Hacker
Compromised sites attempt to install a password-stealing Trojan
R E L A T E D   C O N T E N T

Free email newsletters




ADVERTISEMENT

SQL attack hits 500,000 websites

Sans warns of growing danger

Shaun Nichols in California, vnunet.com 25 Apr 2008
ADVERTISEMENT

Security researchers have uncovered a new SQL attack which has compromised more than half a million web pages.

"They have hit city websites, commercial sites and even government websites, " wrote Sans researcher Donald Smith.

"This type of injection pretty much voids the concept of 'trusted' or 'safe' websites."

Security firm F-Secure said that at least 510,000 pages have fallen victim to the attack.

The compromised sites have been embedded with code that redirects the user to a third-party site at which eight different exploits attempt to install a password-stealing Trojan.

F-Secure and Sans Institute urged administrators to block access to the domains hosting the malware exploit.

The Sans Internet Storm Center recommended blocking access to hxxp:/www.nihaorr1.com and the IP it resolves to 219DOT153DOT46DOT28 at the edge or border of the network.

F-Secure also recommended that administrators of hosting servers check their logs for possible attacks.

The outbreak is the latest in a rash of large-scale attacks this year. In March, a pair of attacks, one infecting 10,000 pages and another compromising 200,000 pages, were uncovered by researchers.

See also:

Infosec Europe 2008Citrix report highlights main priorities  24 Apr 2008
Infosec video lounge in association with Microsoft Part Two  24 Apr 2008
Infosec Europe 2008Confidence plummets as attacks soar  24 Apr 2008
Infosec Europe 2008The latest news and views from Europe's number one information security event  01 May 2008

All Hacking
Tags: Sql, Trojan, Security

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story
R E A D E R   C O M M E N T S

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
Bristol, United Kingdom | Boeing
Sr. Software Architect, Bristol,  Competitive and Relocation Money Available Job Description: This position is for a Systems Analyst/SW Engineer for the Boeing Defence UK office in Bristol. The candidate will lead software development activities in ... more >
London, United Kingdom | MI5
 Oracle Test Analyst, London, From £30,192 depending on skills and experience (pay award pending) Join MI5's new team, and you'll be supporting colleagues as they protect the UK from terrorism, espionage and other national security ... more >
Leeds, United Kingdom | UKCRN
Portal Manager, Leeds In charge of the Portal Management team, you'll manage the day to day operations of the portal and provide editorial function and guidance.  You'll understand and own the portal's strategic aim and ... more >
London, United Kingdom | InterSystems
ARCHITECT / DEVELOPER, London, Very Competitive £  OBJECT ORIENTED DEVELOPER / PROGRAMMER / ARCHITECT with strong OO (object oriented) development experience required by world leading global software provider to act as Senior Technical Consultants. InterSystems Corporation ... more >
More job opportunities