Wikipedia used to spread malicious code

By Tom Espiner, ZDNet UK
Tuesday, November 07, 2006 09:48 AM

A Wikipedia page has been used by hackers in an attempt to spread malicious code.

The entry for the MSBlast worm in the German version of the popular online encyclopedia was altered to include false information about a new version of the Lovesan/MSBlast worm, with links to a supposed fix, according to Sophos. The fix was actually a piece of malicious code, the antivirus vendor said in a notice published Friday.

It is not clear how long the vandalized page was live, but the editors of Wikipedia.de moved quickly to delete the links once they were discovered.

However, because Wikipedia archives old versions of articles, the hackers were still able to send links to the archived entry through a mass-mailed e-mail. This e-mail purported to be from Wikipedia, and directed German users to the fraudulent Lovesan/MSBlast entry. Because the e-mails linked to a legitimate Web site, they were able to bypass some antispam solutions, Sophos reported on Friday.

"The good news is that the authorities at Wikipedia quickly identified and edited the article on their site," Graham Cluley, senior technology consultant at Sophos, said in a statement. "Unfortunately, however, a version of the page remained in the archive, allowing the hackers to send out spam and continue to direct visitors to the malicious code."

Wikipedia confirmed that it has now permanently erased all versions of the page, according to German news site Heise Online.


WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.


Tech Jobs Now!

Search for your ideal tech job:

Five tips for tackling a one-time project

Tech Management

Don't let a one-time project derail your career. An IT consultant shares tips on how to successfully manage a "once-in-a-career" event.


Read more »



Open source blog reloaded!

Blog thumbnail

This is with great pleasure that this "little corner of the Web" is resuming activities through another member of the (now famous ;-)) Beijing Linux User Group (BLUG) doing the..... by Fred Muller

Read more »

Tags

  1. attack
  2. authentication and encryption
  3. blog
  4. data security
  5. e - mail
  6. google inc.
  7. internet
  8. malware
  9. microsoft corp.
  10. network
  11. network security
  12. pc security
  13. researcher
  14. security
  15. security management
  16. software
  17. spam and phishing
  18. symantec corp.
  19. viruses and worms
  20. web