Someone has compromised the free-speech, anti-surveillance repository Cryptome.org and hid malware on the site that infected web surfers over the weekend, Cryptome.org reported.
A malicious PHP file was added to the site on Wednesday and a new directory was created that logged nearly 3,000 IP addresses between Wednesday and Sunday, according to a post on the site on Monday.
The Cryptome post said thousands of HTML files in the site's main directory were found to be contaminated with a malicious script that appeared to download exploits from the Blackhole Toolkit "that may compromise a computer though various vendor vulnerabilities", according to a Symantec description of the attack. This affects Windows platforms, Symantec says. Symantec had offered to investigate the hack, Cryptome.org added.
Meanwhile, Cryptome.org's post said the site was expected to be cleaned up by the end of Monday.
This story originally appeared as Cryptome.org hacked--and inadvertently spreads infection on CNET News.
Get the latest technology news and analysis, blogs and reviews delivered directly to your inbox with ZDNet UK's newsletters.







