Related Links

Related Stories

  • Google users targeted by new malicious websites
    Network security company eSoft’s threat prevention team has discovered new malware sites specifically targeting users of Windows operating system and Google.
  • Zero Day of the Dead
    The data load that has accompanied the globalization of trade would make even Atlas stagger. And that’s without the added burden of counter-terrorisAs you read this, zombie programs are flitting across the internet like a pestilence to infect and drain the life from innocent computer systems. Yet, for all the aggravation and grief they cause, you may never know you are part of a global invasion of the system snatchers, says William Knight. Unless…
  • The battle of the internet browsers
    Browsers are the hackers’ window into your PC – but how are they compromised, and what are vendors doing to harden them? Danny Bradbury examines the techniques vendors are employing, and why user education is one of the primary solutions for increased security
  • SQL injection attacks are in decline – or are they?
    IBM's X-Force 2009 Trend and Risk report claims to show an 11% fall in discovered vulnerabilities compared to 2008, including a decline in the largest categories, such as SQL injections and ActiveX.
  • Windows autorun trojan tops November malware chart
    The latest monthly malware chart from BitDefender claims to show that the largest risk to computer users is currently Trojan.AutorunINF.Gen, a generic family of trojan malware abusing the autorun feature in Windows.

News

SQL injection attacks hit 1.5m websites

14 December 2009

Another 1.5 million websites associated with the newest series of SQL injection attacks have been found by network security specialist eSoft.

The websites compromised by the SQL injection attacks, infect users with the trojan Trojan.Buzus, which runs silently in the background. The trojan steals passwords, financial data, and other sensitive information, the eSoft Threat Prevention Team said in a blog post.

The same script is injected several times in and around the title and meta tags, and in other locations. The sites compromised by the SQL injection attacks share the common characteristics of “script src=http” and a varying script source, eSoft said.

Injected domains include the following (the number indicates the amount of compromised websites eSoft found using Google search):

wgwgg.cn 383 000
a.ll8cc.cn7040
asa.ss.la14 300
1.ll8cc.cn179 000
252a.cn21 300
Kun0o.cn1650
65gd.cn 541 000

The domains host the same javascript using small or hidden iframes to redirect users to other malicious websites where the final payload is delivered.

According to eSoft, the SQL injection attack uses the same technique described by Scansafe last week in the 318x injection where around 300 000 websites were compromised.

eSoft said it is adding detection for the SQL injection attacks and flagging any compromised websites.

 

This article is featured in:
Internet and Network Security Malware and Hardware Security

 

Comment on this article

You must be registered and logged in to leave a comment about this article.