Super Bowl stadium website hacked

Page embedded with exploit code

Written by Shaun Nichols in California

American Football fans looking for information on the Super Bowl in Miami may have found themselves with a nasty malware infection following a successful web attack on Friday. 

Dolphin Stadium, the venue for the game, had its website compromised and injected with exploit code, a stadium spokesman told vnunet.com

Advertisement

The attack was detected and removed within a few hours, and the site currently poses no danger to users.

Initial reports of the attack surfaced late on Friday morning, when security firm Websense notified stadium management that the front page of the site contained a malicious piece of JavaScript. 

The code attempted to exploit a pair of vulnerabilities that can allow for remote code execution.

The first, discovered in April 2006, affects Windows Data Access Components, and the second, disclosed in January 2007, affects Microsoft's Vector Markup Language component.

Both vulnerabilities have been patched by Microsoft, but users without the latest patches were susceptible to a Trojan application. 

The malware installed a key-logger to steal information and a backdoor to allow an attacker to remotely control a system.

Dolphin Stadium was this year's venue for the National Football League's Super Bowl, the most watched sporting event of the year in the US.

The stadium website had been experiencing heavy traffic from the tens of thousands of people attending the game, as well as NFL fans linked to the site through various official Super Bowl websites. 

The Indianapolis Colts won the NFL title with a 29-17 victory over the Chicago Bears.

Tags:

Further reading

Related whitepapers

Related jobs

Do you agree?

IT white papers

Search vnunet IThound

Top categories

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Watch

Shaun Nichols and Iain Thomson

10 Oct 2008

7.33 MBPodcast Special: Views from the Valley More...

Podcast image

09 Oct 2008

12.99 MBComputing podcast - IT implications of the banking crisis, and the FSA clamps down on IT security More...

Shaun Nichols and Iain Thomson

03 Oct 2008

6.49 MBPodcast Special: Views from the Valley More...

Poll

Google Android

Google Android

Are you intending to try out a Google Android mobile phone?

Previous poll results

Spotlight

Microsoft

Microsoft plans Silverlight 2.0 announcement

Web application tool revamp promised later today   More...

Stock prices

Security disclosures tip the stock market

Events such as Microsoft's Patch Tuesday could be used for...  More...

Blogs

Analyst predicts Web 2.0 fire sale

Prices for online apps could soon plummet, says Forrester   More...

MoD building

Latest data breach leads MPs to demand culture change

MoD admits to losing a hard drive containing up to...  More...

Primary Navigation