Cryptome Hit By Blackhole Exploit Kit
wiredmikey writes with an excerpt from Security Week:"Whistleblower site Cryptome has been hacked and infected by the Blackhole exploit kit. ... Cryptome co-founder John Young however told SecurityWeek that the Cryptome site is in the process of cleaning everything up, and that process should be finished by the end of the day. Founded in 1996, Cryptome publishes thousands of documents, including many related to national security, law enforcement and military. On Feb. 12, a reader advised the site that accessing a file had triggered a warning in their antivirus about the Blackhole exploit kit. ... Subsequent analysis found thousands of files on the site had been infected."
Cryptome has certainly seen worse.
security whistleblowers get hacked? neverrrrrrrrrrrrrrrrrrrrrr
< SCRIPT src="/0002/afg/afg.php" >
I'm sure you all will sleep now that your burning curiosity was satisfied.
Symantec says that Blackhole affects "various Windows platforms". Does Cryptome run on Windows?
Give me Classic Slashdot or give me death!
The secret command shows up as a dot (".") on my system.
This may not be enlightening to anyone, but it appears to be a small black hole.
Almost every single sentence on my system ends in one of those ".". Including this one. Oh my god...
The blackhole may suck up all your whistleblow data, but no one can retrieve it from there.
Yes, it matters.
"This post is an artistic work of fiction and falsehood. Only a fool would take anything posted here as fact."
Doc this is heavy!
This attacks specifically checks for, and excludes browsers which are not IE 6 to 8
The thing that bothers em most about this is that it was an end users anti-virus that detected it rather than software protecting the servers.
"If any question why we died, Tell them because our fathers lied."
But the infection started on the 8th of February.
If you can set up a public website so secure that no hacker can ever hack, why don't you set one up?
Instead of criticize, why don't you show the world that such a site is indeed possible?
Maybe you can even make a buck or two out of it
Muchas Gracias, Señor Edward Snowden !
What it really looks for is outdated plugins. Lmgtfy'ing for things like spl0, spl1, spl2 all at once might luck out and show you a source. (Just be careful)
I analyzed a blackhole sent to a blackberry, and all the splX functions came back empty, but it still included the PluginCheck code.
Why would the operator care what browser you have? As long as your java runtime is pre 6u29 its all the same.
I have to wonder if this might be some sort of revenge attack due to the feud that has developed between Wikileaks and Cryptome?
much of left-wing thought is a kind of playing with fire by people who don't even know that fire is hot - George Orwell
This is not a security site. Also, does any of these elite security websites have a 100% clean record?
Can I light a sig ?
That the OS is unknown
McAfee, 'nuff said.
Dude, I don't think the spambot cares what you or anyone else thinks.
jesus, you would think with a post history like manysky211 has, that they would be removed from slashdot. reported as spam.
Hey I just sent in my analysis of the PHP file they were asking about.
Anyone wanna take a second look?
I'm not that great of a PHP coder, but maybe a second, third, nth pair of eyes could help figure it all out.
BTW, they called me A6.
I wonder how supernam will feel about this.