Team-BHP > Shifting gears


Reply
  Search this Thread
5,895 views
Old 27th October 2021, 08:56   #1
BHPian
 
Brumby's Avatar
 
Join Date: Jun 2017
Location: City of Lakes
Posts: 219
Thanked: 782 Times
Isuzu India's website hacked?

While searching for an off-road vehicle (specifically a jeep body) I checked the Thar and the Gurkha and then I thought about checking the Isuzu V-cross as well.

I was surprised to see that the Isuzu India website does not allow me to browse without updating the "Chrome browser" or the "Firefox".

I tried Safari, Brave, Chrome and Firefox with same results.

I am clueless about what Isuzu India wants the visitors to their website to do.

Some screen shots:
Attached Thumbnails
Isuzu India's website hacked?-screen-shot-20211027-8.30.04-am.png  

Isuzu India's website hacked?-screen-shot-20211027-8.29.24-am.png  

Isuzu India's website hacked?-screen-shot-20211027-8.28.52-am.png  

Isuzu India's website hacked?-screen-shot-20211027-8.28.26-am.png  

Brumby is offline   (18) Thanks
Old 27th October 2021, 19:59   #2
Team-BHP Support
 
moralfibre's Avatar
 
Join Date: Dec 2004
Location: MH-12
Posts: 8,476
Thanked: 14,081 Times
re: Isuzu India's website hacked?

Brumby, perhaps your PC needs an AV scan to find malware on it. The website will work fine for everyone else. This is a local issue and doesn't require Isuzu to do anything.
moralfibre is offline   (7) Thanks
Old 28th October 2021, 07:58   #3
BHPian
 
Brumby's Avatar
 
Join Date: Jun 2017
Location: City of Lakes
Posts: 219
Thanked: 782 Times
re: Isuzu India's website hacked?

Quote:
Originally Posted by moralfibre View Post
Brumby, perhaps your PC needs an AV scan to find malware on it. The website will work fine for everyone else. This is a local issue and doesn't require Isuzu to do anything.
I am using a Macbook Air with a paid total security AV from Norton with scan set to automatic.

The problem is that irrespective of the kind of browser used, its asking to update chrome, even on my android phone the issue was there. For Firefox browser the website asked to update Firefox.

On my android phone I have checked the following browsers with similar issue:
Brave
Edge
DuckDuckGo
Firefox

The issue did not show up when I used Tor browser on my android phone.

Hope I am not having some serious issue on my laptop or some digital threat with my ISP.

To verify, I just now checked the website on windows 10 with McAfee paid AV using Firefox browser and the website asked me to update Firefox

I just want to understand that when I am not using Chrome while browsing the website, why should I update chrome.
Attached Thumbnails
Isuzu India's website hacked?-screen-shot-20211028-7.48.06-am.png  


Last edited by Brumby : 28th October 2021 at 08:11.
Brumby is offline   (11) Thanks
Old 28th October 2021, 08:36   #4
GTO
Team-BHP Support
 
GTO's Avatar
 
Join Date: Feb 2004
Location: Bombay
Posts: 71,191
Thanked: 306,469 Times
Re: Isuzu India's website hacked?

I see the same on my computer & so does Chetan_Rao. It does appear that their website is compromised.

Please don't click on that button .
GTO is offline   (18) Thanks
Old 28th October 2021, 10:37   #5
BHPian
 
Prowler's Avatar
 
Join Date: Jul 2008
Location: Madras
Posts: 783
Thanked: 1,373 Times
Re: Isuzu India's website hacked?

Quote:
Originally Posted by Brumby View Post

I just want to understand that when I am not using Chrome while browsing the website, why should I update chrome.
The site is based on WordPress CMS. Wordpress sites unless diligently updated and 'fixed' regularly have vulnerability issues.
The site as of now pulls up a popup page asking you to click on a link which may install a Trojan to susceptible browsers.
I tried to run the script in a sandboxed browser and it didn't take the bait. Just wanted to see what it's payload is.

Unless you click on the Update link, you don't need to worry about any issue.

It is about time Isuzu fixed this.
Prowler is offline   (6) Thanks
Old 28th October 2021, 11:19   #6
Senior - BHPian
 
skanchan95's Avatar
 
Join Date: Jul 2010
Location: Mangalore KA-19
Posts: 1,285
Thanked: 5,584 Times
Re: Isuzu India's website hacked?

I am getting in the same popup. IF one moves the mouse on the Green "Update Chrome" button - the link shown is "https://www.isuzu.in/universalpopup/update.php" ( marked in Red).
Isuzu India's website hacked?-1.jpg

This probably will install some malware on your PC, if clicked. If it indeed was a Google Chrome update, the link should have been a google chrome link, and not Isuzu Update link.
skanchan95 is offline   (5) Thanks
Old 28th October 2021, 11:51   #7
Senior - BHPian
 
sandeepmdas's Avatar
 
Join Date: Feb 2005
Location: Varkala
Posts: 1,550
Thanked: 2,599 Times
Re: Isuzu India's website hacked?

The website is indeed using WordPress, but the version it uses is the latest: 5.8.1

I clicked the popup (Linux guy here), and it tried to download an executable file, install.exe. Ubuntu then warned me that the download contains "either a virus or malware".
Attached Thumbnails
Isuzu India's website hacked?-screenshot-20211028-115322.png  


Last edited by sandeepmdas : 28th October 2021 at 12:06.
sandeepmdas is offline   (20) Thanks
Old 28th October 2021, 15:12   #8
BHPian
 
Brumby's Avatar
 
Join Date: Jun 2017
Location: City of Lakes
Posts: 219
Thanked: 782 Times
Re: Isuzu India's website hacked?

Whenever I experience such incidents, I wonder whether there are any people designate by the companies to look after such affairs and how much importance do they give to their digital face.

The company's website is its digital interface for the customers and Isuzu, by no means is an organisation which should overlook such basic stuff.

The worst was an experience with Axis bank. A mail sent to the email address of ombudsman (given in their website) bounced
Brumby is offline   (7) Thanks
Old 28th October 2021, 20:24   #9
BHPian
 
Join Date: May 2019
Location: Trivandrum
Posts: 77
Thanked: 467 Times
Re: Isuzu India's website hacked?

Quote:
Originally Posted by sandeepmdas View Post
I clicked the popup (Linux guy here), and it tried to download an executable file, install.exe. Ubuntu then warned me that the download contains "either a virus or malware".
Adding a tip for checking suspicious files.

If you have downloaded a file and want to be sure it's clean before running it, then scan it using virustotal.com. Virustotal scans the uploaded file/link using 60+ Antivirus scanners. Virustotal is owned by Google since 2012.

There are other similar websites too, more on them here.

Would be interesting to see what it has to say about install.exe!

As a rule, you shouldn't click on banners or pop-ups with links which say your computer is infected or your browser is outdated. Oh! and never enable macros on Office(Excel, Word) files downloaded off the internet unless you are very very sure they are safe.

Edit: Site seems to be fine now.
Google has a facility for reporting websites with malicious software (Click here) and also phishing sites (click here). In addition you can also check the status of a suspicious page - click here.
BTW i don't work for Google, i wouldn't mind it though, hey Sergey! you hear me?

Last edited by vik99 : 28th October 2021 at 20:49. Reason: added links
vik99 is offline   (14) Thanks
Old 28th October 2021, 22:25   #10
Senior - BHPian
 
sandeepmdas's Avatar
 
Join Date: Feb 2005
Location: Varkala
Posts: 1,550
Thanked: 2,599 Times
Re: Isuzu India's website hacked?

Quote:
Originally Posted by vik99 View Post

Would be interesting to see what it has to say about install.exe!
In fact, I somehow controlled the itch to "test drive" the EXE, you won't get a juicy malware everyday. But meeting a deadline is paramount as you know.

I had to let it go.
sandeepmdas is offline   (3) Thanks
Old 31st October 2021, 08:31   #11
BHPian
 
Join Date: May 2019
Location: Trivandrum
Posts: 77
Thanked: 467 Times
Re: Isuzu India's website hacked?

Quote:
Originally Posted by Brumby View Post

I am clueless about what Isuzu India wants the visitors to their website to do.
Google seems to have blacklisted malicious URLs on the website...Isuzu India's website hacked?-screenshot_20211031081523361_com.google.android.gm.jpg

Folks receiving email updates on this thread are being shown this message.
vik99 is offline   (3) Thanks
Old 1st November 2021, 12:39   #12
BHPian
 
ambarkhan's Avatar
 
Join Date: Apr 2021
Location: Pune
Posts: 102
Thanked: 729 Times
Re: Isuzu India's website hacked?

Isuzu India is using a CMS(Content management System ) Wordpress(approx 40% websites on internet are built on same platform). It is a very easy platform to start with and very robust for many use cases in future.

Because of easy of use, many websites are deployed using it and often, not very competent people are behind such deployments. End result is websites with default or poor security settings.

Also there are many free tools/scripts are available on internet to exploit such omissions.
I assume that was the case what happened on their website. I saw at least one issue just before typing this.
ambarkhan is offline  
Old 1st November 2021, 14:12   #13
BHPian
 
veyron_head's Avatar
 
Join Date: Aug 2009
Location: Bangalore
Posts: 592
Thanked: 716 Times
Re: Isuzu India's website hacked?

But which nutjob hacked Isuzu's website,of all ?! What do they even plan to gain!
veyron_head is offline  
Old 2nd November 2021, 06:49   #14
BHPian
 
Join Date: May 2019
Location: Trivandrum
Posts: 77
Thanked: 467 Times
Re: Isuzu India's website hacked?

Quote:
Originally Posted by veyron_head View Post
But which nutjob hacked Isuzu's website,of all ?! What do they even plan to gain!
This targets visitors to the website.

The attack on the website is a stage in a multi stage attack. Once a visitor to the website runs the malicious executable, the attackers would gain control over the visitor's computer. This would give them access to the victim's personal data and the ability to launch further attacks.

Imagine the possibilities for the attackers if they were to compromise the system admin of a bank this way or just the computer of someone who frequently uses internet banking.

Once a visitor to the website runs the malicious executable (masquerading as a Google Chrome update), the only thing that can save him is if he or she has an AV installed which can detect this executable as malicious. Even that is not foolproof as the bad guys often test their wares to ensure AVs don't detect them.
vik99 is offline   (1) Thanks
Old 2nd November 2021, 09:44   #15
BHPian
 
veyron_head's Avatar
 
Join Date: Aug 2009
Location: Bangalore
Posts: 592
Thanked: 716 Times
Re: Isuzu India's website hacked?

Quote:
Originally Posted by vik99 View Post
This targets visitors to the website.

The attack on the website is a stage in a multi stage attack. Once a visitor to the website runs the malicious executable, the attackers would gain control over the visitor's computer. This would give them access to the victim's personal data and the ability to launch further attacks.
I understand the rationale behind hacking. Was just wondering why they would do that to Isuzu's website which will hardly get visitors, compared to a Maruti or Hyundai.
veyron_head is offline   (1) Thanks
Reply

Most Viewed
Thread Tools Search this Thread
Search this Thread:

Advanced Search

Copyright ©2000 - 2024, Team-BHP.com
Proudly powered by E2E Networks