Feeds

Dancing Sepp Blatter on 'World Cup site' creates security flap

Footy kingpin spotted throwing electronically doctored shapes

SANS - Survey on application security programs

The appearance of an animated Sepp Blatter dancing on what appeared to be a World Cup website caused confusion in anti-virus circles on Tuesday.

Tweets such as "Brazil 2014 website hacked to show a dancing Sepp Blatter on the home page http://www.fifa-brazil-2014.com" were forwarded to El Reg's security desk, sports subsection early on Tuesday.

The dancing Blatter "trick" is the one commonly used by phishing/clickjacking and could be perhaps seen as a skewed tribute to the Fifa president.

"Looking at the source code I wouldn't be surprised if it flagged some heuristics-based scanners," Martijn Grooten, anti-spam test director at Virus Bulletin, told El Reg.

Independent security researcher Darrel Rendell noted concerns about the WHOIS and hosting provider of the dancing Sepp site.

However Rik Ferguson, VP of security research at Trend Micro, was able to rule out foul play. "It's not a hack but a clever viral marketing campaign using a typo-squatted domain," Ferguson explained.

The official site is: http://www.fifa.com/worldcup/index.html and the campaign site is: http://www.fifa-brazil-2014.com (beware: there's a cheesy soundtrack and Blatter boogies to the sound of kettle drums).

"It was done through a private domain registration through DomainsbyProxy, though it's pretty clear who registered it," Ferguson added.

The launch of the viral marketing campaign coincides with street protests across Brazil against the amount of funds poured into building World Cup facilities, while basic public services remain rudimentary. The dancing Blatter merchants appears to be linked to people running an online campaign for a "fair" World Cup in Brazil next year. ®

Combat fraud and increase customer satisfaction

More from The Register

next story
Parent gabfest Mumsnet hit by SSL bug: My heart bleeds, grins hacker
Natter-board tells middle-class Britain to purée its passwords
Samsung Galaxy S5 fingerprint scanner hacked in just 4 DAYS
Sammy's newbie cooked slower than iPhone, also costs more to build
Obama allows NSA to exploit 0-days: report
If the spooks say they need it, they get it
Web data BLEEDOUT: Users to feel the pain as Heartbleed bug revealed
Vendors and ISPs have work to do updating firmware - if it's possible to fix this
Snowden-inspired crypto-email service Lavaboom launches
German service pays tribute to Lavabit
One year on: diplomatic fail as Chinese APT gangs get back to work
Mandiant says past 12 months shows Beijing won't call off its hackers
Call of Duty 'fragged using OpenSSL's Heartbleed exploit'
So it begins ... or maybe not, says one analyst
NSA denies it knew about and USED Heartbleed encryption flaw for TWO YEARS
Agency forgets it exists to protect communications, not just spy on them
prev story

Whitepapers

Designing a defence for mobile apps
In this whitepaper learn the various considerations for defending mobile applications; from the mobile application architecture itself to the myriad testing technologies needed to properly assess mobile applications risk.
3 Big data security analytics techniques
Applying these Big Data security analytics techniques can help you make your business safer by detecting attacks early, before significant damage is done.
Five 3D headsets to be won!
We were so impressed by the Durovis Dive headset we’ve asked the company to give some away to Reg readers.
The benefits of software based PBX
Why you should break free from your proprietary PBX and how to leverage your existing server hardware.
Securing web applications made simple and scalable
In this whitepaper learn how automated security testing can provide a simple and scalable way to protect your web applications.