An online attack on the website of the General Secretariat of Shipping (shipping.gov.gr) with simultaneous alteration of the website took place a few hours ago. According to reports identified by SecNews editors on foreign forums, unknown individuals (probably foreigners judging by the posted messages)proceeded to add/alter an internal and central website with simultaneous posting of a message.
The hackers appear to have identified a vulnerability in the shipping.gov.gr website server , which allowed them to gain full administrator access to the server and add the altered content. Currently, anyone visiting the website sees the following content:

The server of the General Secretariat of Shipping appears to have been targeted by more than one hacker, since a few hours ago the website appears to have been taken over by someone else under the pseudonym "TrafiQuant" who had even made his contact e-mail address public (!).
However, it seems that other hackers have carried out a second attack where they are essentially targeting the first hacker (Trafiquant)!! It is worth mentioning that the profile of the attackers indicates low-tech hackers who use automated tools to identify exposed servers.
It is inconceivable, as security researchers who analyzed the attack tell us, that government websites in the gov.gr domain could be a playground for low-level hackers!!! Furthermore, until now the responsible administrators do not seem to have noticed the alteration.
The information systems of the General Secretariat of Shipping that were targeted, as we have found, are within the Syzefxis, which serves almost the entire Public sector, structured (at least theoretically) in accordance with all modern security requirements.
As we have mentioned many times in the past, Syzefxis as a provider DOES NOT essentially bear the responsibility of managing the servers of each entity but simply provides the means of access. Comprehensive care should be taken to ensure that at least the entities that manage sensitive personal data are protected, drawing on expertise from Syzefxis management executives who are appropriately trained and responsible for security issues.
The competent administrators of the General Secretariat of Shipping must IMMEDIATELY take the necessary measures and repair at a technical level the weaknesses used by the hackers to gain unauthorized access. The server that is indicated to have been attacked must be placed outside the network and thoroughly analyzed for digital evidence, in order to identify the exact way in which the intrusion was carried out and to expel the attackers in case they have penetrated other servers of the network under investigation. It seems that the attackers used a weakness in the Drupal administrative platform on which the website was created, as we can see from Google's cached results.
Stay tuned to SecNews, the reliable 24-hour information website on information systems security and cyber breaches.




