Threat Level: green Handler on Duty: Pedro Bueno

SANS ISC InfoSec Handlers Diary Blog


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

Website Warnings

Published: 2009-08-01
Last Updated: 2009-08-01 22:49:54 UTC
by Deborah Hale (Version: 1)
7 comment(s)

We received an email today from a lady who runs a website that helps to look for and locate missing children. She has been using Google Alerts to get the information out about the children they are trying to locate.   Unfortunately someone has compromised one of the links and it was passing infections to those who have visited the page.  The lady was really disappointed and angry that someone would do something so awful to such a good cause.

Unfortunately this is happening more often than you realize.  Websites that are trying to improve our world, trying to help those who can't help themselves, business websites and social networking sites have all fallen victim to these bad players.

As I mentioned in my diary yesterday we had a customers website that was Gumblar'd.  We disabled the website and changed the FTP and Admin password on the account.  It was really a good thing that we did.  I checked my logs this morning and sure enough - the perp that compromised the account must have discovered that his little BOT had died and was attempting to login last night to revive it.  Fortunately they were unable too and now we have firewalled them so that they can't  get to any of our servers again.

So this is just a word of warning.  You can't be sure that you will not visit a website that has some malware imbedded so make sure you protect yourself.  Make sure that you use a good anti-virus, make sure that you use a firewall, make sure that you use good, strong passwords and change them often.  There are several sites on the Internet that will tell you how strong you passwords are. A couple that I have used are:

www.microsoft.com/protect/yourself/password/checker.mspx

www.securitystats.com/tools/password.php

We all need to do our part to minimize the damage done by the bad guys and try to help to teach our friends, relatives and neighbors to protect themselves as well.  To all of you that do, thanks a bunch.  You help to make our Internet a safer place for all.

Deb Hale Long Lines, LLC

7 comment(s)
Diary Archives