« Hello | Main | Words _can_ hurt you after all »

September 18, 2008

As if they didn't have enough problems...

Hi folks,

Poor old Texas. Not only did hurricane ike hit them really hard, but it seems that at least of pages on the Texas National Guard website are hacked. If you visit the wrong page, it reaches out to a website, probably in Russia (can't confirm it, because the isp for the host is not answering whois queries), and is installing a rootkit, if you're not patched. Now, here are a few screenshots, just for interest's sake, but _DON'T GO_ to any of these sites unless you know what you're doing!

Here's what the initial screen looks like (more or less) when you visit it with a normal webbrowser ...

Mainscreen

Looks pretty normal, but if you have some good debug tools, you find it's actually reaching out to somewhere strange ... add-block-plus.net, which in turn reaches to a couple of other places (you should be able to click the image to see it full-size)...

Bho

and if you're not patched, when you close your browser, you find that your desktop has changed, and now looks like this ...

After_the_hit

Gosh! Spyware!? Who'd have thought it?!?!? Of course, anybody who watches this stuff a bit knows  that this machine is now hopelessly nailed, and code has been installed in the background, and their pitch is that they'll remove it for a meer $49.95, and insert your credit card number here, please.

And, of course, now that they've got your machine, they're not going to let it go until they've got what they want, because they've installed a rootkit...

Rootkit

It just seems a bit ironic that when Texas has been hammered so hard by the hurricane, the guys that are probably helping out the most have been hacked. The poor Texas National Guard needs to find how the Bad Guys got in, and then plug that hole.

It's a dangerous world out there folks... keep safe!

Cheers

Roger

Comments

Feed You can follow this conversation by subscribing to the comment feed for this post.

Verify your Comment

Previewing your Comment

This is only a preview. Your comment has not yet been posted.

Working...
Your comment could not be posted. Error type:
Your comment has been saved. Comments are moderated and will not appear until approved by the author. Post another comment

The letters and numbers you entered did not match the image. Please try again.

As a final step before posting your comment, enter the letters and numbers you see in the image below. This prevents automated programs from posting comments.

Having trouble reading this image? View an alternate.

Working...

Post a comment

Comments are moderated, and will not appear until the author has approved them.

AVG's Homepage | About Us | Privacy Policy | © 2008 AVG Technologies