Hacker
Compromised sites attempt to install a password-stealing Trojan
R E L A T E D   C O N T E N T
ADVERTISEMENT

SQL attack hits 500,000 websites

Sans warns of growing danger

Shaun Nichols in California, vnunet.com 25 Apr 2008
ADVERTISEMENT

Security researchers have uncovered a new SQL attack which has compromised more than half a million web pages.

"They have hit city websites, commercial sites and even government websites, " wrote Sans researcher Donald Smith.

"This type of injection pretty much voids the concept of 'trusted' or 'safe' websites."

Security firm F-Secure said that at least 510,000 pages have fallen victim to the attack.

The compromised sites have been embedded with code that redirects the user to a third-party site at which eight different exploits attempt to install a password-stealing Trojan.

F-Secure and Sans Institute urged administrators to block access to the domains hosting the malware exploit.

The Sans Internet Storm Center recommended blocking access to hxxp:/www.nihaorr1.com and the IP it resolves to 219DOT153DOT46DOT28 at the edge or border of the network.

F-Secure also recommended that administrators of hosting servers check their logs for possible attacks.

The outbreak is the latest in a rash of large-scale attacks this year. In March, a pair of attacks, one infecting 10,000 pages and another compromising 200,000 pages, were uncovered by researchers.

See also:

Infosec Europe 2008Citrix report highlights main priorities  24 Apr 2008
Infosec video lounge in association with Microsoft Part Two  24 Apr 2008
Infosec Europe 2008Confidence plummets as attacks soar  24 Apr 2008
Infosec Europe 2008The latest news and views from Europe's number one information security event  01 May 2008

All Hacking
Tags: Sql, Trojan, Security

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story
R E A D E R   C O M M E N T S

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
London, Waterloo, United Kingdom | Christian Aid
Database Administrator, London, Waterloo, Starting at £34,858 and progressing to £38,983 per annum We are seeking an experienced Database Administrator to be responsible for the implementation, availability, performance and security of all Christian Aid database ... more >
London, United Kingdom | Shell
Portfolio & Architecture Manager,London Shell is a business that's built on ideas. We believe that for every problem, there's a solution. That anything can be done if we put our minds to it. Shell Downstream ... more >
Warrington, United Kingdom | Environment Agency
Solution Architect, Warrington, Salary and Package to attract the best These positions require highly skilled Solution Architects with demonstrable experience of working within a complex enterprise project environment. Working within the Business Solutions Team you ... more >
Bristol, United Kingdom | Environment Agency
Technical Architect, Bristol, Salary and package to attract the best These positions require highly skilled Technical Architects with demonstrable experience of working within a complex and distributed infrastructure environment. Working within the Service Assurance team ... more >
More job opportunities