Jump to content

HEADS UP : Fake drug scam


Recommended Posts

Guest theeldergeek
Posted

BBC News - Fake drug scam hijacks UK college websites

 

I've already found 1 school in Kent who have been affected, Longfield Academy

 

Just do a UK search on Google for something like "cialis professional" and you'll see .sch.uk and .ac.uk addresses in some of the results, although there are in actual fact not just academic sites that have been hit.

 

I have no idea what the vulnerability is, or how it is being planted within the PHP.

Posted

PHP injection technique could be almost anything but most likely something that allows files to be written to a publicly writable folder/file

 

For anyone looking into this I highly recommend mod_security (for Apache web servers) along with Suhosin to detect and intercept most attacks. There is also a service from Atomicorp that provides updated rulesets and/or a hardened Linux distro...

Posted
Looks like it's more than college websites too. Daily Telegraph website, Isle of Wight Council Job Vacancies, Pershore High in Wilts, Purbeck school in Dorset... :(
Posted

I see BBC IT reporting is up to its usual standards. "Security firm respins story about something that's been going on for years, news at 11."

 

http://www.edugeek.net/forums/security/36990-hundreds-uk-school-government-websites-hacked-sell-viagra-pornography.html

 

If you don't keep up to date with patches on a public-facing webserver (or leave unmoderated comments turned on), you'll be pushing penis pills before you know it. This is basic, noob-level IT skills.

Guest theeldergeek
Posted (edited)
I see BBC IT reporting is up to its usual standards. "Security firm respins story about something that's been going on for years, news at 11."

 

http://www.edugeek.net/forums/security/36990-hundreds-uk-school-government-websites-hacked-sell-viagra-pornography.html

 

If you don't keep up to date with patches on a public-facing webserver (or leave unmoderated comments turned on), you'll be pushing penis pills before you know it. This is basic, noob-level IT skills.

 

Shame I can't delete my original post; pointless of me to post any info when something that is apparently 9 months out of date is remembered by someone else and plucked from the archives.

 

:getmecoat:

 

Nonetheless, here's a page that really does demonstrate the level to which this vulnerability can be exploited.

Edited by theeldergeek
Posted (edited)
Shame I can't delete my original post; pointless of me to post any info when something that is apparently 9 months out of date is remembered by someone else and plucked from the archives.

 

:getmecoat:

 

Sorry dude, I wasn't having a go at you - the BBCs habit of believing any old IT PR crap they're fed just annoys me. :)

 

In .sch.uk it's much cleaner than it was back in May/June last year. Brum was especially noticeably bad, purely because they'd slapped cms installs randomly around their infrastructure and hadn't bothered to patch (or decommission abandoned ones). This can be solved by sacking the negligent, but it's local government so it's epicly hard to get fired for incompetence.

Edited by pete
typo
Guest theeldergeek
Posted
Sorry dude, I wasn't having a go at you - the BBCs habit of believing any old IT PR crap they're fed just annoys me.

 

Oh, it's OK, I know you weren't having a go at me, I was highlighting (badly) the quality of BBC journalism, in that if something that is 9 months old can be found in a forum archive, it just goes to show how poor their resources are at getting up-to-date news.

 

I think equally worrying however, is that whilst educational establishments were clearly targeted, there are an awful lot of privately run web sites in the link I posted who (for one reason or another) won't have a clue about vulnerabilities.

 

How can someone who runs a small business website on, say, Joomla, be expected to ensure it is secure when all they do is press the "Fantastico" button and the site is installed for them?

Posted
How can someone who runs a small business website on, say, Joomla, be expected to ensure it is secure when all they do is press the "Fantastico" button and the site is installed for them?

 

Realise their strengths and weaknesses and hire a professional. I use an accountant for sorting out earnings for contract work because he's better at it than me (and he saves me money) - an accountant should hire a web designer if they want a new website.

 

They could use a host who's prepared to do it for you (and commits to an SLA for patching within $days of fix available).

 

If they want to do it themselves (assuming shared hosting), all they really have to do is rtfm and subscribe to the Joomla security mailing list. Those two things alone will put him head and shoulders above most small business owners from a security perspective.

Guest theeldergeek
Posted
Realise their strengths and weaknesses and hire a professional. I use an accountant for sorting out earnings for contract work because he's better at it than me (and he saves me money) - an accountant should hire a web designer if they want a new website.

 

They could use a host who's prepared to do it for you (and commits to an SLA for patching within $days of fix available).

 

If they want to do it themselves (assuming shared hosting), all they really have to do is rtfm and subscribe to the Joomla security mailing list. Those two things alone will put him head and shoulders above most small business owners from a security perspective.

 

Trouble is, many small businesses (and certainly private individuals who run web sites) don't have the budget for a professional to come in and do their sites, so they do it themselves, or get it done on the cheap. A website is a website is a website as far as they are concerned - security? what security?

 

How many of us fix our own cars, or do our own DIY? Why don't we get the 'pros' in?

 

Because we can do just as good a job, and aren't as aware of building regs or safety issues that the pros would perhaps be?

Posted

It may have been an old thread but it bears repeating that security is not an "as and when" deal... It needs to be looked at regularly...

 

Given up on the number of numpties who do the fantastico installs... Like placing a gun in a toddlers hands and expecting them to be safe...

Guest theeldergeek
Posted
Given up on the number of numpties who do the fantastico installs... Like placing a gun in a toddlers hands and expecting them to be safe...

 

Hmmm, not entirely sure I agree with the people using "Fantastico" and such like as being numpties in respect of the pitfalls of using such. Surely some responsibility lies with the hosting provider?

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...