All the latest UK technology news, reviews and analysis

US Treasury web sites hacked using iFrame

by Iain Thomson

04 May 2010

Comments: 2

  • Tweet this
US Treasury
Three sites at the US Treasury have been hacked using a code injection attack

At least three US Treasury department web sites have fallen victim to a code injection attack using iFrames.

Roger Thompson, chief research officer at security firm AVG, told V3.co.uk that it is extremely uncommon for federal government sites to be hacked.

"City and country level sites get hacked all the time in the US and the UK, but it is very unusual to see an attack like this," he said.

The affected sites, which have now been taken down, are bep.gov, bep.treas.gov and moneyfactory.gov.

The attack used an iFrame to add malware to the sites which reportedly sent data via a series of hosted PCs to the controller believed to be in eastern Europe.

Thompson said that the precise method of attack had not been proved, but that there was an 80 per cent chance that it came from the use of a third-party site visitor counter. He suspected the flaw could prove difficult to fix.

"I would not be at all surprised if it does not come back when they restart the sites, in which case we will have a bit of a chuckle and tell them again," he said.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

30%

1%

12%

57%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Symanteccloud

Social networking: a guide for IT managers

Social networking is almost ubiquitous. This white paper examines the benefits and risks and it looks at the different ways companies can reconcile them

Riverbed

Mitigating the risks of IT change

The importance of understanding your infrastructure

Scrum Master

Want to work for one of the most dynamic, creative environments...

Interactive & Mobile QA Engineer

Want to work for one of the most dynamic, creative environments...

Enterprise Architect - London - £100k - £120k

Roc Search is currently recruiting for an Infrastructure...

IP Services Project Engineer (Alcatel/Cisco)

Want to work for one of the most dynamic, creative environments...

To send to more than one email address, simply separate each address with a comma.