avaya’s own employees have been among the earliest users and have seen first-hand how the product can improve collaboration and make people more efficient and effective. Read more.
-
Ubuntu Linux Bible (Version 9.10 and 10.04) Third Edition
-
Professional XML Development with Apache Tools
-
Oh My Modula 2 PPR *Not Sold Separately
-
Mission-critical Security Planner
-
VBscript Programmer's Reference, Second Edition
-
Database Development for Dummies
-
Computing Concepts with C++ Essentials 3E
-
Embedded System Design
-
QuickBooks 2007 All-In-One Desk Reference for Dummies








Comments
Post new comment