The Register®

Original URL: http://www.theregister.co.uk/2004/11/22/falk_bofra_statement/

Falk statement on Bofra attack

Hacked load balancer

By Falk eSolutions

Posted in Site News, 22nd November 2004 10:04 GMT

Site notice On Saturday, The Register suspended service by third party ad serving supplier, Falk, following security issues detailed here (http://www.theregister.co.uk/2004/11/21/register_adserver_attack/).

Falk fixed the problem within six hours of notification. Here is its summary of what went wrong:

Saturday, 20th November 2004 Falk eSolutions clients using AdSolution Global experienced problems with banner delivery between 6.10pm and 12.30pm GMT. This started on Saturday morning with a hacker attack on one of our load balancers. This attack made use of a weak point on this specific type of load balancer. The function of a load balancer is to evenly distribute requests to the multiple servers behind it. The system concerned was only used to handle a specific request type to our ad server and has now been investigated.

The use of a weak point in one of our load balancers led to user requests not being passed to the ad servers. Instead the user requests were answered with a 302 redirect to a compromised website. This happened with approximately every 30th request. Users visiting websites that carry banner advertising delivered by our system were periodically delivered a file from the compromised site. This file tries to execute the IE-Exploit function on the users' computer.