Stories
Slash Boxes
Comments

SoylentNews is people

posted by Fnord666 on Monday November 19 2018, @04:06PM   Printer-friendly
from the I-know-what-kind-of-wish-*I*-would-make dept.

Make-A-Wish Website Crammed with Coin-Mining Malware:

Researchers with Trustwave say the (now clean) WorldWish.org site was compromised via a Drupal exploit and seeded with malicious JavaScript that enlisted the CPU cycles of visitor's machines to covertly generate cryptocurrency.

It seems that the site was using an older version of the Drupal CMS that was vulnerable to CVE-2018-7600, the remote code execution bug known for marketing purposes as "Drupalgeddon 2." The successful exploit of the vulnerability gives an attacker the current user's access level and, in the case of web servers, this means the ability to access and modify pages.

In the context of a crypto-jacking attack, the compromised page has a short script embedded into it that calls another server to get the actual cryptocoin mining script. That server can also be obfuscated by changing its address or bouncing the connection off other servers. When a user visits the infected page, the mining script is called and the user's machine is used to generate cryptocurrency for the attacker.

Having been widely reported since May, the Drupal bug is now easy to scan for and target for attack, thanks to readily available exploit scripts. This means anyone from novice cybercriminals to large, organized groups could be behind the attack.

[...] "For all we know this is one poor administrator trying to handle an international website with a lot of users," Sigler explained.

"We have seen time and time again where security gets overlooked."

Protecting against the attack is easy enough: Make sure Drupal (and all other web server apps) are updated and fully patched. Admins should also keep a close eye on any changes or unusual activity on their pages that could signal an attack.

What kind of person would compromise a site that grants wishes to dying youngsters?


Original Submission

This discussion has been archived. No new comments can be posted.
Display Options Threshold/Breakthrough Mark All as Read Mark All as Unread
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
(1)
  • (Score: 1, Touché) by Anonymous Coward on Monday November 19 2018, @04:43PM (5 children)

    by Anonymous Coward on Monday November 19 2018, @04:43PM (#763911)

    maybe the person was trying to be helpful. :) like "hey, jackass! update your shit!"

    • (Score: 5, Funny) by ikanreed on Monday November 19 2018, @04:53PM

      by ikanreed (3164) Subscriber Badge on Monday November 19 2018, @04:53PM (#763915) Journal

      You know, my neighbors weren't happy about when I made a similar "lock your upper story windows" argument.

    • (Score: -1, Troll) by Anonymous Coward on Monday November 19 2018, @07:01PM (1 child)

      by Anonymous Coward on Monday November 19 2018, @07:01PM (#763967)

      What kind of person would compromise a site that grants wishes to dying youngsters?

      The kind of scum that next week has the $$ to sneak over and be at your airport / point of entry as either a 'visitor worker' or 'refugee'. And then accidentally bombs your kids in your home town.

      • (Score: 0) by Anonymous Coward on Monday November 19 2018, @07:44PM

        by Anonymous Coward on Monday November 19 2018, @07:44PM (#763985)

        Let me guess, the kids being bombed happen in a third world country, and not in the West. And it was some western terrorist sitting in an office pressing a button to bomb a school full of children ... in a third world country thousands of miles away.

    • (Score: 2) by isostatic on Monday November 19 2018, @07:28PM (1 child)

      by isostatic (365) on Monday November 19 2018, @07:28PM (#763980) Journal

      And in the meantime here's a crypto currency donation to you

      • (Score: 0) by Anonymous Coward on Monday November 19 2018, @09:38PM

        by Anonymous Coward on Monday November 19 2018, @09:38PM (#764028)

        [ attachment missing! ]

  • (Score: 4, Insightful) by Subsentient on Monday November 19 2018, @05:15PM (1 child)

    by Subsentient (1111) on Monday November 19 2018, @05:15PM (#763924) Homepage Journal

    I hate humanity so fucking much. Nothing's sacred. A charity for dying children taken over with cryptomining malware. Absolutely disgusting.

    --
    "It is no measure of health to be well adjusted to a profoundly sick society." -Jiddu Krishnamurti
    • (Score: 3, Funny) by FatPhil on Monday November 19 2018, @05:26PM

      by FatPhil (863) <{pc-soylent} {at} {asdf.fi}> on Monday November 19 2018, @05:26PM (#763935) Homepage
      You're probably ascribing morals to a small script.
      --
      Great minds discuss ideas; average minds discuss events; small minds discuss people; the smallest discuss themselves
  • (Score: 5, Insightful) by ilsa on Monday November 19 2018, @05:37PM

    by ilsa (6082) Subscriber Badge on Monday November 19 2018, @05:37PM (#763938)

    It's highly unlikely that they were targeted by a specific person.

    Most likely, there is some server somewhere configured to blindly hit public IPs, look for specific vulnerabilities, and then exploit them when found.

    Anyone who actively monitors firewalls are used to seeing random incoming traffic that tries to hit services that don't actually exist on the IPs being hit. Whatever the IP is actually doing, or who it belongs to, is irrelevant.

    Welcome to the 2018 internet.

  • (Score: 5, Funny) by Runaway1956 on Monday November 19 2018, @05:44PM (1 child)

    by Runaway1956 (2926) Subscriber Badge on Monday November 19 2018, @05:44PM (#763942) Journal

    Someone was wishing they had truckloads of money. So, they set up a money making scheme on the make-a-wish site. How is this a problem?

  • (Score: 2) by sonamchauhan on Tuesday November 20 2018, @12:39AM

    by sonamchauhan (6546) on Tuesday November 20 2018, @12:39AM (#764096)

    "Yippeee, 5 Bitcoin. Oh wait, false alarm"
    "Yippee, 0.0034 Bitcoin. Oh wait ...."

(1)