Login: Password: Forget password? / Register New User 
logo
Home Home | RSS feed - Onekit.com Software Magazine (Windows PC Software News) Current issue Current issue | RSS feed - Onekit.com Software Magazine (Latest Forum Topics) Forum and Community Forum & Community | Onekit's Software OneKit's Software | About us About us | Live Chat with Support Team Chat with support []
Games Graphics & Design MP3 & Audio Internet & Networks System & Utilities Home & Education Business WebDev SoftDev
Reviews & Articles :: Hackers raid US government and corporate data
Issue: July 2007 > Internet & Networks > Article "Hackers raid US government and corporate data"

Hackers raid US government and corporate data (Hackers raid US government and corporate data)  Hackers raid US government and corporate data

Internet & Networks
Hackers stole information from the US Department of Transportation and several US corporations by seducing employees with fake job listings on ads and email, a computer security firm said on Monday.

The list of victims included several companies known for providing security services to government agencies.

They include consulting firm Booz Allen, computer services company Unisys, computer maker HP and satellite network provider Hughes Network Systems, a unit of Hughes Communications, said Mel Morris, chief executive of British internet security provider Prevx.

HP declined to comment, while officials with other companies couldn't be reached for comment. A Department of Transportation spokeswoman said the agency couldn't find any indication of a security breach.

Malicious programs were able to pass sophisticated security systems undetected because that software hadn't been instructed that they were dangerous. Hackers targeted only a limited group of personal computers, which kept traffic down and allowed them to stay under the radar of security police who tend to identify threats when activity reaches a certain level.

"What is most worrying is that this particular sample of malware wasn't recognised by existing antivirus software. It was able to slip through enterprise defenses," said Yankee Group security analyst Andrew Jaquith, who learned of the breach from Morris.

It was not clear whether the hackers used information stolen from the personal computers, Morris said.

Internet security firms began to release patches to fight the malicious software on Monday night.

Trend Micro, for example, has sent its customers software that prevents the malicious software from being installed on computers. It also blocks browsers from going to websites that the company has identified as being infected with the dangerous programs, said company spokesman Mike Haro.

"This is a serious threat. It shows how sophisticated hackers have become," Haro said.

A piece of software, NTOS.exe, probes the PC for confidential data, then sends it to a website hosted on Yahoo. That site's owner is probably unaware that it is being used by hackers, Morris said.

That website hosts data that had been stolen from more than 1,000 PCs and encrypted before it was posted on the site, according to Morris.

He said that he believes the hackers have set up several "sister" websites that are collecting similar data from other squadrons of malicious software.

Officials with Yahoo weren't available for comment.

Morris said that he had downloaded the data from the website and decrypted it at the request of investigators from the FBI's Law Enforcement Online, or LEO, programme, who were looking into the matter.

An FBI spokesman declined comment, saying it is agency policy to neither confirm nor deny whether an investigation is ongoing.

Related Links:
July 18, 2007
Author: Reuters
There are no users' comments | Post your comment
Copyright 2003-2008 - Software Magazine, onekit.com, Legal Notices
Advertisement Advertisement