Skip the navigation

Hackers target French ISP's site

It tried to install malicious software on visitors' computers

By Peter Sayer and Paul Roberts
August 26, 2004 12:00 PM ET

IDG News Service - A hacker compromised the corporate Web site of France Telecom SA's Internet service provider subsidiary, Wanadoo, on Monday, causing the site to try to install a malicious software program on visitors' computers, the company said yesterday.
The site, www.wanadoo.com, had been altered to use two common software exploits that redirect visitors' Web browsers from Wanadoo.com to Web sites that attempted to download a Trojan horse program onto their computers. The attacks are just the latest example of malicious hackers compromising prominent Web pages and using them to distribute malicious code to unsuspecting users.
"Someone succeeded in breaking into the site and altering a page," Wanadoo spokeswoman Caroline Ponsi said yesterday. The attack happened Monday night, she said, and occurred despite the fact that "all our software is up to date."
"We're in the process of checking everything before starting it up again," she said. "We have an idea how he got in."
Wanadoo has identified the network from which the attack originated, and has made a complaint to the ISP concerned, she said.
The Wanadoo site was taken down at about 5:30 p.m. Central European time Tuesday, redirecting visitors to a notice that a technical problem had occurred.
During the attack, Wanadoo.com distributed copies of two common exploits, Exploit-ByteVerify and MHTML URL. At least one of the files, MHTML URL, was also used in the June attacks that used compromised Internet Information Services Web servers to distribute malicious code, said Craig Schmugar, virus research manager at McAfee Inc.'s Antivirus Emergency Response Team Labs.
If the attack successfully exploited the software holes, users unknowingly accessed a Web site that copied a Trojan horse program called loaderfox onto their computers.
Microsoft Corp. issued software patches for the holes compromised by both exploit programs, Schmugar said. McAfee's antivirus software spotted the files pushed out by Wanadoo.com.
The Wanadoo site, which usually provides background information on the company's strategy and structure, was still not operating today, although the redirection was changed to point toward the site for Wanadoo's French subscribers.
The Wanadoo hack is the latest in a string of such incidents in recent months.
In June, a Russian hacking group known as the hangUP team used a recently patched buffer overflow vulnerability in Microsoft's implementation of Secure Sockets Layer to compromise vulnerable Windows 2000 systems running IIS Version 5 Web servers. The June attacks also used two vulnerabilities in Windows and the Internet Explorer Web browser to silently run a malicious computer code called Scob or Download.ject. from the IIS servers on machinesthat visited the compromised sites, redirecting the customers to Web sites controlled by the hackers and downloading a Trojan horse program that captures keystrokes and personal data.
Last week, researchers at PivX Solutions Inc. in Newport Beach, Calif., intercepted malicious code that closely resembled Scob. The new attacks used mass-distributed instant messages to lure Internet users to Web sites that distribute malicious code similar to Download.ject, said Thor Larholm, senior security researcher at PivX.

Reprinted with permission from IDG.net. Story copyright 2010 International Data Group. All rights reserved.
Additional Resources
Forrester Consulting - Optimizing Users and Applications in a Mobile World
WHITE PAPER
Solving application issues over the WAN requires careful consideration. Based on their independent research, Forrester Consulting offers recommendations on how to tackle application performance issues, insufficient bandwidth and the inability to quickly restore users in a disaster.

Read now.

Security KnowledgeVault
WHITE PAPER
Security is not an option. This KnowledgeVault Series offers professional advice how to be proactive in the fight against cybercrimes and multi-layered security threats; how to adopt a holistic approach to protecting and managing data; and how to hire a qualified security assessor. Make security your Number 1 priority.

Read now.

Cut Communications Costs Once and for All
WHITE PAPER
New IP-based communications systems are being deployed by small and midsized businesses at a rapid rate. Learn how these organizations are enabling faster responsiveness, creating better customer experiences, speeding office or mobile interactions, and dramatically reducing existing communications costs.

Read now.

Cybercrime and Hacking White Papers
Streamline Compliance and Increase ROI
Streamline, simplify, and automate compliance related activities; especially those that impact multiple business units. This white paper from NetIQ, outlines solutions that will...
Protecting Point of Sale Systems from Targeted Attack
If you are responsible for protecting retail systems, download this case study to learn how this retailer eliminated the threat of malware on...
From the Frontline - Preventing APT
Is your company's network secure? Are your endpoints and servers secured? Before you answer, read this case study on a US Military Command...
Stop Hackers Before They Attack
Hacktivism, Identify Theft, Financial Gain, Cyber War - regardless of motivation, stopping today's hackers requires a new proactive approach to protecting endpoints. Learn...
The four rules of complete web protection
As an IT manager you've always known the web is a dangerous place. But with infections growing and the demands on your time...
All Cybercrime and Hacking White Papers
Cybercrime and Hacking Webcasts
WikiLeaks: How am I Affected?
The latest WikiLeaks episode has raised questions about how organizations and governments protect their sensitive information. While this incident was isolated, it has...
Optimizing Networks for the Cloud
Join guest speaker, Rohit Mehra, IDC Director of Enterprise Communications Infrastructure, to explore current trends, discuss best practices for optimizing Data Center and...
Apps QuickStart Series Part 2: Designing and Deploying SQL Server on VMware vSphere
Download this webcast to learn about the design considerations for virtualizing SQL workloads, performance and scalability information and high-availability options, as well as...
Apps QuickStart Series Part 1: Designing and Deploying Exchange 2010 on VMware vSphere
Download this webcast to learn the virtual hardware design considerations for Exchange 2010, deployment using the building block approach, options for high-availability and...
Customer Spotlight: How IPC The Hospitalist Company Implemented Oracle on VMware
Have you been looking to hear about customer's experiences with the new VMware vCenter Site Recovery Manager product? View this webcast to learn...
All Cybercrime and Hacking Webcasts
Newsletter Sign-Up

Receive the latest news test, reviews and trends on your favorite technology topics

Choose a newsletter
  1. View all newsletters | Privacy Policy
IT Jobs