ad info




CNN.com
 MAIN PAGE
 WORLD
 U.S.
 LOCAL
 POLITICS
 WEATHER
 BUSINESS
 SPORTS
* TECHNOLOGY
   computing
   personal technology
 SPACE
 HEALTH
 ENTERTAINMENT
 BOOKS
 TRAVEL
 FOOD
 ARTS & STYLE
 NATURE
 IN-DEPTH
 ANALYSIS
 myCNN

 Headline News brief
 news quiz
 daily almanac

  MULTIMEDIA:
 video
 video archive
 audio
 multimedia showcase
 more services

  E-MAIL:
Subscribe to one of our news e-mail lists.
Enter your address:
Or:
Get a free e-mail account

 DISCUSSION:
 message boards
 chat
 feedback

  CNN WEB SITES:
CNN Websites
 AsiaNow
 En Español
 Em Português
 Svenska
 Norge
 Danmark
 Italian

 FASTER ACCESS:
 europe
 japan

 TIME INC. SITES:
 CNN NETWORKS:
Networks image
 more networks
 transcripts

 SITE INFO:
 help
 contents
 search
 ad info
 jobs

 WEB SERVICES:

COMPUTING

Hackers tampering with Internet, e-mail links

February 8, 2000
Web posted at: 8:35 a.m. EST (1335 GMT)

by Diane Frank

From...
Federal Computer Week

(IDG) -- Federal and industry security teams are warning agencies about malicious code embedded in Internet links on World Wide Web sites and in e-mails that could allow hackers to capture any information entered by the user.

MORE COMPUTING INTELLIGENCE
IDG.net   IDG.net home page
  How to safeguard your personal information, your PC--and your children
  Diary of a hack attack
  Reviews & in-depth info at IDG.net
  Subscribe to IDG.net's free daily newsletters
  News Radio
  * Fusion audio primers
  * Computerworld Minute

The Computer Emergency Response Team (CERT) Coordination Center, the Defense Department CERT, the DOD Joint Task Force for Computer Network Defense, the Federal Computer Incident Response Capability and the FBI's National Infrastructure Protection Center jointly issued the alert on Wednesday.

The method the hackers used, called cross-site scripting, is embedded HTML script or tags that are not usually recognized by Internet servers, so anyone using any system or Web browser is vulnerable, according to the advisory. As soon as a user clicks on a link that includes the malicious script, whether the link is on a Web page or in an e-mail, the user sends to the Web server the malicious code. Hackers then can capture or change the page the user sees, affecting both the user and the server administrator.

The advisory includes steps that users and Web site administrators can take to protect themselves. But technical teams and law enforcement officials are encouraging users to forward any information or feedback. So far, no attacks had been reported, but the potential for harm is very high, according to the advisory.


RELATED STORIES:
The Web is a hacker's playground
January 18, 2000
Teens steal thousands of Net accounts
January 14, 2000
Governments ready to fight cyber-crime in new millennium
January 2, 2000
Security hole found in Netscape mail system
December 16, 1999

RELATED IDG.net STORIES:
How to safeguard your personal information, your PC--and your children
(PC World Online)
Stop Hackers Before They Attack
(PC World Online)
Hacker magazine calls for movie business protest
(NetworkWorld Fusion)
@Stake's pitch: Hackers are your friends
(NetworkWorld Fusion)
HTML virus affects Internet Explorer
(Computerworld)
CERT warns of networked denial of service attacks
(Computerworld)
Y2K gaves some admins a security education
(Computerworld)
Diary of a hack attack
(NetworkWorld Fusion)
Note: Pages will open in a new browser window
External sites are not endorsed by CNN Interactive.

RELATED SITES:
FedCIRC Advisory FA-2000-02 Malicious HTML Tags Embedded in Client Web Requests
Note: Pages will open in a new browser window
External sites are not endorsed by CNN Interactive.
 LATEST HEADLINES:
SEARCH CNN.com
Enter keyword(s)   go    help

Back to the top   © 2001 Cable News Network. All Rights Reserved.
Terms under which this service is provided to you.
Read our privacy guidelines.