Author Topic: Indonesia Government Site is injected  (Read 2651 times)

0 Members and 1 Guest are viewing this topic.

Offline Yanto.Chiang

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1371
  • Soli Deo Gloria
    • PT Garuda Sinatriya Globalindo
Indonesia Government Site is injected
« on: August 19, 2013, 01:13:09 PM »
Dear All,

This evening we found that one of Indonesian website has been injected by malicious javascript. The site is : hxxp://xxx.ombudsman.go.id

But from some website scanner, this site is secured and not listed as blacklist website :

https://www.virustotal.com/en/url/1fc02a52599e47f617377e38d90cae32feed81782f2c60e46576f41e830dd891/analysis/1376909538/
http://www.urlvoid.com/scan/ombudsman.go.id/
http://vscan.novirusthanks.org/analysis/ff08bb97b936305f8106362e50d73a19/aW5kZXg=/

Is that true that this website is injected?
Yanto Chiang | IT Security Consultants | AVAST Premium Security | GarudaSinatriya

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37527
  • Not a avast user
Re: Indonesia Government Site is injected
« Reply #1 on: August 19, 2013, 01:19:09 PM »
« Last Edit: August 19, 2013, 01:20:42 PM by Pondus »

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: Indonesia Government Site is injected
« Reply #2 on: August 19, 2013, 01:56:23 PM »
I'd say they are hacked given the site is down. Avast isn't the cause of the blockage either. (Disabled until I can the install to work).

URLQuery: http://urlquery.net/report.php?id=4619208
« Last Edit: August 19, 2013, 01:59:23 PM by alan1998 »
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37527
  • Not a avast user
Re: Indonesia Government Site is injected
« Reply #3 on: August 19, 2013, 02:01:45 PM »
according to this the site is not down, click pic in top richt corner.   http://urlquery.net/report.php?id=4619234



Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: Indonesia Government Site is injected
« Reply #4 on: August 19, 2013, 03:30:49 PM »
When I tried going on it wasn't loading. Or is thatr Java at the hand?
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33897
  • malware fighter
Re: Indonesia Government Site is injected
« Reply #5 on: August 19, 2013, 04:50:53 PM »
Outdated joomla at the culprit of this hack, http://ombudsman.go.id/test404page.js
404 Not Found
Content-Length: 277
Content-Type: text/html
failure: <urlopen error timed out>

polonus
« Last Edit: August 19, 2013, 07:01:45 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!