TIO website hit by malware

Feb 8, 2010 5:36 PM
Tags: tio | malware | websense | vulnerability

Weekend malware runs one new process per target machine.

The website of the Telecommunications Industry Ombudsman (TIO) has suffered a malware attack that caused it to be taken offline today.

The site was blocked for Google users this afternoon, with the search engine listing it as suspicious since Friday.

According to Google's diagnostic page, three pages on tio.com.au were infected, and successful infection resulted in an average of one new process on the target machine.

John DuBois, who is the TIO's Communications Manager, confirmed that the site was infected.

"There was some sort of foreign intrusion into the site," he told iTnews.

"We're still investigating the source of the issue; we took the site down for a little while and made sure that it was all clean."

However, a brief investigation by web security vendor Websense revealed that the site was still infected as of 5pm today.

According to Websense's Q3-Q4 2009 State of Internet Security report, 71 percent of Web sites with malicious code that were discovered during those six months were revealed to be legitimate sites that had been compromised.

"This is quite typical of cases where sites with legitimate purposes have been compromised by malicious code," Websense's ANZ marketing manager, David Brophy, told iTnews.

"It's a well-known site; it gets a lot of traffic," he said of the TIO Web site. "It [malicious code] only has to be up there for a couple of hours to potentially infect a lot of people."


  • Email a Friend
  • Print Page
TIO website hit by malware
"See what happens when your web editors visit pron sites from a browser located on the web server!"
By gonny
 
 
Comments: 3
Thoughts on this article? Add a comment below.
Daveh
Feb 8, 2010 5:46 PM
Quick. Tell Conroy, he needs to update the blacklist
SvenV
Feb 8, 2010 6:43 PM
When contacted about the issue, the TIO replied:
"There is nothing wrong with our website, it's fine."

And later:
"I'm not a computer expert, but our site is fine. It sounds like a problem with your computer. You should get an expert to take a look at it and find out what the problem is."

http://magicunlimited.typepad.com/magic_unlimited_with_elli/2010/02/with-friends-like-these.html
gonny
Feb 9, 2010 11:13 AM
See what happens when your web editors visit pron sites from a browser located on the web server!
Comment:
Want to participate in the discussion?
Or log in now to comment
 
 
 
Top Stories
Oracle shuts down open source test servers
Playing nice with the open source community, Larry?
 
Google hosts election debate
Lundy, Fletcher and Ludlam face off on tech policies.
 
Telstra fined $18.5m for exchange access
Kept competitive DSLAM kit out.
 

Latest VideosSee all videos »

Latest Comments
"Now Julia, if only you would promise not to filter the internet in your next term of government ..."
by hsvandrew Jul 31, 2010 9:33 AM
 
"@Nate - my fears are that if we use a national consortium as an interface to international ..."
by heavenlyhaloes Jul 31, 2010 12:41 AM
 
"Did anybody notice that on Apple's website the iPhone is missing the AT&T logo on the top bar? ..."
by brownenicola Jul 30, 2010 10:18 PM
 
"@digger11 - when will you learn just to remain quiet when you don't have all the facts or a ..."
by Bazwalt Jul 30, 2010 7:13 PM
 
"Wakie is right, Digger11 is either an exceptional forum troll or a massive moron. For those who ..."
by Bazwalt Jul 30, 2010 6:51 PM
Polls
Did Google breach the Telecommunications Interception or Privacy Acts during its WiFi wardrive?

   |   View results
Yes. There is no excuse for collecting this data.
  28%
 
No. If your wireless network is unsecured, you have no right to complain
  72%
TOTAL VOTES: 1873

Vote