Shaun Nichols in California, vnunet.com25 Apr 2008
ADVERTISEMENT
Security researchers have uncovered a new SQL attack which has compromised
more than half a million web pages.
"They have hit city websites, commercial sites and even government websites,
" wrote Sans researcher Donald Smith.
"This type of injection pretty much voids the concept of 'trusted' or 'safe'
websites."
Security firm F-Secure said that at least 510,000 pages have fallen victim to
the attack.
The compromised sites have been embedded with code that redirects the user to
a third-party site at which eight different exploits attempt to install a
password-stealing Trojan.
F-Secure and Sans Institute urged administrators to block access to the
domains hosting the malware exploit.
The Sans
Internet Storm Center recommended blocking access to hxxp:/www.nihaorr1.com
and the IP it resolves to 219DOT153DOT46DOT28 at the edge or border of the
network.
F-Secure also recommended that administrators of hosting servers check their
logs for possible attacks.
The outbreak is the latest in a rash of large-scale attacks this year. In
March, a pair of attacks, one infecting 10,000 pages and another compromising
200,000 pages, were uncovered by researchers.
Central London, United Kingdom | MI5 Security Service
Communications Centre Engineer - Competitive salaries + excellent benefits - Central London Getting the best out of technology is critical to helping us protect the UK. Join MI5 and use your skills and experience to ... more >
Technology and Systems Consulting Event - LondonWith the right balance, you'll achieve great things. Join our Consulting practice and have the opportunity to balance your technical and business consulting skills to bring out the best ... more >
Central London, United Kingdom | MI5 Security Services
Messaging System Engineer - Competitive salaries + excellent benefits - Central London Getting the best out of technology is critical to helping us protect the UK. Join MI5 and use your skills and experience to help ... more >
Position # 395423 Environment Manager Location - Reading, Berkshire Job Description: There is a requirement for an Environmental Manager for the Sandpits environment. This position is to act as the single point of contact for ... more >More job opportunities