Feeds

Cybercrooks plant phishing scam on crime reduction website

Home Office pwned

Protecting against web application threats using SSL

Phishing fraudsters hacked a Home Office crime reduction website to host an Italian phishing website on Monday.

An RFI (Remote file inclusion) exploit was used to launch the phished page off the webserver hosting crimereduction.homeoffice.gov.uk. As a result of the SQL Injection attack a page resembling the Poste.it site was served up so that it appeared to come from the homeoffice.gov domain. Poste.it is the website of an Italian bank and is a frequent target of phishing attacks.

Net security firm PrevX, which detected the attack, reckons phishing fraudsters used the POST method so that phished data submitted by prospective marks was sent to them. Quite why they picked a government page, much less one in the UK, to host a phishing attack remains unclear beyond possible motives of showing off or "sticking it to the man".

The Home Office pulled the rogue content from its site early on Monday morning. The attack is the latest example of cybercriminals abusing security exploits on trusted websites to serve up fraudulent content. SQL Injection attacks are a favorite attack strategy. The long-standing approach, used to hack thousands of website, including US Department of Homeland Security and UK government sites last month, has now been applied to target a Home Office-run crime reduction website.

"This is very embarrassing for the Home Office, having the Crime Reduction website hacked by cybercriminals is a bit like having a mugger hiding in the local police station nicking people's wallets when they come in," said Jacques Erasmus, head of malware research at Prevx. ®

Reducing the cost and complexity of web vulnerability management

More from The Register

next story
Spies would need SUPER POWERS to tap undersea cables
Why mess with armoured 10kV cables when land-based, and legal, snoop tools are easier?
Apple Pay is a tidy payday for Apple with 0.15% cut, sources say
Cupertino slurps 15 cents from every $100 purchase
Critical Adobe Reader and Acrobat patches FINALLY make it out
Eight vulns healed, including XSS and DoS paths
Israeli spies rebel over mass-snooping on innocent Palestinians
'Disciplinary treatment will be sharp and clear' vow spy-chiefs
YouTube, Amazon and Yahoo! caught in malvertising mess
Cisco says 'Kyle and Stan' attack is spreading through compromised ad networks
Hackers pop Brazil newspaper to root home routers
Step One: try default passwords. Step Two: Repeat Step One until success
Microsoft to patch ASP.NET mess even if you don't
We know what's good for you, because we made the mess says Redmond
NORKS ban Wi-Fi and satellite internet at embassies
Crackdown on tardy diplomatic sysadmins providing accidental unfiltered internet access
prev story

Whitepapers

Providing a secure and efficient Helpdesk
A single remote control platform for user support is be key to providing an efficient helpdesk. Retain full control over the way in which screen and keystroke data is transmitted.
WIN a very cool portable ZX Spectrum
Win a one-off portable Spectrum built by legendary hardware hacker Ben Heck
Storage capacity and performance optimization at Mizuno USA
Mizuno USA turn to Tegile storage technology to solve both their SAN and backup issues.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Security and trust: The backbone of doing business over the internet
Explores the current state of website security and the contributions Symantec is making to help organizations protect critical data and build trust with customers.