On Metacritic: BioShock 2: The reviews are in
BNET Business Network:
BNET
TechRepublic
ZDNet

July 21st, 2008

Kaspersky's Malaysian site hacked by Turkish hacker

Posted by Dancho Danchev @ 4:26 am

Categories: Anti Virus, Black Hat, Hackers

Tags: Kaspersky, SQL Injection, Web Site Defacement, Turkey, Malaysia, Dancho Danchev

According to Zone-h.org, Kaspersky’s Malaysian site has been defaced by a Turkish hacker during the weekend, through aKaspersky’s Malaysian site hacked by Turkish hacker SQL injection, leaving the following message - “hacked by m0sted And Amen Kaspersky Shop Hax0red No War Turkish Hacker Thanx to Terrorist Crew all team members“.

“The official Malaysian Kaspersky Antivirus’s website has been hacked yesterday by a Turkish cracker going by the handle of “m0sted”. Along with it, the same cracker hacked also the official Kaspersky S.E.S. online shop and its several other subdomains. The attacker reported “patriotism” as the reason behind the attack and “SQL Injection” as the technical way the intrusion was performed.

Both websites  has been home page defaced as well as several other secondary pages.  The incident, though appearing a simple website defacement, might carry along big risks for end-users because from both the websites, evaluation copies of the Kaspersky Antivirus are distributed to the public. In theory, the attacker could have uploaded trojanized versions of the antivirus, infecting in this way the unaware users attempting a download from a trusted Kaspersky’s file repository (remember the trojan in the Debian file repository?).”

Are users at risk due to the compromise? Not in this case, however, the attack is a wake up call which if not taken seriously enough could result in an ironic situation where a security vendor’s site is infecting its visitors with malware. It has happened before, and it will definitely happen again.

This is not an isolated incident. According to Zone-h’s archive, since 2000 there have been 36 web site defacements of international Kaspersky sites, with Kaspersky’s French site getting hacked and re-hacked on an yearly basis. And while in none of the incidents there was any malicious software served, or a live exploit URL that could have been embedded into the legitimate site, there’s an ongoing trend related to web site defacements in regard to their interest in monetizing the access they have to the vulnerable sites, by injecting malware URLs, hosting phishing pages, and also, locally hosting blackhat SEO junk pages where they would eventually earn money through affiliate based networks.

In the time of blogging there’s no indication of a malware attack at the site, and kaspersky.com.my remains offline, presumably in an attempt to audit the site for web application vulnerabilities before putting it back online.

Related posts :

Dancho DanchevDancho Danchev is an independent security consultant and cyber threats analyst, with extensive experience in open source intelligence gathering, malware and cybercrime incident response. He's been an active security blogger since 2007, and maintains a popular security blog. See his full profile and disclosure of his industry affiliations.

Email Dancho Danchev

Subscribe to Zero Day via Email alerts or RSS.

Related Discussions on TechRepublic

Did you know you can take part in these discussions with your ZDNet membership?

  • Talkback
  • Most Recent of 9 Talkback(s)
Websites Were Under Construction
Both of the websites that were attacked are managed using third-party hosting. The sites have never been publicly accessible as they are still under construction.

Since the websites are still b... (Read the rest)
Posted by: SpencerB Posted on: 07/28/08 You are currently: a Guest | | Terms of Use
Hackers Gone Wild?  Rafal.Los (RX8volution) | 07/21/08
so called "hackers"  JamesDoyle | 07/21/08
RE: Kaspersky's Malaysian site hacked by Turkish hacker  ryanlee05 | 07/21/08
I hope its safe  tracy anne | 07/21/08
ok fanboy  JamesDoyle | 07/21/08
Indeed they are  tracy anne | 07/22/08
RE: Kaspersky's Malaysian site hacked by Turkish hacker  shuklabhi | 07/21/08
What a black-eye...  RS9 | 07/22/08
Websites Were Under Construction  SpencerB | 07/28/08

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement
Click Here

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads