The company's Web site was compromised with the same exploit that was recently used at the Council on Foreign Relations. According to security researcher Eric Romang, the same attack used on the Web site for the Council on Foreign Relations (CFR) was also recently used on the Web site for microturbine manufacturer Capstone Turbine Corporation.
"Capstone figures to be a valuable target, Romang said, given its position in the energy community as a producer of microturbine energy products," writes Threatpost's Michael Mimoso. "He found the same malicious html file on the Capstone site as was found residing on the CFR site."
"One interesting aspect is that capstoneturbine.com was also compromised back in September and was used to serve an exploit for a different IE vulnerability that was unpatched at the time," writes Computerworld's Lucian Constantin. "The same attackers might be behind the new IE exploit, Romang said."
Jindrich Kubec, director of threat intelligence at Avast, later wrote that he'd also noted the compromise at capstoneturbine.com in September of 2012. "I wrote to Capstone Turbine on 19th September about the Flash exploit stuff they were hosting," Kubec tweeted. "They never replied. And also not fixed."
Information Security, Ethical Hacking, website Security, Database Security, IT Audit and Compliance, Security news, Programming, Linux and Security.
Friday, 25 January 2013
Department of Homeland Security Web Site Hacked
WordPress configuration information and database login details were posted online. Hacker group NullCrew recently claimed to have breached the Department of Homeland Security's Study in the States Web site, which provides information on educational opportunities in the U.S. for international students.
"The hackers have published WordPress configuration details, along with other server information and even database login credentials," writes Softpedia's Eduard Kovacs. "They’ve also revealed the exact location of the vulnerability that has allowed them to gain access to the site."
"Considering the DHS is meant to specialize in security, [you have to] wonder why they are using what is clearly [an] exploitable older version of WordPress," Cyber War News reports.
Sophos' Paul Ducklin says this should serve as a reminder to be sure you're updated with the latest security fixes for all back-end components you use, consider running a Web Application Firewall (WAF), and perform regular penetration tests against your own Web properties. "It's not a matter of if, or even of when, you might get attacked," he writes. "If you're inviting inbound Web requests, you're already under attack!"
"The hackers have published WordPress configuration details, along with other server information and even database login credentials," writes Softpedia's Eduard Kovacs. "They’ve also revealed the exact location of the vulnerability that has allowed them to gain access to the site."
"Considering the DHS is meant to specialize in security, [you have to] wonder why they are using what is clearly [an] exploitable older version of WordPress," Cyber War News reports.
Sophos' Paul Ducklin says this should serve as a reminder to be sure you're updated with the latest security fixes for all back-end components you use, consider running a Web Application Firewall (WAF), and perform regular penetration tests against your own Web properties. "It's not a matter of if, or even of when, you might get attacked," he writes. "If you're inviting inbound Web requests, you're already under attack!"
Subscribe to:
Posts (Atom)