Security Management
Published on Security Management (http://www.securitymanagement.com)
U.K.: MI-5 Web Site Hacked
By Matthew Harwood
Created 07/30/2009 - 09:57



    
Wrap-Up?: 
No
Weight: 
0
Lead Headline?: 
No
Date: 
07/30/2009
By Line: 
By Matthew Harwood
Teaser: 

Britain's domestic intelligence agency has admitted that a vulnerability in its Web site's search engine could have allowed hackers to divert visitors to malicious pages, reports ZDNet UK.

Britain's domestic intelligence agency has admitted that a vulnerability in its Web site's search engine could have allowed hackers to divert visitors to malicious pages, reports ZDNet UK [1].

The cross-site scripting and Iframe injection vulnerabilities was exposed by a hacker named [-TE-]-Neo, who posted on a popular hacking forum that MI-5's Web site could be hacked through its search engine.

According to ZDNet UK:

The MI5 site uses an embedded Google search engine, said a spokesperson for the agency, who also confirmed that the site had been vulnerable through the search tool. However, the website is hosted separately from MI5's back-end systems and is not connected to sensitive data, the spokesperson added.

Once MI5 was informed of the vulnerability, it took action to remedy the situation, said the spokesperson. The flaw was not maliciously exploited and had been limited to that search engine.

Last year, Eastern European hackers infected thousands of British Web sites, including local government and National Health Service Web sites, with a virus called Asprox. Its believed that some visitors to these sites had their identities stolen and found money taken from their bank accounts as well as other frauds, reports The Telegraph [2].


♦ Photo by Cyril Cavalié/Flickr [3]

Related Resources: 
Thumbnail: 

Comments

Injections

Submitted by ryan on Mon, 08/03/2009 - 07:44.

Most of the security vulnerabities occur due to code injections. Its where the backend takes the user parameter on web page and processes it as a command. So, an unsecure search tool might take a search term, parse it and run it on the system opening a loophole for a hacker.

P.S: I personally run a online dating site and hence know about website security.


Security Management is the award-winning publication of ASIS International, the preeminent international
organization for security professionals, with more than 38,000 members worldwide.

ASIS International, Inc. Worldwide Headquarters, 1625 Prince Street, Alexandria, Virginia 22314-2818 U.S.A.
703.519.6200 | fax 703.519.6299 | www.asisonline.org

ASIS

© 2013 Security Management
This site is protected by copyright and trade mark laws under U.S. and International law.
No part of this work may be reproduced without the written permission of Security Management.

Powered by: Phase2 Technology

Source URL: http://www.securitymanagement.com/news/uk-mi-5-web-site-hacked-005976

Links:
[1] http://news.zdnet.co.uk/security/0,1000000189,39700487,00.htm
[2] http://www.telegraph.co.uk/technology/news/5937833/Identity-theft-hackers-attack-MI5-website.html
[3] http://www.flickr.com/photos/cyrilcavalie/2594932689/