Hackers Co-Opt Comedy Central and Other Websites to Steal User Passwords   11/23/2004 - 1,369 views, 2 Comments

Summary: The unpermitted and surreptitious use of legitimate websites by hackers to steal the passwords and other sensitive information of users visiting those sites is on the rise. This is illustrated in blazing highlights by the brazen use of the Comedy Central website over the ...

Previous Article « Removing Cookies from Your System for All Browser Types
Read Next Article » Be Big Brother to Your Website Visitors - Website Monitoring to the Nth Degree

The unpermitted and surreptitious use of legitimate websites by hackers to steal the passwords and other sensitive information of users visiting those sites is on the rise.

This is illustrated in blazing highlights by the brazen use of the Comedy Central website over the weekend, along with several other sites. In each instance, the hackers had managed to install a virus on the website. In addition to grabbing sensitive data, the virus was also able to inject other programs onto the visiting user’s computer.

But that’s not where it ends. In a rather brilliant twist, the hackers drove traffic to the infected sites by planting seemingly legitimate ads which actually drove those who clicked the ads to the infected sites, on other sites!

The sites which unknowingly featured the bogus ads included TheRegister.co.uk, and Ilse.nl, a large Internet company in the Netherlands.

How, you may ask, did the hackers manage to plant the malicious advertisements?

Completing their trifecta, the hackers took control of of German advertising firm Falk Solutions AG.

Got that? So they 1) took control of the advertising firm, used that advantage to plant nefarious code in the 2) advertisements which featured in places like The Register, so that 3) when users clicked on the ads, they were driven to the legitimate websites, but with altered code which drove them to where the virus lay in wait to 4) steal their passwords and infect their own machines.

Diabolical.

Fortunately, this only appears to affect those who are using Internet Explorer, and who have not installed the Service Pack 2 software upgrade for XP. If you or your users are in this category, please update your system right away!

You can read more about this at the Washington Post.

Hackers Use Web Sites, Ads to Infect PCs (washingtonpost.com)

Get FREE email alerts of new Internet Patrol stories!
    *We never share your email address with anyone

Email Address:
Date of first visit:
How you found us:

Be sure to watch for the confirmation email!

Subscribe
to The Internet Patrol on your cell phone    Email the link for this page to a friend!

Read more:

»  Comedy Central Offers Internet Television with Its Motherload Network

»  Comedy Central Adds Shows to iTunes

»  Hackers, Government Unite to Take Down Terrorist Websites

»  Vast Majority of US Bank Websites Pose Security Risk to Users Says Study

For additional similar stories check out our archives on Everything Else

 

2 Comments »

  1. Hackers Co-Opt Comedy Central and Other Websites to Steal User Passwords
    The unpermitted and surreptitious use of legitimate websites by hackers to steal the passwords and other sensitive information of users visiting those sites is on the rise. This is illustrated in blazing highlights by the brazen use of the Comedy…

    Trackback by Lockergnome's Net Patrol — 11/23/2004 @ 11:37 pm

  2. Why does it seem the hackers are allways one step ahead of. The software to deny them access to so many pc. maybe i have a over active imagnation in away to deal with these hackers. Would it be pratical to seat up a world wide web of decoy super pc. To direct these hackers into these decoy system. lIke a trap to cage these hackers in a worldwide decoy web based system . Are maybe this idea is to far fetched and not pratical.

    Comment by Randall — 6/9/2008 @ 9:07 pm

RSS feed for comments on this post. TrackBack URI

Leave a comment

Warning! All comments which contain URLs and are clearly just spam to generate a link back to the URL will be deleted on sight. Don't bother wasting your time!

If you are going to include a URL in your comment,
please keep it under 25 characters in length,
or use TinyURL to shorten it before including it in your comment.

Line and paragraph breaks are automatic, your email address is never displayed.
HTML allowed: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

(required)

(required)


If you have not posted a comment here before, we apologize for having to ask you to enter the letters and numbers you see in the image above to validate your comment, but we are being attacked by thousands of comment form spams every day! You only need to do this once; once you have successfuly posted a comment here you will not be asked to do this again. Thank you for your understanding!

 
The Internet Patrol
Patrolling the Internet for You!