|
|
Our friends from Sunbelt reported the Bank of India website as seriously compromised late last night. The main page of this website had a hidden IFRAME linking to a malicious website hosting multiple exploits. An unsuspecting visitor will end up getting infected if their system is not fully patched.
At McAfee Avert Labs, we come across defacements of Indian websites on a regular basis. This is only the second high profile incident where a popular Indian website was compromised to serve malware. A prior incident took place with the national air carrier’s website AirIndia getting compromised to host malware.
Following is a pictorial representation of how the Bank of India website was found to be linked to malicious sites, this morning (Indian time).

McAfee protects its customers against this threat via script scan. You can read more about this on one of our earlier blogs here. The obfuscated scripts that attempt to exploit users machines are blocked from execution, thereby, nullifying the attack. The script used in this attack was proactively detected as JS/Downloader-AUD.
Following are some of the malware we saw getting downloaded at the time of writing this blog (Credits to Prashanth PR for analysis).
Update: We made contact with the Bank officials and intimated them about the situation. The site has been cleaned up now
|
|
This is only the second high profile incident where a popular Indian website was compromised to serve malware.I did not quite got the presentation. But I am sure that the guys who did this one. did a great job.
I think that they should strenghten their seciruty on thier sites. Specially thet money is greatly involve on thier site. Many people who are capable of doing this are cant wait to get their hands on them.
“Its surprising how important websites where finacial transactions take place can have such security lapses ! “
They are not the first! safety tech is not yet fully developed.
Kudos to McAfee !
Its surprising how important websites where finacial transactions take place can have such security lapses !
Indian financial institutions need to wake up and smell the coffee ! Its too bad that they cannot be sued at the drop of the hat like in many other countries, if that were the case, they would be more cautious about their customers getting impacted. They need to invest more in making their websites secure !!
Well done Gents,
Even though India being a major state in Software industry, less importance is given to security in most of the establishments.
For instance While I was going through this blog a TV channel was flashing a news of a Guy who hacked and posted passwords of few high profile Indian Govt employees.
Time to wake up and act upon.
Submit your own comments / message for this post