(联合早报网讯)资讯通信发展管理局已针对总理公署与总统府网站搜索功能分页遭入侵事件,展开调查。
与此同时,资信局正在进一步加强所有政府网站的安全,这可能导致网民有时无法登陆网站,资信局将尽快完成这项提升工程。
联合早报网报道,资信局刚刚发布文告说,总理公署网站分页于7日晚上11时17分,以及总统府网站分页于今天凌晨12时20分遭入侵。
资信局说,受影响的是进行搜索功能的分页。黑客是钻这些分页的“跨网站脚本”(cross-site scripting)的安全漏洞。资信局已对两起事件展开调查。
发言人说,两个网站并没有发现类似问题,资信局将尽快使受影响网页恢复正常。
资信局发言人说:“资信局将继续加强所有政府网站的安全。这将包括检测、弥补安全漏洞,以及提升软件。在这期间,用户可能会有时无法顺利登陆政府网站,我们将尽快解决这些问题。对此所造成的不便,资信局深表歉意。”
(联合早报网讯)周四晚上,总理公署网站的一个分页被黑客入侵。
资讯通信发展管理局(IDA)今天凌晨约1时30分许发表声明说,周四晚上11时17分,总理公署网站一个搜寻分页被攻击。
该网页被攻击后,显示其他来源的网页。不过,总理公署的主要网站仍然运作正常。目前事件正在调查中。
资信局说,这个分页出现了“跨网站脚本”(cross-site scripting)的安全漏洞。这样的安全漏洞,允许黑客在页面上放置另一种代码,其他用户在观看网页时就会受到影响。
法新社所捕捉到的分页截图照片显示,黑客在分页上放了印有“今天作为新加坡人,真好(It's great to be Singaporean today)”的字样,以及一个盖伊·福克斯(Guy Fawkes)面具的图样。
'Subpage' of the Prime Minister's Office website hacked; Investigations ongoing
A section of the Prime Minister's Office (PMO) website was hacked into late Thursday night.
The Infocomm Development Authority of Singapore (IDA) said in a statement at about 1.30am on Friday that "a subpage for search on the PMO website was reported to be compromised" on Thursday at 11.17pm.
"A vulnerability in that subpage was exploited to display pages from other sources. This vulnerability is known as cross-site scripting," said the IDA. "The PMO main website is still working, and we are working to restore the page that has been compromised. The matter is under investigation."
This latest cyber intrusion comes after hacktivists threatened to cripple Singapore's information technology infrastructure last week. On Wednesday, Prime Minister Lee Hsien Loong issued a warning, saying that the authorities will "spare no effort" to track down those who threaten to attack the country's computer networks and bring them to justice.
Published on Nov 08, 2013
The Straits Times
The Straits Times