English

Hello 

Create Profile

Creating your profile will enable you to submit photos and stories to get published on News24.


Please provide a username for your profile page:

This username must be unique, cannot be edited and will be used in the URL to your profile page across the entire 24.com network.

Settings

Location Settings

News24 allows you to edit the display of certain components based on a location. If you wish to personalise the page based on your preferences, please select a location for each component and click "Submit" in order for the changes to take affect.









Facebook Sign-In

Hi News addict,

Join the News24 Community to be involved in breaking the news.

Log in with Facebook to comment and personalise news, weather and listings.

 
 

Mass infection as hackers strike

2008-04-29 11:15
line

Johannesburg - Web developers all over the world have been scrambling to protect their sites from one of the biggest hacking attempts from one source to date, an information security expert said.

A mysterious hacker group, with an IP address registered in Shanghai, China, hacked up to 354 000 sites on Friday afternoon according to an index by Google, but the number could be a lot higher, said Deloitte security and privacy consultant, Dominic White.

Other media reports said that up to 500 000 websites were affected.

"Google can take up to a week to re-index a site, and they're doing it all the time, so the picture may look very different in a day from now," said White.

The hacking began in early April with an attack on several thousand websites using SQL injection, a technique that exploits a security vulnerability occurring in the database layer of an application.

This has resulted in those websites attempting to infect any visitors to the site with malicious software.

According to White this software, or Trojan, can pilfer credit card information as well as install spyware.

Risk of attack going unnoticed

ICT security expert Dino Covotsos, MD of Telspace, a Johannesburg-based company specialising in managed security services, confirmed the attack.

Covotsos said the attack was prominent, also in South Africa, where a lot of sites were defaced.

He said they got calls from companies saying they were affected, but some didn't even know that they were hit.

Abroad, the UK and US government sites were infected as well as several US university sites.

Anyone visiting a hacked web page will in turn have their computer infected with malicious software due to flaws in older versions of iTunes, Microsoft Windows, AIM or RealPlayer.

When the hacking began early in April several thousand sites were infected. However, it has since restarted again in earnest from a new origin point.

"This software has a very effective strategy, and targets weaknesses in several components of the user's computer," said White.

Army of infected computers

"Once infected, passwords are looked for and sent back to a central computer, additionally these machines are co-opted into an army of infected computers (called a botnet), which the controlling group can use to perform large distributed attacks."

This controlling group is entirely unknown at this stage. While the hacker's IP address is registered in China, White said this doesn't mean they are from there.

"In the last couple of days, these guys have re-grouped and launched a far more ambitious attack which has successfully infected several hundred thousand websites putting any visitors to those websites (a multiple of several hundred thousand) at risk," said White.

Some anti-virus products provide protection, and White said it is important that users update their anti-virus software daily if possible, and download the latest versions of software like iTunes and RealPlayer and apply security patches to their Windows operating system "to ensure the latest protection against rapidly evolving threats such as these, are enabled".

For now the situation seems to be under control - the one website where the malicious code was coming from was blocked, Covotsos told News24.

He added that the worm wasn't written too well because they could see where it was going and what it was doing.

However, Covotsos cautioned that another more potent worm could be unleashed in a few weeks time and that companies should secure their code and fix their servers.

Read News24’s Comments Policy

inside news24

 

140
1
1 of 10

Latest comment in Sci-Tech

tshiamo.stevens says... American men continue to fall victim to Russian and Nigerian Online Romance scammers posing as stranded beautiful American women wanting to come "home" after losing all their possessions. They send money through western union to assist their "fiancees". Just goes to show what happens when you think with the dead down there not the one above your shoulders! Read the article...

 
Traffic
Lottery
 
  • Wednesday Ladysmith - 22:09 PM
    Road name: N11 Both Ways
    ROADWORK - two sets of stop / go controls just south of the R68 Dundee exit - expect waiting times of up to 20 minutes between Ladysmith and Newcastle (ends March 2013)
  • Saturday Pretoria - 08:07 AM
    Road name: N1 Both Ways
    ROADWORKS - lane closures on both carriageways for long term roadworks between the N4 Witbank Highway Interchange and the Zambesi Drive exit - EXPECT DELAYS (until Jan 2013)
 
More traffic reports...
 

Jobs [change area]

Cars[change area]

MERCEDES

C200 K Classic MY00
2002
R 138,600.00

VOLKSWAGEN

CitiGolf 1.4i 5-dr MY04
2007
R 72,995.00

MAZDA

BT-50 2.5 TDi SLX Freestyle Cab 4x4 Dsl PU MY08
2011
R 259,900.00

Property [change area]

Vulintaba Country Estate, Upper Drakensberg

A lifestyle estate beyond compare. Home Package Options From R990 000

Travel - Look, Book, Go!

Casa Rex, Vilanculos

Spend 5 nights in at the magical Mozambican resort of Casa Rex from R7983 per person sharing. Includes accommodation, return flights, taxes and transfers. Book now!

Kalahari.com - shop online today

Legos

Let your child construct his own fun with only his imagination limiting his creations. Buy now.

iPad

Update the way you socialize, work and play with the latest iPad models. Buy now.

Max Payne 3

Seeking Redemption from the past, Max hopes to enter his last fight and finally put his demons to rest. Buy now.

Sins of the Father

Foul play in New York City sets the tone. Boundaries pushed, Loyalties tested and secrets unravelled in Jeffrey Archer’s, Sins of the Father. Buy now.

Nikon Camera Range

Capture and preserve your life’s precious memories with the Nikon Camera Range. Buy now.

OLX Free Classifieds [change area]

pool table

For Sale, Toys - Games - Hobbies in South Africa, Gauteng, Johannesburg. Date May 6

Lexus: IS

Vehicles, Cars in South Africa, Gauteng, Johannesburg. Date May 7

stylish bachelor furnished in sandton from 1st of june

Real Estate, Houses - Apartments for Rent in South Africa, Gauteng, Johannesburg. Date May 7

BlackBerry Curve 9360

The BlackBerry Curve 9360 smartphone comes preloaded with Blackberry OS7...

From R2599.00

I'm shopping for:

Horoscopes
Aquarius
Aquarius

You’re friendly by nature and you don’t really have to go too out of your way to befriend the people you work with. Just be your...read more

There are new stories on the homepage. Click here to see them.