英国学术网站被劫持销售假药
文章来源:未知 文章作者:meng 发布时间:2010-03-07 05:46 字体: [ ]  进入论坛
(单词翻译:双击或拖选)

UK academic institutions have unwittingly become the accomplices1 of criminals selling fake drugs online.

英国某学术机构在毫不知情的情况下成为犯罪分子在网上销售假药的帮凶。

Servers were used to bounce people on to fake <a href=pharmacy2 sites" width="226" height="170" src="/upimg/100307/4_063406_1.jpg" />
Servers were used to bounce people on to fake pharmacy sites

A security firm has discovered many organisations using the .ac domain3(域名,领域) are unknowingly pushing customers to websites offering the fake pills.

The scam(骗局,诡计) exploits software flaws to piggyback(背负式装运) on the computing4 resources of the colleges and universities.

Researchers at security company Imperva believe "thousands" of organisations may have fallen victim.

"It's a pretty successful campaign," said Amichai Shulman, of the firm, which uncovered the targeted attack.

Drug search

Imperva has found that many higher education institutions that use the .ac.uk domain are unknowingly helping5 customers get through to the spammers'(垃圾邮件制作者) sites.

In most cases, said Mr Shulman, the spammers have exploited vulnerabilities in a widely used technology called PHP. Many organisations use this technology to make websites more interactive6.

"They used these vulnerabilities to inject PHP code into the site," said Mr Shulman.

The injected code included search terms associated with drugs such as Viagra(伟哥) , Cialis(西力士,壮阳药) and many others. Also included was code that spotted7 when a visitor arrived at a compromised site from Google.

When combined, the code meant that when a person searched for in the drugs online, the universities and colleges web addresses would pop up in the top results. Anyone clicking on the link would then be re-directed to a fake pharmacy peddling8(叫卖) counterfeit9 pills.

At all other times a visitor would get through to the proper site. Typing in a web address would also lead straight to the real site.

"It's difficult to detect sometimes if you just type the link in your browser10 you get the original content," said Mr Shulman.

The criminals use the technique of piggy backing on legitimate11(合法的,正当的) sites to ensure that their websites show up in search engine results.

Mr Shulman said the speed with which sites were being put up and taken down made it hard to get an exact figure for how many sites had been hit. However, he estimated that "thousands" of sites, including many universities and colleges, had been caught out by the drug spammers.

Ravensbourne College of Design and Communication in Kent was one school that fell victim.

"We immediately took action to temporarily close down and remove the compromised area while we resolved the issue," said a spokeswoman for the college in a statement.

"Once we discovered the issue we were able to rectify12(改正,整顿) it quickly, and we believe our site is now secure," she said.

"Some issues - such as the change to the search result text - may still appear on search results while we wait for the search engines to re-crawl the website."



点击收听单词发音收听单词发音  

1 accomplices d2d44186ab38e4c55857a53f3f536458     
从犯,帮凶,同谋( accomplice的名词复数 )
参考例句:
  • He was given away by one of his accomplices. 他被一个同伙出卖了。
  • The chief criminals shall be punished without fail, those who are accomplices under duress shall go unpunished and those who perform deeds of merIt'shall be rewarded. 首恶必办, 胁从不问,立功受奖。
2 pharmacy h3hzT     
n.药房,药剂学,制药业,配药业,一批备用药品
参考例句:
  • She works at the pharmacy.她在药房工作。
  • Modern pharmacy has solved the problem of sleeplessness.现代制药学已经解决了失眠问题。
3 domain ys8xC     
n.(活动等)领域,范围;领地,势力范围
参考例句:
  • This information should be in the public domain.这一消息应该为公众所知。
  • This question comes into the domain of philosophy.这一问题属于哲学范畴。
4 computing tvBzxs     
n.计算
参考例句:
  • to work in computing 从事信息处理
  • Back in the dark ages of computing, in about 1980, they started a software company. 早在计算机尚未普及的时代(约1980年),他们就创办了软件公司。
5 helping 2rGzDc     
n.食物的一份&adj.帮助人的,辅助的
参考例句:
  • The poor children regularly pony up for a second helping of my hamburger. 那些可怜的孩子们总是要求我把我的汉堡包再给他们一份。
  • By doing this, they may at times be helping to restore competition. 这样一来, 他在某些时候,有助于竞争的加强。
6 interactive KqZzFY     
adj.相互作用的,互相影响的,(电脑)交互的
参考例句:
  • The psychotherapy is carried out in small interactive groups.这种心理治疗是在互动的小组之间进行的。
  • This will make videogames more interactive than ever.这将使电子游戏的互动性更胜以往。
7 spotted 7FEyj     
adj.有斑点的,斑纹的,弄污了的
参考例句:
  • The milkman selected the spotted cows,from among a herd of two hundred.牛奶商从一群200头牛中选出有斑点的牛。
  • Sam's shop stocks short spotted socks.山姆的商店屯积了有斑点的短袜。
8 peddling c15a58556d0c84a06eb622ab9226ef81     
忙于琐事的,无关紧要的
参考例句:
  • He worked as a door-to-door salesman peddling cloths and brushes. 他的工作是上门推销抹布和刷子。
  • "If he doesn't like peddling, why doesn't he practice law? "要是他不高兴卖柴火,干吗不当律师呢?
9 counterfeit 1oEz8     
vt.伪造,仿造;adj.伪造的,假冒的
参考例句:
  • It is a crime to counterfeit money.伪造货币是犯罪行为。
  • The painting looked old but was a recent counterfeit.这幅画看上去年代久远,实际是最近的一幅赝品。
10 browser gx7z2M     
n.浏览者
参考例句:
  • View edits in a web browser.在浏览器中看编辑的效果。
  • I think my browser has a list of shareware links.我想在浏览器中会有一系列的共享软件链接。
11 legitimate L9ZzJ     
adj.合法的,合理的,合乎逻辑的;v.使合法
参考例句:
  • Sickness is a legitimate reason for asking for leave.生病是请假的一个正当的理由。
  • That's a perfectly legitimate fear.怀有这种恐惧完全在情理之中。
12 rectify 8AezO     
v.订正,矫正,改正
参考例句:
  • The matter will rectify itself in a few days.那件事过几天就会变好。
  • You can rectify this fault if you insert a slash.插人一条斜线便可以纠正此错误。
发表评论
请自觉遵守互联网相关的政策法规,严禁发布色情、暴力、反动的言论。
评价:
表情:
验证码:点击我更换图片