<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Darknet - The Darkside &#187; hacking embassy sites</title>
	<atom:link href="http://www.darknet.org.uk/tag/hacking-embassy-sites/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<lastBuildDate>Tue, 07 Feb 2012 18:34:17 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Hacked Embassy Websites Delivering Malware</title>
		<link>http://www.darknet.org.uk/2008/01/hacked-embassy-websites-delivering-malware/</link>
		<comments>http://www.darknet.org.uk/2008/01/hacked-embassy-websites-delivering-malware/#comments</comments>
		<pubDate>Thu, 24 Jan 2008 08:16:43 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Spammers & Scammers]]></category>
		<category><![CDATA[Web Hacking]]></category>
		<category><![CDATA[embassy]]></category>
		<category><![CDATA[hacking embassy sites]]></category>
		<category><![CDATA[hacking website]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[trojans]]></category>
		<category><![CDATA[viruses]]></category>
		<category><![CDATA[worms]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/2008/01/hacked-embassy-websites-delivering-malware/</guid>
		<description><![CDATA[It seems like malware pushers have found another avenue to delivery their payloads, Embassy websites. Which makes sense as they are probably not maintained well nor updated often meaning the chance they are easily compromised is quite high. Plus a lot probably use off the shelf CMS software, which when not updated is a playground [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>It seems like malware pushers have found another avenue to delivery their payloads, Embassy websites. Which makes sense as they are probably not maintained well nor updated often meaning the chance they are easily compromised is quite high.</p>
<p>Plus a lot probably use off the shelf CMS software, which when not updated is a playground for hackers.</p>
<blockquote><p>Add embassy websites to the growing list of hacked internet destinations trying to infect visitor PCs with malware.</p>
<p>Earlier this week, the site for the Netherlands Embassy in Russia was caught serving a script that tried to dupe people into installing software that made their machines part of a botnet, according to Ofer Elzam, director of product management for eSafe, a business unit of Aladdin that blocks malicious web content from its customers&#8217; networks. In November the Ministry of Foreign Affairs of Georgia and Ukraine Embassy Web site in Lithuania were found to be launching similar attacks, he says.</p></blockquote>
<p>Again it just goes to show that a lot of malicious attacks are based around human elements, in this case trust. People will naturally trust an Embassy website, so if you embed it with a message to download some kind of protective software&#8230;a lot of people will do it.</p>
<blockquote><p>Frequently, the compromised websites launch code that scours a visitor&#8217;s machine for unpatched vulnerabilities in Windows or in applications such as Apple&#8217;s QuickTime media player. Such was the case in two recent hacking sprees that affected hundreds of thousands of sites, including those of mom-and-pop ecommerce companies and the City of Cleveland.</p>
<p>But in the case of the Netherlands Embassy, the attackers simply included text that instructed visitors to download and install the malware. Of course, no self-respecting Reg reader would fall for such a ruse. But sadly, Elzam says, because the instruction is coming from a trusted site, plenty of less savvy users do fall for the ploy. Saps.</p></blockquote>
<p>Again we can just educate and spread the news, tell people not to trust any web sites if possible, use md5 hashes, use trusted sources, scan for the viruses etc..</p>
<p>Trust no one! (Except me of course *evil laugh*).</p>
<p></p>
<p>Source: <a href="http://www.theregister.co.uk/2008/01/23/embassy_sites_serve_malware/">The Register</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Hacked+Embassy+Websites+Delivering+Malware+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D791+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2008/01/hacked-embassy-websites-delivering-malware/&amp;t=Hacked+Embassy+Websites+Delivering+Malware" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2008/01/hacked-embassy-websites-delivering-malware/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2008/01/hacked-embassy-websites-delivering-malware/&amp;title=Hacked+Embassy+Websites+Delivering+Malware" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2008/01/hacked-embassy-websites-delivering-malware/&amp;title=Hacked+Embassy+Websites+Delivering+Malware" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2008/01/hacked-embassy-websites-delivering-malware/&amp;title=Hacked+Embassy+Websites+Delivering+Malware" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2008/01/hacked-embassy-websites-delivering-malware/&amp;title=Hacked+Embassy+Websites+Delivering+Malware" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2008%2F01%2Fhacked-embassy-websites-delivering-malware%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2008/01/hacked-embassy-websites-delivering-malware/feed/</wfw:commentRss>
		<slash:comments>7</slash:comments>
		</item>
	</channel>
</rss>

