TIO website hit by malware

 

Weekend malware runs one new process per target machine.

The website of the Telecommunications Industry Ombudsman (TIO) has suffered a malware attack that caused it to be taken offline today.

The site was blocked for Google users this afternoon, with the search engine listing it as suspicious since Friday.

According to Google's diagnostic page, three pages on tio.com.au were infected, and successful infection resulted in an average of one new process on the target machine.

John DuBois, who is the TIO's Communications Manager, confirmed that the site was infected.

"There was some sort of foreign intrusion into the site," he told iTnews.

"We're still investigating the source of the issue; we took the site down for a little while and made sure that it was all clean."

However, a brief investigation by web security vendor Websense revealed that the site was still infected as of 5pm today.

According to Websense's Q3-Q4 2009 State of Internet Security report, 71 percent of Web sites with malicious code that were discovered during those six months were revealed to be legitimate sites that had been compromised.

"This is quite typical of cases where sites with legitimate purposes have been compromised by malicious code," Websense's ANZ marketing manager, David Brophy, told iTnews.

"It's a well-known site; it gets a lot of traffic," he said of the TIO Web site. "It [malicious code] only has to be up there for a couple of hours to potentially infect a lot of people."


TIO website hit by malware
"See what happens when your web editors visit pron sites from a browser located on the web server!"
By gonny
 
 
 
Comments: 3
Daveh
Feb 8, 2010 5:46 PM
Quick. Tell Conroy, he needs to update the blacklist
SvenV
Feb 8, 2010 6:43 PM
When contacted about the issue, the TIO replied:
"There is nothing wrong with our website, it's fine."

And later:
"I'm not a computer expert, but our site is fine. It sounds like a problem with your computer. You should get an expert to take a look at it and find out what the problem is."

http://magicunlimited.typepad.com/magic_unlimited_with_elli/2010/02/with-friends-like-these.html
gonny
Feb 9, 2010 11:13 AM
See what happens when your web editors visit pron sites from a browser located on the web server!
Comments have been disabled for this article.
 
 
 
Top Stories
iTnews on tour: The Executive Summit Series
Join us in Sydney and Melbourne to meet Australia's tech leaders.
 
NBN Co braces for secrecy probe
Opinion: Is commercial sensitivity a catch-all?
 
Exclusive: NBN Co withholds fibre upgrade price
Fears trial details could breach contractor confidentiality.
 
Sign up to receive iTnews email bulletins
   FOLLOW US...

Latest VideosSee all videos »

Latest Comments
Polls
Was your 2012 IT budget...




   |   View results
Cut by less than ten percent?
  17%
 
Cut by more than ten percent?
  34%
 
Flat
  26%
 
Increased by less than ten percent?
  7%
 
Increased by more than ten percent?
  15%
TOTAL VOTES: 350

Vote
Will you still use DropBox and other cloud storage in the wake of the Megauploads saga?

   |   View results
Yes
  63%
 
No
  37%
TOTAL VOTES: 230

Vote