US feds pull travel site offline after hacker break-in
GovTrip trips up
Regcast training : Hyper-V 3.0, VM high availability and disaster recovery
A travel reservations website used by US government agencies remains offline more than a week after it was infected with malware that tried to install malicious code on the PCs of those who visited the site.
Agencies including the Federal Aviation Administration, the Environmental Protection Agency, and the Department of Transportation all reportedly directed employees not to use the website until further notice. (Those advisories presumably were sent prior to the the site being taken down).
"Employees should not access GovTrip from any DOT/FHWA PC while at work and we strongly suggest employees refrain from any attempts to access GovTrip using a home system or government-issued laptop as this could cause the PC to be infected with a virus that may not be detected by your anti-virus software," a Department of Transportation email sent to employees read, according to Brian Krebs's Security Fix blog, which first reported the security lapse.
The breach comes two weeks after hackers broke into the Federal Aviation Administration's computer system and accessed the names and Social Security numbers of 45,000 employees and retirees.
The General Services Administration issued a statement earlier this week that confirmed the attack took place on February 11 and said "no personal data was known to be compromised." It has yet to issue an update, and representatives didn't immediately return a phone call. Defense contractor Northrop Grumman, which Security Fix says manages the computer system, has declined to comment.
"While the attack and potential compromising of employees personal and financial information is troubling enough, perhaps more so is the complete lack of information released on this subject," Nextgov.com complained. ®
COMMENTS
Go back to bed America...
Nothing to see here... Go back to bed America, your government is in control.
Infection in T-minus...
"'Employees should not access GovTrip from any DOT/FHWA PC while at work and we strongly suggest employees refrain from any attempts to access GovTrip using a home system or government-issued laptop as this could cause the PC to be infected with a virus that may not be detected by your anti-virus software,' a Department of Transportation email sent to employees read..."
But of course, they'll continue to keep the site up so that it can infect the people who haven't been warned (read: the world at large). We certainly wouldn't want to do the right thing and, you know, REMOVE THE MALWARE. That would be too much work, apparently.
Oh but rest assured that...
"no personal data was known to be compromised."
How much more fool-truthy and slipshod-shuffle can a blanket passive-voice past-tense false-face sootheover "assurance" ever be than that? By the ringing in me Third Ear as well as the stench in me Third Nostril, this is the selfsame bland passive Gummint voice that every so often tells us, "We have requested and received assurances from the government of Torturestan that the high-value detainee rendered thereunto for Robust Interrogation Tech Treatment will not be known to have been tortured." Like it "Never Happened".
They do it to everyone they can get away with doing it to. This time it is their own employees that the Overmen have punked. It is an abomination; the entire glossing-out practice should be wiped from the arse of the Earth forthwith. Gah.

IT infrastructure monitoring strategies
Agentless Backup is Not a Myth
Top 10 SIEM implementer’s checklist
Steps to Take Before Choosing a Business Continuity Partner
Requirements Checklist for Choosing a Cloud Backup and Recovery Service Provider