New hacker scheme is infecting educational servers worldwide with Viagra ads

04 March 2010
Imperva's latest report warns that hackers have become industrialized and represent an exponentially increased threat to individuals, organizations and Government. Imperva’s report says the emerging industrialization of hacking parallels the way in which the 19th century revolution advanced methods and accelerated assembly from single to mass production. The result is that today’s cybercrime industry has transformed and automated itself to improve efficiency, scalability and profitability.

As an example of this ‘industrial revolution’, Imperva has discovered a new hacker scheme that is infecting educational servers worldwide with Viagra ads that infect web users with malware when they visit the infected page on the legitimate education site. According to Imperva, cyber-criminals are using industrialized methods to automate an as-yet unreported search engine manipulation scheme that has infected hundreds, possibly thousands of .edu and .ac.uk servers worldwide with Viagra ads.

“This attack on academic institutions highlights how hacking has become industrialized infecting servers from major institutions including UC Berkeley, Ohio State, University of Oxford and more. Ironically, this technique is the most prevalent method used to create havoc in cyberspace, yet remains virtually unknown to the general public,” explained Imperva CTO Amichai Shulman.

Key findings in the report include the organizational structure and technical innovations for automating attacks:

Organization structure

Over the years, a clear definition of roles and responsibilities within the hacking community has developed to form a supply chain that resembles a drug cartel. The division of labor in today’s industrialized hacking industry includes:

- Researchers: A researcher’s sole responsibility is to hunt for vulnerabilities in applications, frameworks, and products and feed their knowledge to malicious organizations for the sake of profit.

- Farmers: A farmer’s primary responsibility is to maintain and increase the presence of botnets in cyberspace through mass infection.

- Dealers: Dealers are tasked with the distribution of malicious payloads.

Technical innovations

Hacking techniques once considered cutting-edge and executed only by savvy experts are now bundled into software tools available for download. Today, the hacking community typically deploys a two-stage process designed to proliferate botnets and perform mass attacks.

- Search engine manipulation. This technique is the most prevalent method used to spread bots, yet remains virtually unknown to the general public. Essentially, attackers promote Web-link references to infected pages by leaving comment spam in online forums and by infecting legitimate sites with hidden references to infected pages. For example, a hacker may infect unsuspecting Web pages with invisible references to popular search terms, such as “Britney Spears” or “Tiger Woods.” Search engines then scour the websites reading the invisible references. As a result, these malicious websites now top search engine results. In turn, consumers unknowingly visit these sites and consequently infected their computers with the botnet software.

- Executing mass attacks through automated software. To gain unauthorized access into applications, dealers input email addresses and usernames as well as upload lists of anonymous proxy addresses into specialized software, the same way consumers upload addresses to distribute holiday cards. Automated attack software then performs a password attack by entering commonly used passwords. In addition, today’s industrialized hackers can also input a range of URLs and obtain inadequately protected sensitive data.

 

Latest school and university security articles

 Devon and Cornwall police force reduces property burglary with Hermes property registration and identification devices

 SALTO Systems's offline access control readers combine with Siemens' SiPass security management system

 W32 Stuxnet-B rootkit can install itself automatically from a USB memory stick onto a fully-patched PC

 ASSA protects live-in students at Chaucer College in Canterbury

 OnSSI IP-based video surveillance system expands with Mesa County Valley schools' recording needs

 IndigoVision's HD IP Cameras monitor the opening ceremony of New Zealand high school

 Top security tips for the summer holiday season

 Mobotix CCTV protects the oldest public museum in Scotland

 SelectaDNA Grease helps Lancashire school combat lead theft

 Cody High School in Wyoming replaces analog video system with Axis network cameras

...[view more articles on education security]...

 

Other security websites:

Education security links

Education Minister sees devastation The Minister of Education has received a first hand look at the extent of the earthquake damage at one Christchurch school.

Education Management Corporation Urges Department of Education to Reconsider Gainful Employment Rule Education Management Corporation , one of the largest providers of post-secondary education in North America, today provided an official response to the U.S. Department of Education's proposed rule defining "Gainful Employment."

Security alert for fear of sabotage, assassination Deputy Prime Minister for security affairs Suthep Thuagsuban said on Thursday that he ordered strengthened security at key government offices, private buildings and important figures after some explos...

Somalia security official: Car bomb explodes at front gate of Mogadishu airport, 2 killed Somalia security official: Car bomb explodes at front gate of Mogadishu airport, 2 killed.

Higher education chief decries cuts in funding Massachusetts higher education commissioner Richard Freeland criticized state legislators yesterday for continuing to cut funding for public universities and colleges amid increased student demand, saying that they have put the system of 29 schools in a compromised position. Higher education - Education - Colleges and Universities - Educators - Public university

Call to merge Scottish education services Education authorities are facing a call to merge so classrooms may be spared the worst of the cuts in public spending.

Education Foundation hosting exhibit & recognition event Sept. 29 DEARBORN — Dearborn Education Foundation will be displaying the fruits of its labor during an exhibit Sept. 29.

directory of Education security suppliers
Search directory Register your company
Education Security books:

SEARCH NEWS
DIRECTORY
Google