The Register® — Biting the hand that feeds IT

Feeds

California gov site invaded by smut and malware again

Feels like the first time

Regcast training : Hyper-V 3.0, VM high availability and disaster recovery

Raising troubling questions about the security of America's government websites, more domains ending in .gov have been found hosting links that push porn and malware.

They include the Marin County Transportation Authority, which has has watched its site get hacked at least twice before. In early October the domain forced the shutdown of all California government websites until admins could remove the links. A week after the sites were disinfected, the rogue pointers returned.

On Friday, more than 24 hours after this post from Sunbelt Software first reported the reemergence of the links, the gov site was riddled with at least a dozen pages that, when clicked, redirected users to smut sites. Users then got a messaging saying they had to install a special codec in order to view the content. The codecs contain Trojans that install malware.

By Friday evening in California, the tainted pages were finally removed, and the executive director of the agency apologized for the problem.

The other site actively pushing smut and malware at the time of writing was USAid, a federally operated agency that extends aid to countries recovering from disasters. Perhaps they should attend to their own affairs first.

Over the past several months, the poisoning of search caches belonging to Google and other search engines has emerged as a chief tactic by miscreants in inflating rankings of their malicious websites. At the moment, Google security pros are scrambling to eradicate a flood of malicious links. Problem is, the purveyors of smut and malware are quickly able to taint the cache with a new batch of domains. The whack-a-mole battle finally prompted Google to issue this request for help from its users.

The infections of the gov sites, which are easily documented by these two Google searches (safe to click if you don't mind "porn" in your url, but you probably shouldn't click on any of search results), appear to be yet another attempt to boost the rankings of the malicious sites.

Dianne Steinhauser, executive director of the Marin County Transportation Authority, said she thought the problem was fixed in mid September, after her agency dumped its old web host, StartLogic, and contracted with a new one.

"Even though we quit any web hosting with them, they had a publicly accessible web page with our name on it," she told The Register. "They still had a web service under our name, and that was a complete surprise."

Hackers were able to create the porn- and malware-infested pages by infiltrating StartLogic's system, she said. The pages became inaccessible after her office directed the web host to remove the web-accessible service, she said.

"I am exceptionally apologetic for anyone that was contaminated by virtue of our name," she said.

Attempts to reach representatives of StartLogic and USAid were not successful. ®

Agentless Backup is Not a Myth

Latest Comments

The obvious response

When a Government site (any Government, not just the US) is hijacked in this manner, the obvious - and appropriate, and measured - response is to launch a major, deliberate denial of service attack on the site(s) in the link(s). Governments have the power (and the legal right - I won't talk about ethics nor morals, since no Government has ever had more than a nodding acquaintance with either of those) to defend themselves against attack, and this is certainly an attack.

Furthermore, if the Government in question wants to permanently discourage such attacks, competent IT security blokes (and/or blokesses) should be immediately put on the trail of the ultimate beneficiaries of the hijackings, and once located, their assets and persons seized. Let's put Gitmo to some "good" use for once!

But that will never happen, because, as is all too obvious, competent IT people avoid Government jobs like chavs avoid work.

0
0

Gov't and IT. The fun never ends

@Paul Murray.

Surely you are not suggesting that the same public bureaucracies that brought us the California Dept. of Motor Vehicles computer upgrade fiasco in the early 1990s be responsible for hosting their own websites. These idiots spent more than US$44 million on a system that was never built and would have been obsolete before it was finished. (San Francisco Chronicle, February 2, 1997)

We can't afford that sort of efficiency in our Gov't IT departments.

0
0

Outsourcing

Time to stop outsourcing key government functionality - and these days, having a public website is key. Plunk down some cash for a couple of machines, cluster them and run them in-house. Kick those damn web hosting companies - bloody extortion what they are after to simply host a domain name.

0
0

More from The Register

 breaking news
Number of cops abusing Police National Computer access on the rise
Only a telegram from the Queen can get you off it
 breaking news
NSA PRISM snoop-gate: Won't someone think of the children, wails Apple
10,000 things probed, mostly about missing kids, Alzheimer patients, we're told
Flash flaw potentially makes every webcam or laptop a PEEPHOLE
But it's a Google problem - Chrome only, insists Adobe
Internet fraud still stings suckers
Australians twice as gullible as Americans
 breaking news
NSA PRISM-gate: Relax, GCHQ spooks 'keep us safe', says Cameron
Whatever they are up to, it's all above board, we're told
 breaking news
Yahoo! joins! rivals! in! PRISM! data! request! admission!
Keep calm and carry on using American tech firms, folks
PRISM snitch claims NSA hacked Chinese targets since 2009
Snowden suddenly looks safer in Hong Kong after revelations
 breaking news
US chief spook: Look, we only want to spy on 6.66 BEELLLION of you
Americans assured they are not in the NSA's sights
Speech-to-text drives motorists to distraction
Will talking to you mean I crash into that car up ahead, Siri?
DHS warns of vulns in hospital medical equipment
Has your doctor's anasthesia machine been hacked?