Iran turmoil fuels 'hacktivist' attacks on websites
Last Updated: Friday, June 26, 2009 | 11:34 AM ET
The Associated Press
Supporters of reformist presidential candidate Mir Hossein Mousavi carry his poster during a rally in Tehran on June 15. (Kamran Jebreili/Associated Press) For about 90 minutes Wednesday, visitors to the Oregon university system's website found themselves taken for a ride they didn't ask for. They were redirected to another site under the control of a hacker, who posted an 89-word screed criticizing the protests in Iran.
"We never cheated in elections," the site read, in black and red. The message included invective aimed at U.S. President Barack Obama and made derogatory comments about Iranian opposition leader Mir Hossein Mousavi, who alleges his country's June 12 presidential election was rigged.
As internet attacks go, this type isn't uncommon, and the site was quickly restored to normal. The attack also didn't appear to harm visitors' machines: The site appeared to only serve up a political message rather than a computer virus, as some hacked sites carry. Very few people were likely affected, too, because the site averages fewer than 1,000 hits a day.
'Websites that aren't properly protected are like blank subway walls. Hackers can come by and spray their political messages.'— Graham Cluley, Sophos
What the incident shows, though, is how political turmoil can spill quickly into unexpected parts of the internet, as sites that have nothing to do with a conflict often get hijacked and turned into bully pulpits for so-called "hacktivists" bent on advancing a political cause, rather than making money.
"It's a bit like graffiti on the subway," said Graham Cluley, senior technology consultant with Sophos, a computer security software company. "Websites that aren't properly protected are like blank subway walls. Hackers can come by and spray their political messages."
The schism in Iran over the disputed presidential election has already led to a range of internet attacks. Some activists have been urging supporters to try to take down government sites with "denial-of-service" attacks, in which the sites are flooded with so much internet traffic that their servers buckle. Mounting those attacks can be relatively easy using widely available hacking programs.
That assault may be working: Many official Iranian sites are currently inaccessible, though it's unclear whether the outages are hacking-related.
For its part, Iran has employed filtering technology to restrict what sites people in the country can visit.
Global trend
The incident at the Oregon university system, which oversees Oregon's seven public universities, is just one example of what happens repeatedly whenever a political conflict flares these days. The war in Iraq, fighting in Israel, the Beijing Olympics and the Russia-Georgia conflict all saw examples of hackers commandeering sites to push their political message.
Sites that are hacked in this way aren't necessarily targeted for their political affiliations. Instead, hackers seek them out because of security vulnerabilities in their computer networks. Those vulnerabilities can be simple to find with automated tools hackers have built to sniff out weaknesses in websites' programming code.
Figuring out the culprits is usually very hard, sometimes impossible, because it's easy to cover your tracks online.
Figuring out the culprits is usually very hard, sometimes impossible, because it's easy to cover your tracks online. And unless the hackers leave some kind of hint that they're associated with a larger criminal gang, there's little chance law enforcement will get deeply involved.
"More and more people are kind of thinking this is acceptable behaviour on the internet," Cluley said. "If you're clever and smart and don't do something dumb, your chances of getting caught are probably quite small."
Diane Saunders, spokeswoman for the Oregon university authority, said the school system was analyzing computer files for clues about who might be responsible. She said the hackers were able to access the site through a vulnerability in third-party software that tracks the number of visitors to the site. That vulnerability has now been fixed.
In many cases, major world events give online criminals a great opening to try and lure more victims into garden-variety internet swindles.
Alan Paller, director of research for the SANS Institute, a computer security training organization, said hundreds of fake websites spring up after every big news event to try and fool people into coughing up their money or personal data, or both. Sometimes they'll take the form of fake Red Cross sites, for example, that solicit donations.
The perpetrators are really good at making fake sites look real. They're also relentless advertisers: Spam volumes also surge after a big news event, with crooks trying to direct victims to sites that will infect their computers.
Paller says the effectiveness of those campaigns "is almost entirely determined by how well they exploit current news stories" and craft provocative headlines to sucker somebody into clicking on the link.
The hackers behind the attack on the Oregon university system's website got noticed — for 90 minutes at least.
Share Tools
Top News Headlines
- Everest victim's husband says family not seeking government help
- The husband of a Toronto woman who died trying to climb Mt. Everest on Saturday says his family is not seeking government help to cover the cost of bringing his wife's body home. more »
- B.C. premier unhappy with disgraced Mountie's transfer
- B.C. Premier Christy Clark says she is not happy with the RCMP decision to transfer a disgraced Alberta Mountie to the West Coast. more »
- Henrique's OT goal sends Devils into Stanley Cup final
- The New Jersey Devils will vie for a potential fourth Stanley Cup in franchise history after defeating the New York Rangers in six games in the Eastern final, courtesy of rookie Adam Henrique's goal early in overtime. more »
- Employment Insurance review boards to be scrapped
- The federal government is scrapping two review boards used by people appealing decisions made about their employment insurance. more »
Latest Technology & Science News Headlines
- Unloading of docked SpaceX capsule to start Saturday
- The privately bankrolled SpaceX Dragon capsule made a historic arrival at the International Space Station on Friday, and astronauts will begin unloading some of the 544 kilograms of food, water, clothing and other supplies its carrying starting Saturday.
more »
- South Africa, Australia to share world's largest telescope
- South Africa and Australia will jointly host the Square Kilometre Array, which promises to be the world's largest telescope, the international consortium in charge of the project said Friday. more »
- Bonavista, N.L., 'coyote' was really wolf, tests confirm
- Wolves have not been seen in Newfoundland since around 1930 and were believed to have been hunted to extinction on the island, but genetic tests have confirmed that an 82-pound animal shot on the Bonavista Peninsula in March was, in fact, a wolf. more »
- Once-rare argus butterfly thriving thanks to climate change
- Global warming is threatening the existence of many species, such as the giant polar bear, but in the case of Britain's brown argus butterfly, it took a species in trouble and made it thrive. more »
- Yahoo scraps digital magazine designed for iPad
- Yahoo has killed Livestand, a tablet magazine, just six months after its debut on the iPad. more »
Bob McDonald's Blog
Government to shut down unique fresh water research area May. 25, 2012 12:31 PM The Experimental Lakes Area research facility in Northern Ontario is being closed down after 44 years of providing invaluable data to scientists in Canada and internationally, a decision that has stunned researchers and environmental groups.
Quirks & Quarks
- May 26: Before the Lights Go Out May. 25, 2012 4:15 PM A new book, "Before the Lights Go Out: Conquering the Energy Crisis Before It Conquers Us", suggests that the unpredictable, unplanned, ad-hoc way our energy use developed in the past will shape our energy future.
Latest Features
- Aylmer triple stabbing leads to first-degree murder charges
- Everest victim's husband says family not seeking government help
- Reclaiming the dead on Mt. Everest
- Employment Insurance review boards to be scrapped
- Teens share bullying tales in confession booth
- Canada ending 'Buffalo shuffle' for visas, closing consulate
- Brave cat makes epic leap of faith
- What a Greek euro exit could mean for Canada
- Double-lung recipient dances on Ellen show

