Cryptome Hit By Blackhole Exploit Kit 49
wiredmikey writes with an excerpt from Security Week:"Whistleblower site Cryptome has been hacked and infected by the Blackhole exploit kit. ... Cryptome co-founder John Young however told SecurityWeek that the Cryptome site is in the process of cleaning everything up, and that process should be finished by the end of the day. Founded in 1996, Cryptome publishes thousands of documents, including many related to national security, law enforcement and military. On Feb. 12, a reader advised the site that accessing a file had triggered a warning in their antivirus about the Blackhole exploit kit. ... Subsequent analysis found thousands of files on the site had been infected."
Cryptome has certainly seen worse.
frosty day in hell when (Score:1)
security whistleblowers get hacked? neverrrrrrrrrrrrrrrrrrrrrr
Don't criticize, do it ! (Score:3, Insightful)
If you can set up a public website so secure that no hacker can ever hack, why don't you set one up?
Instead of criticize, why don't you show the world that such a site is indeed possible?
Maybe you can even make a buck or two out of it
Re:Don't criticize, do it ! (Score:4, Informative)
If you can set up a public website so secure that no hacker can ever hack, why don't you set one up?
Formally verified web servers [nist.gov] have been around for a while.
Re:Don't criticize, do it ! (Score:4, Insightful)
"Formally verified web servers have been around for a while."
This reminds me of Knuth's famous quote about some code he released:
"Beware of bugs in the above code; I have only proved it correct, not tried it."
Re: (Score:1)
The fact you posed this, and even worse, it was moderated up, is just mind blowing. It wonderfully validates just how completely clueless and out of touch with reality so many people, such as yourself, really are.
The only secure computer is one powered off, locked in a vault. And even then, its only as secure as the one who holds the key.
Formally verified web servers are for CYA and provide only a minimal diference, if any, in the real world.
We at slashdot are all dumber now for having read your post.
The mysterious command (Score:5, Informative)
< SCRIPT src="/0002/afg/afg.php" >
I'm sure you all will sleep now that your burning curiosity was satisfied.
Re: (Score:1, Troll)
Perhaps, just perhaps, Cryptome is infecting its visitors on purpose. You dont publish "thousands of documents, including many related to national security, law enforcement and military" without breaking a few eggs.
Now that the common rabbles antivirus software has caught up, they are in the process of "cleaning up" the code so it wont happen again for a bit... watch this space.
Blackhole (Score:4, Funny)
Symantec says that Blackhole affects "various Windows platforms". Does Cryptome run on Windows?
Re:Blackhole (Score:5, Informative)
Symantec says that Blackhole affects "various Windows platforms". Does Cryptome run on Windows?
Whether or not cryptome runs in windows is not for me to say, however I do believe that cryptome was compromised and made to distribute the blackhole exploit. The following is found on TFA:
Although I'm not a full fledged security researcher, I could shed some light on the script that you found on your server. The basic program flow goes like this when a client loads the script (in your case every time anyone visits one of your pages):
After step 5 probably the browser is under attack and it will probably be a successful attack since the attackers knows the client to be a windows machine running an internet explorer browser, my guess would be that the client is now infected and part of a botnet to be used in other attacks. The IP address of the attacker is a webserver for the domain http://absolutely-free-meeting.com/ [absolutely...eeting.com] I'm not sure they have anything to do with this attack, probably they are a comprimised server like your webserver was compromised. The WHOIS information for this domain is registered by godady and I include their data and the registrants data below, it would be best to contact both so that they can clean up their server also. Conclusion:
PS: I tried to format that as best I could but slashdot was having none of it
Re: (Score:2, Insightful)
Re: (Score:1)
Re: (Score:1)
Or they've outsourced that bit to somewhere else?
mysterious (Score:5, Funny)
The secret command shows up as a dot (".") on my system.
This may not be enlightening to anyone, but it appears to be a small black hole.
Re: (Score:3)
It's just evidence of the LHC working properly.
Re: (Score:2)
You should have warned him not to lean too close to his screen or he could potentially be sucked in and crushed by the immense gravitational forces known in exist in certain configurations of punctuation
Most Slashdotters are aware of the risk and that is why we so often see the more cautious ones omitting any meaningful punctuation
With any luck the LHC will continue past its triumph in explaining the observed asymmetry between grammar and punctuation Nazis to helping us understand the Higgs and the asymmetr
Re: (Score:2)
Also be careful, if the punctuation begins to glow, its reaching the end of its life and is about to evaporate in rather impressive gamma ray burst. The upside, is you can use the burst to sterilize food for long term storage or eliminate unpleasant neighbors.
Re: (Score:2)
even more careful slashdotters avoid the use of capital letters as the increase in mass from the extra black can cause the danger zone to increase in size a great deal
Re:mysterious (Score:5, Funny)
I clicked on the link and I couldn't see anything.
Since then I've been slowly depressing my back button for what seems like years... to you.
I've been infected too. (Score:1)
Almost every single sentence on my system ends in one of those ".". Including this one. Oh my god...
Don't worry (Score:2)
The blackhole may suck up all your whistleblow data, but no one can retrieve it from there.
Re: (Score:2, Interesting)
Not true. Black holes emit radiation in the form of Hawking Radiation. Because of the laws of physics, this radiation carries information about what went into the hole. Wikipedia's description is decent. http://en.wikipedia.org/wiki/Black_hole_information_paradox [wikipedia.org]
"Blackhole WINDOWS Exploit Kit". (Score:5, Informative)
Yes, it matters.
"Blackhole IE Exploit Kit" (Score:5, Informative)
This attacks specifically checks for, and excludes browsers which are not IE 6 to 8
Re: (Score:2)
Blackhole expliot kit?? (Score:1)
Doc this is heavy!
Hmm (Score:2)
The thing that bothers em most about this is that it was an end users anti-virus that detected it rather than software protecting the servers.
Re: (Score:2)
Re: (Score:1)
Not sure what you're saying, in general I expect a server to have better protection than a client.
Re: (Score:2)
See how the protection offered expands from a basic to premium services.
Your host might offer https, static, databases, web 2.0 look/feel, unlimited data but extra security may be an 'extra'.
Re: (Score:2)
Re: (Score:1)
That's another odd statement, I think the previous guy was trying to sell me something and you seem to be stating the obvious, I would not expect a compromised system to detect an issue (which is what I think you meant) the idea is to keep it from being compromised in the first place.
Re: (Score:2)
Doesn't say so in TFA (Score:2, Informative)
But the infection started on the 8th of February.
Revenge? (Score:2)
I have to wonder if this might be some sort of revenge attack due to the feud that has developed between Wikileaks and Cryptome?
Re: (Score:2)
I don't think there's really a feud, just that Cryptome got pissy that this new little upstart Wikileaks came and stole all it's glory with leaks that made Cryptome's past leaks look pretty small fry.
Really, Cryptome showed a bit of penis envy, but that was about it.
Re: (Score:1)
Analysis (Score:1)
Anyone wanna take a second look?
I'm not that great of a PHP coder, but maybe a second, third, nth pair of eyes could help figure it all out.
BTW, they called me A6.