WHID 2008-39: Hacker compromises a south african political party web site

Attack Information
WHID ID: 
2008-39
Date Occured: 
7 Aug 2008
Attack Method: 
Outcome Information
Outcome: 
Target Information
Attacked Entity Field: 
Government
Attacked Entity Geography: 
South Africa
Attacked System's Technology: 
WordPress
Source Information
Attack Source Geography: 
Russia

The South African Democratic Alliance party's web site seems like another random victim of the Asprox family of bots. This specific incident demonstrates several issues:

  • Aprox successfully attacks organizations that should really know better.
  • While most known cases of Asprox attacks result in planting of malware on the web site, since this is easily detected by malware search services, the very brutal injection used by Asprox probably takes down more sites than it infects with malware.
  • According to one comment, the site used an outdated version of WordPress, stressing again the problem with not upgrading in a timely manner, especially open source software.

More information: