PDA

View Full Version : Security Vendor: Bank Site Hacked, Dispensing Malware



SBgooo
02.09.07, 10:57
The Web site of the Bank of India has been hacked and is now an unwitting dispenser of an enormous amount of malware code to visitors, including rootkits and trojans, according to Sunbelt Software, which advises not currently visiting the Bankofindia.com site.

"It's very pernicious stuff," says Alex Eckelberry, president of security firm Sunbelt Software.

Eckelberry says some of Sunbelt's employees happened to be doing research during the past few hours and visited the Web site and determined it was infected with at least a dozen malware programs attempting to infect any vulnerable machine used by someone visiting Bankofindia.com.

"We have Indian employees here trying to share this information with them now, which we're also sharing with organizations such as CERT," Eckelberry says. "It's a huge payload of malicious code," which Sunbelt is still analyzing, he says.

The payload from the Bank of India site is said to be attempting a number of Internet Explorer exploits to break into computers that may not be fully patched. Other types of software-application exploits may also be involved, which Sunbelt is still analyzing.

"Somehow the hackers managed to insert this code into the Web site," Eckelberry says. "We're seeing lots of rootkits and trojans, though not yet a keylogger."

Sunbelt says the situation is still fluid and every effort is being made to notify Bank of India, described as a government-operated site with more than 2,000 branches.

Read Sunbelt's description of the Bank of India malware problem.

For more information about enterprise networking, go to NetworkWorld. Story copyright 2007 Network World Inc. All rights reserved.

source is here : pcworld (http://www.pcworld.com/article/id,136666-page,1-c,topics/article.html)

StonedAssassin
12.09.07, 00:36
Couldn't they just upload a backup or something and get rid of the bad code? I mean its a bank... banks should have loads of backups

Azraelle
01.10.07, 12:20
Indian admins doesn't use backups