Yet another massive SQL injection attack may be underway, according to the SANS Internet Storm Center.
Based on a Google search of the malicious string being used, more than 4000 websites have been infected, SANS handler Mark Hofman said in a post Friday.
That is a rapid rise from Thursday, the day the ambush was first detected, when only about 80 sites appeared to be compromised.
Impacted sites appear to be running Microsoft Internet Information Services (IIS) or Microsoft SQL web servers and are using software from ASP.NET or ColdFusion, Hofman said.
Visitors to hacked sites are being redirected to pages trying to push rogue anti-virus programs or another payload.
"The hex will show in the IIS log files, so monitor those," Hofman wrote. "Make sure that applications only have the access they require, so if the page does not need to update a (database), then use an account that can only read."
He also recommended blocking access to the malicious redirect site.
Similar waves of SQL injection attacks have been common for years, including a major one earlier this year.
This article originally appeared at scmagazineus.com
Copyright © SC Magazine, US edition
A confirmation email has been sent to your email address - SUPPLIED GOES EMAIL HERE. Please click on the link in the email to verify your email address. You need to verify your email before you can start posting.
If you do not receive your confirmation email within the next few minutes, it may be because the email has been captured by a junk mail filter. Please ensure you add the domain @itnews.com.au to your white-listed senders.