Thousands of web servers hit by SQL attack

By
Follow google news

A wave of new SQL injection attacks appears to have infected several thousand web servers, including government and financial services sites.

Thousands of web servers hit by SQL attack
A wave of new SQL injection attacks appears to have infected several thousand web servers, including government and financial services sites.

Internet security specialist Secure Computing has issued a warning of an SQL injection attack that appears to have infected several thousand web servers, including government and financial services sites.

According to a blog on the company's TrustedSource information site, the attack began late last Friday. It targets machines running Microsoft SQL Server.

The post said that “It's also possible that web servers with Sybase database backends could also conceivably be exploited.”

Sybase largely uses the same SQL syntax and table structure as SQL Server.

Visitors to infected web servers could be sent one of many different forms of malware, TrustedSource warned.

“Similar to phishing, this attack takes advantage of the website visitor's trust in the site they are visiting. Instead of phishing for information, however, malware is sent to the client, which the client has a higher likelihood of accepting being from a trusted site,” the company claimed.

This type of attack SQL attack could be used to launch phishing attacks on sites requesting financial information, or any other type of attack where the visitors' trust can be exploited, warned TrustedSource.

“As of today, this attack is still working and ongoing. We are seeing evidence of successful exploitation attempts across hundreds of web pages. These web pages are associated with web sites from around the world and supplying various content including government sites, sales sites, real estate sites, and financial information sites among others,” the company added.

See original article on scmagazineus.com

Add iTnews as your trusted source

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © SC Magazine, US edition
Tags:

Most Read Articles

Services Australia describes fraud, debt-related machine learning use cases

Services Australia describes fraud, debt-related machine learning use cases

Attacker embeds Claude Code in mass credential harvesting op

Attacker embeds Claude Code in mass credential harvesting op

'Copy Fail' Linux privesc bug lay dormant in kernel since 2017

'Copy Fail' Linux privesc bug lay dormant in kernel since 2017

Medibank reveals attack vector and cost of 2022 security breach

Medibank reveals attack vector and cost of 2022 security breach

Log In

  |  Forgot your password?