Auncle Lee Hsien Loong, ho sei bo!!!!! Enjoy!
PMO, Istana sites 'compromised'
Curious? Clicked? Your PC may be
infected
Reports by RONALD LOH
Were you one of those who were curious about the images which appeared on subsites of the Prime Minister's Office and the Istana?
Did you click on the URL posted on some forums?
Well, your computer may now be infected with malware or viruses, said the Infocomm Development Authority (IDA) yesterday.
Between 11pm on Thursday and 12.20am on Friday, hackers created an alpha-numeric code which, when pasted on a search engines of the two sites, led to pictures posted by the hackers (See other report.)
But IDA said the two subpages were removed within 15 minutes and they are taking measures to strength all government websites.
This comes after an alleged call by the hacker collective Anonymous to mark Nov 5 with a protest.
On that day, a spike in hacking activity showed up on IDA's radar.
Despite unusually high traffic to many government websites on Nov 5, IDA said there were no successful cyber intrusions or denial-of-service attempts on both transactional and non-transactional government sites.
But even a hacking attempt is illegal and could be punishable under the Computer Misuse and Cybersecurity Act, said criminal lawyer Rajan Supramaniam.
"Once you make an attempt, there is an intention to hack. If you're traced and caught, you have to be prepared to face the consequences," he said.
Last week, Anonymous allegedly threatened to bring down Singapore's infrastructure in a show of protest against the Internet licensing framework.
On Wednesday, Prime Minister Lee Hsien Loong said the Singapore Government "will spare no effort to track down" anyone who attempts to bring down the Republic's cyber infrastructure.
Cyber security experts told The New Paper on Thursday that a lot of resources are needed to track down these hackers.
But experience shows it can be done despite sophisticated tactics empolyed by hackers to cover their tracks.
Mr Alex Nian, manager of IT firm SecureIT-NET, said hackers usually gather networks of infected computers - known as botnets - by hacking into PCs and installing malware in them.
They then use botnets to carry out hacking activities, such as denial-of-service - making a network/service unavailable to users by diverting a high amount of traffic to the website - or remotely controlling the botnets to hack into government servers.
VIRAL VIDEO
They could have even used an infected computer to upload the video, which went viral last week.
These infected PCs could be all over the world, and locating them will be difficult, said Mr Nian.
"Our Government would have to seek permission from the country's Internet Service Providers to get the IP address of these overseas computers. Their request could take a while to be processed.
"The request could even be rejected due to privacy laws,"he said.
There would also be no guarantee the original computer can be traced, he said.
Is it worth the effort to track them down?
Yes, said political analyst Eugene Tan, a Singapore Management University law professor.
"It would send a strong signal that our Government has the resolve and also to deter future perpetrators," he said.
Given that cyber attacks have now become a transnational crime, there is a greater need for countries to work together, said cyber security expert Eric Chan, Fortinet's regional technical director for South-east Asia and Hong Kong.
An example would be Singapore's initiative to set up a cybercrime working group at the 9th Association of South East Asian Nations (ASEAN) Ministerial Meeting on Transnational Crime in September.
Regional law enforcement agencies will then have a special platform to discuss strategies to fight cybercrime.
Said Mr Chan: "The Internet is without borders and cyber criminals often reside outside the country where the attacks take place."
"Cooperation among international authorities is extremely important in bringing cyber criminals to justice, and that's where organisations like Interpol and Asean can play a part."
"The PMO's website incident was a result of a typical cross-site scripting where the cyber criminal exploited the 'search' function on the website, and injected content from external sources. In this particular instance, the cyber criminal had redirected the URL to the criminal's intended image.
- Software security firm Trend Micro spokesman saying it's not a hack
'Compromise' explained
A subpage of the Istana and Prime Minister's Office (PMO) websites each were compromised on Thursday night and yesterday morning, said the Infocomm Development Authority (IDA).
In a statement released yesterday, IDA said authorities detected a "compromise" in a subpage of the PMO website at about 11.15pm on Thursday. A similar "compromise" was detected in the Istana's page just after midnight yesterday.
The affected subpages were taken down within 15 minutes, said IDA. It said that both main websites remained functional.
"There was a vulnerability in the search engine function of both websites," said Mr James Kang, IDA's assistant CEO.
First, the hacker created images of the PMO and Istana's websites using components of both pages and his own images, said IDA.
He then exploited the vulnerability in the websites' search engine to direct people to the image, which IDA said does not belong to the main website.
It is believed screenshots of the two images were also shared on forums.
The matter is under investigation by IDA and the police.
Meanwhile, IDA said it is strengthening all government websites.
This includes checking of vulnerabilities and software patching.
IDA also said it received an unusually high number of denial-of-service attempts on Tuesday but said there were no successful cyber intrusions.
News, The New Paper, Saturday, November 9 2013, Pg 6
Originally posted by Genie99b:Thanks Mr Leelee. It is indeed inspiring to see such patriotism in a fellow sg
Just a few doubts that I was hoping you could clarify for me.
Did the hacker threaten to attack essential infrastructure of sg?
Were you able to access the internet? Had your credit card details stolen maybe…encountered traffic lights that were behaving wierdly…omg I hope no one was injured. Most important of all, your TV working right?
Cos I read that it was mostly .gov.sg websites that were down for maintenance. You know the usual router issues. It was all too sudden so they had no time give any notice. The poor chaps must have OT to replace the router.
Well rest assured the govt will indeed protect our essential infrastructure. Our TV by god the nerve these scoundrels have.
Off to school now got to study hard so you can contribute and protect our essential infrastructures in future.
think kackers go for banking infrastructure.probably route the ip addy to antarctica even...
Can visiting hacked websites give you computer virus? ![]()
Originally posted by charlize:Can visiting hacked websites give you computer virus?
visiting gov.sg sites can kena virus.
sg so scary.
![]()
Originally posted by Clivebenss:visiting gov.sg sites can kena virus.
sg so scary.
Originally posted by Shorter ninja:
This country is full of lies!
more scary then.
![]()
AHAHAHAHAHAHAHAHAHAHAHAHA!!! ![]()
Originally posted by Clivebenss:more scary then.
Originally posted by Shorter ninja:
This country is so teruk but because we have Malaysia next door we are totaly camouflaged>hahahaha
![]()
Did they get another $2 company to set up their cyber defence ?
The guy in charge say that he will spare no effort to hunt down the Messi.
I rather he spend more effort in solving the problem at his backyard - mrt breakdown, ponding, local - FT disparity.
![]()
![]()
![]()
![]()
spf posting such vague message to save face like PAP govt???
All bo lor yong! Jiak liao bee!
TR Emeritus (TRE) has been informed that a James Raj is being investigated for offences under the Computer Misuse Act in connection with the recent website hacking incidents in Singapore.
Noted lawyer M Ravi will be representing the accused in court tomorrow (12 Nov).
According to Mr Ravi, the accused has been reprimanded since last week. The police have denied the accused access to his lawyer, Mr Ravi, however. Mr Ravi will only be meeting James for the first time tomorrow when he will be charged in court.
Mr Ravi was informed only this morning (11 Nov) that James had asked for Mr Ravi to represent him.
James is believed to have been found in possession of some sort of hacking device or devices.
It is not known if James is connected to “The Messiah”.
James will be charged in Court 26 tomorrow morning at 9am. He is currently still in police custody.
Separately, a Mr Faizal Mohd has also engaged Mr Ravi for a case of vandalism.
Mr Faizal was said to have sprayed the word “Anonymous” in a school and is being investigated for any links with the hacktivist group, Anonymous.
More updates will be provided when TRE hears of anything.
Not sure they anyhow arrest James Raj as scapegoat or not?
The police denied access James Raj to his lawyer, Mr Ravi. I believe if the accused hacker is Lee hsien loong's son, sure police will allow his son to meet lawyer.
SPF works for PAP govt in Singapore , the rest of us citizens are just nothing to them. SPF another group under PAP is jiak liao bee!! They like to skive. Go round coffee shops lim kopi.
KNN! waste our taxpayers' money on these jiakliaobee govt and their contingencies of boloryong.
Ya lorh
Hacking won't happen if we don't have PAP govt making life difficult for us.
PAP asks for it.
Faizal kena when he sprayed Anonymous. What about when we use the word Anonymous, are they going to arrest us?
PAP creating lots of mess for sg citizens and this country. There is no end to this doing of theirs. They have to be gotten rid off.
James will be charged in Court 26 tomorrow morning at 9am. He is currently still in police custody.
anyone going?
Originally posted by Summer hill:James will be charged in Court 26 tomorrow morning at 9am. He is currently still in police custody.
anyone going?
Are you going? Reallly not sure how credible is their finding. May be they anyhow arrest someone to cool the damn bloody ah kua Lee Hsien Loong and gang .
Anyone can have the hacking device. Just like if you are pregnant you must be a married lady, this kind of crap.
Originally posted by SJS6638:Are you going? Reallly not sure how credible is their finding. May be they anyhow arrest someone to cool the damn bloody ah kua Lee Hsien Loong and gang .
Anyone can have the hacking device. Just like if you are pregnant you must be a married lady, this kind of crap.
no, i'll be at school tomorrow from 8am to 11am. no chance.