The site was hacked between Jan. 26 and 28, Websense reported, and until approximately 11 a.m. PST Friday was actively serving up a backdoor Trojan horse and password stealer.
The attacker planted a link to a malicious JavaScript file in the header of the front page of the site; that script executed when the official Dolphin Stadium site was rendered. Hubbard said that the script exploited two Windows vulnerabilities, one patched in April, the second last month.
By Friday morning, the malicious site hosting the JavaScript file has been taken down, although Hubbard said the link remained in the stadium's site header. He recommended that users stay away from the URL. "It's possible [the attackers] still have access to the server," he says.
Sunday, the Indianapolis Colts face the Chicago Bears in the National Football League's biggest game of the year. The Colts are favored by a touchdown.
Stay connected and informed by visiting the CA Solutions Center Community!

Become a member today for instant access to free InformationWeek research, expert advice, peer perspectives, and more on the following topics:
- Application Performance Management (APM)
- Security Management
- Mainframe 2.0
- IT Automation
- Service Assurance
Also, visit our Government and Financial Services groups to see how these technologies apply specifically to those industries.
NOTE: Offer valid for U.S., U.S. possessions, & Canada only.