UK intelligence site breached by hacker

By Tom Espiner, ZDNet UK
Friday, July 31, 2009 11:12 AM

MI5 has closed up a flaw on its Web site that could have opened up visitors to malicious attacks, the UK intelligence agency said.

The Web site suffered a cross-site scripting vulnerability that could have allowed hackers to inject code into the site and redirect users to malicious pages, MI5 admitted on Wednesday.

However, the government service insisted the Web site had been secured quickly, and that at no time had any intelligence operatives been exposed by the flaw.

"MI5 takes security very seriously," the intelligence agency told ZDNet UK. "The Web site is secure and hosted in a high-security environment."

Last week, a hacker with the handle '[-TE-]-Neo' wrote that the MI5 Web site was vulnerable to cross-site scripting and Iframe injection. The put the post on the Team Elite hacker forum last week, claiming the site was breachable through the search engine. Team Elite notified MI5's administrator of the flaw before posting proof-of-concept code.

The MI5 site uses an embedded Google search engine, said a spokesperson for the agency, who also confirmed that the site had been vulnerable through the search tool. However, the Web site is hosted separately from MI5's back-end systems and is not connected to sensitive data, the spokesperson added.

Once MI5 was informed of the vulnerability, it took action to remedy the situation, said the spokesperson. The flaw was not maliciously exploited and had been limited to that search engine.


WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.


Tech Jobs Now!

Search for your ideal tech job:

Keep IMAP e-mail messages locally using OfflineIMAP

Open Source

Vincent Danen discusses the uses of OfflineIMAP for synchronizing local and remote IMAP mailboxes and providing a good method for backing up e-mail.


Read more »



Buying a projector? Try an LED TV instead

Blog thumbnail

If you're thinking of buying a new projector for your office meeting room, why not consider getting an LED TV instead. LED TVs are similar to LCD TVs except..... by Lee Lup Yuen

Read more »

Tags

  1. attack
  2. authentication and encryption
  3. blog
  4. data security
  5. e - mail
  6. hacking
  7. internet
  8. malware
  9. microsoft corp.
  10. network
  11. network security
  12. pc security
  13. researcher
  14. security
  15. security management
  16. software
  17. spam and phishing
  18. symantec corp.
  19. viruses and worms
  20. web