On BNET: 10 ways to manage your geeks
BNET Business Network:
BNET
TechRepublic
ZDNet

By Joris Evers
Posted on ZDNet News: Feb 2, 2007 7:59:00 PM

Cybercrooks broke in to the Dolphin Stadium Web site and rigged it to load malicious software onto unpatched Windows PCs, security experts warned Friday.

Hackers reprogrammed the Web site for the Super Bowl stadium so it would automatically load a malicious script, Web security firm Websense said. This script would attempt to exploit a pair of known Windows security holes and install programs that would put the PC under the attacker's control.

Hacked stadium site

"Assuming you're not patched, a Trojan downloader with a backdoor and a password stealer gets installed on your computer without you knowing it," said Dan Hubbard, vice president of security research at San Diego, Calif.-based Websense.

The initial breach of the Dolphin Stadium Web site appears to have occurred on January 25, Hubbard said. The site was cleaned up around 11 a.m. PST on Friday, he said.

A Dolphin Stadium representative confirmed the hack. "The stadium Web site was compromised and the problem was resolved," said the representative, who asked not to be named. She could not give an indication as to how many people were exposed to the attack, but did say the site is getting more visits "just because of the Super Bowl."

The attack exploited two known security holes in the way Windows handles Vector Markup Language, or VML, documents, Websense said. Microsoft issued patches for these flaws in September and January. This means that people who hadn't yet applied the latest Microsoft fixes would be vulnerable to the attack.

The file downloaded in the attack is a keystroke logger and a remote control tool, also called a backdoor, Websense said. Attackers get full access to the compromised PC.

"The Web is a hostile environment," said Jeremiah Grossman, chief technology officer at Web security company WhiteHat Security. "Eight out of 10 Web sites have serious flaws that enable these types of attacks. It's important for users to stay up to date with patches. However, another way to combat malicious hackers and malware is by using an alternative Web browser such as Firefox."

People who visited the Dolphin Stadium Web site with a Windows PC that lacked the most recent patches should run a security scan to clean their machines. Websense has provided details on the malicious code to antivirus software makers, so all security tools should detect it soon, Hubbard said.

"Some antivirus vendors do detect it today, but most do not. We are sharing this information with antivirus vendors to get their cleaning tools up to date," he said.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 13 Talkback(s)
Browser Crashes
How come sites like freewebs cause rowsers other than IE to crash? Is it intentional? (Read the rest)
Posted by: chrisprim Posted on: 02/06/07 You are currently: a Guest | | Terms of Use
Why do you say they were not patched?  Mikael_z | 02/05/07
I'd say you figure wrong  boomchuck1 | 02/05/07
Even if you don't want to the security patches...  KWierso | 02/05/07
Yes, good to patch BUT...  Mikael_z | 02/05/07
it's not about which os.  Sxooter_z | 02/05/07
Common misconception  Sxooter_z | 02/05/07
Will this java security flaw affect my mac?  mikebellman | 02/05/07
Not likely  Gilbert Barnes | 02/06/07
biased statement  corticus | 02/05/07
yeah, but...  dragonmago@... | 02/05/07
Explain this to me.  trm1945 | 02/05/07
Right on  Gazok | 02/06/07
Browser Crashes  chrisprim | 02/06/07

What do you think?

advertisement
advertisement

White Papers, Webcasts, and Downloads

Smartphones

  • Last year, many businesses deferred the purchase of new laptops in favor of smartphones, and why not? Offering phone, calendar, email, IM and Web access, they’re arguably the most practical business tools. Check out the latest CNET Reviews of Blackberry devices for all the knowledge you need to make an intelligent choice.
  • From Our Sponsors
  • Press and be impressed.
  • Tap into streaming videos or view files on the go. Feel life with the powerful touch of the BlackBerry® Storm™. Learn more
advertisement
Click Here