02/06/2014
Kochi: The official website of the Kochi Metro Rail Corporation was hacked by a group which calls itself ‘ReZk2LL team’, in the wee hours of Monday. The hackers also uploaded a picture of the Palestinian flag along with anti-Israeli posts to indicate that the site, www.kochimetro.org had been hacked.
The message uploaded by the hackers read: “To the ignorant observer Israel may appear modern, vigorous and democratic largely thanks to the outrageous bias in Western media and the $$$ wh**es who have become our leaders…now wake up!!!”
Although officials first thought it was an ‘overseas’ job, done by experts from abroad, it was later learnt that it was the handiwork of hactivists in Kerala. The website had been hosted by the State Data Centre. The hack, despite being a minor one, has posed worries over the security offered by the Centre for Development of Imaging Technology (C-DIT) for government websites.
However, C-DIT officials said the matter was under control and the website would be back to normal soon. But, it is learnt that it will take at least a month to decrypt and reset the hacked website. The Kochi Metro Rail Corporation has lodged a complaint with the cyber police.
It has also asked the IT Mission and C-DIT to probe the incident and take appropriate action. The weak security features of government websites in India has been an issue of concern ever since hackers from abroad started targeting it. It’s been noticed that websites with .gov.in and .org as suffixes are the sites most vulnerable to hacker-attacks.
Kerala websites are hackers’ favourite
Thiruvananthapuram: A few months ago the Computer Emergency Response Team - Kerala conducted a security audit of the 200-odd websites of state government departments and organisations and found that many sites and online applications were vulnerable to cyber attacks. The CERT-K also submitted a set of recommendations on enhancing the security features of the websites and web-based applications to agencies maintaining those sites.
Incidentally, CERT-K, an agency under the Kerala State IT Mission, had found that the website of the Kochi Metro Rail Corporation that has now suffered a cyber attack was among the sites found to be vulnerable to such attacks.
During the last 15 months, 81 government websites were hacked and the cyber attacks on government websites are on the rise. Almost all the illegal intrusions had taken place from foreign countries like Pakistan, Switzerland and Turkey. Hence the state had little scope in the bringing the hackers before the law.
With the government foraying more and more into e-governance and online payments, the security of government websites assumes more importance. A majority of government websites are maintained by government agencies like Centre for Development of Imaging Technology and National Informatics Centre.
To ensure the security of government websites, the Kerala State IT Mission had directed the state data centres that only those websites and web-based applications that had undergone the prescribes security audit in accordance with the procedures laid down by Standardisation Testing and Quality Certification directorate under the Central IT Ministry should be hosted in the data centre. The CERT-K also conducts security audit of the sites periodically to ensure cyber security. Most of the sites that were hit by cyber attacks were developed on the Joomla software platform, sources point out.
Till a directive from the Ministry of IT in 2010 that all government websites should be hosted only in government servers, many key websites were hosted even in foreign or private servers. At present a majority of government websites are hosted in the State Data Centre at Co-Bank Towers in the state capital, while some of the new websites are hosted at the New State Data Centre at Technopark.
IT Department sources said that while the new state data centre had enhanced security features, the old data centre did not have much advanced security features. More than one hundred websites and web-applications are hosted at the old data centre.
Any illegal intrusion from cyber space to the state data centres, which are repositories of the key data pertaining to the state, may have serious implications. Hence it is high time the
government ensured a foolproof security of the websites, especially while venturing into e-payments in a massive way.