Newsletter:

Skip Navigation LinksHome > News > Security > SQL attack hits 500,000 websites

SQL attack hits 500,000 websites

By Shaun Nichols
26 April 2008 10:22AM
Tags: sql | attack | hits | 500 | 000 | websites

Security researchers have uncovered a new SQL attack which has compromised more than half a million web pages.

"They have hit city websites, commercial sites and even government websites, " wrote Sans researcher Donald Smith.

"This type of injection pretty much voids the concept of 'trusted' or 'safe' websites."

Security firm F-Secure said that at least 510,000 pages have fallen victim to the attack.

The compromised sites have been embedded with code that redirects the user to a third-party site at which eight different exploits attempt to install a password-stealing Trojan.

F-Secure and Sans Institute urged administrators to block access to the domains hosting the malware exploit.

The Sans Internet Storm Center recommended blocking access to hxxp:/www.nihaorr1.com and the IP it resolves to 219DOT153DOT46DOT28 at the edge or border of the network.

F-Secure also recommended that administrators of hosting servers check their logs for possible attacks.

The outbreak is the latest in a rash of large-scale attacks this year. In March, a pair of attacks, one infecting 10,000 pages and another compromising 200,000 pages, were uncovered by researchers.

Copyright © 2008 vnunet.com

   


Ads by Google





Product Reviews

Star Rating
The Kerio WinRoute Firewall is an interesting product for this category.
Star Rating
The BiGuard S6000 extends the network to the remote user with features such as Network Extender, Transport...
Star Rating
Sendmail Sentrion DS 3.0 is a rack-mounted email authentication appliance used strictly for applying digital...
Like the sky box in a sports stadium, Skybox SRM offers an overall view of everything.
Star Rating
The offering from Symantec is much larger than the scope of this review.
ITNews NetSeminars
TopTopics
(19991) -  iphone
(4714) -  accc
(3946) -  hack
(3802) -  internet
(3501) -  apple
(3481) -  government
(3194) -  microsoft
(3161) -  telstra
(3022) -  vista
(2934) -  smartphone
(1993) -  security
(1884) -  online
(1714) -  spam
(1573) -  yahoo
(1444) -  data