ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Hackers attacked parliament using WMF exploit

Tom Espiner ZDNet.co.uk

Published: 23 Jan 2006 13:35 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

The British Parliament was attacked late last year by hackers who tried to exploit the WMF flaw within Windows, security experts confirmed on Friday.

MessageLabs, the email filtering provider for the UK government, told ZDNet UK that targeted emails were sent to various individuals within government departments in an attempt to take control of their computers.

The attack occurred over the Christmas period and came from China, according to Mark Toshack, manager of antivirus operations at MessageLabs, who added that the emails were intercepted before they reached the government's systems.

"The attack definitely came from China — we know that because we log the IP addresses. The UK Government was targeted but none [of the emails] got through. No-one was affected — they were attacked but they [the government] didn't know about it until we told them," said Toshack.

The vulnerability with the way that WMF images are handled by Windows was discovered in November 2005. In a WMF attack, exploit code is hidden within a seemingly normal image that can be spread via emails or instant messages.

The first exploit code targeting the flaw was detected on 29 December, but Microsoft did not issue a patch until 5 January, after a security research released his own, unofficial patch.

The attack occurred on the morning of 2 January, before Microsoft's official patch was available. The hackers tried to send emails that used a social-engineering technique to lure users into opening an attachment containing the WMF/Setabortproc Trojan.

The Trojan, had it been downloaded, would have allowed the attackers to view files on the PC. The hackers may also have been able to install keylogging malware, said Toshack, enabling attackers to see classified government passwords.

The attack was individually tailored, and sent to 70 people in the government, according to MessageLabs. It played on people's natural curiosity by purporting to come from a government security organisation. The Trojan was hidden as an attachment called "map.wmf".

The body text of one of the emails read:

"Attached is the digital map for you. You should meet that man at those points separately. Delete the map thereafter. Good luck. Tommy"

The hackers could have been successful if the emails had reached their destinations, said Toshack. "It's like something you get from spooks — you can think 'I'm suddenly an MI5 agent.' You can see how it could work — it plays on people's romanticism about spies," Toshack suggested.

Speaking last November, Alan Paller, director of the SANS Institute, claimed that the Chinese government was employing malicious hackers.

"Of course it's the government. Governments will pay anything for control of other governments' computers. All governments will pay anything. It's so much better than tapping a phone," Paller told ZDNet UK.

Toshack could not confirm whether the Chinese government had been involved. "It is a Chinese hacker gang. I don't know if it is the Chinese government, and I don't know if it's the Chinese government paying a hacker gang," he said.

According to a Home Office source, the government is concerned about the threat posed by Trojan attacks. A Home Office spokesman would not confirm or deny an attack took place over Christmas.

"We do not comment on security matters, but have had discussions with many governments and computer emergency response teams from around the world on the matter of targeted Trojan attacks," a Home Office spokesperson told ZDNet UK.

The attempted attack on Parliament was first reported by The Guardian last week.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
169 out of 281 people found this useful



Company/Topic Alerts

Create a new alert from the list below:





Related Jobs

JavaScript / AJAX / Web 2.0 development role

I have a brand new, exciting opening in Edinburgh for a rapidly expanding software house poised to further attack the market on the back of recent ...

Pathways Improvement & Development Manager

This client have a significantly increased need for pathway re-design and improvements due to the recent designation as an early adopter for the Map ...

Marketing Analysts required 22-27K+ benefits Manchester

My industry leading financial client is seeking competent and ambitious analysts to develop targeted customer analysis, lists, models and reports for ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment