Newsletter:

Skip Navigation LinksHome > News > Security > SQL attack hits 500,000 websites

SQL attack hits 500,000 websites

By Shaun Nichols
26 April 2008 10:22AM
Tags: sql | attack | hits | 500 | 000 | websites

Security researchers have uncovered a new SQL attack which has compromised more than half a million web pages.

"They have hit city websites, commercial sites and even government websites, " wrote Sans researcher Donald Smith.

"This type of injection pretty much voids the concept of 'trusted' or 'safe' websites."

Security firm F-Secure said that at least 510,000 pages have fallen victim to the attack.

The compromised sites have been embedded with code that redirects the user to a third-party site at which eight different exploits attempt to install a password-stealing Trojan.

F-Secure and Sans Institute urged administrators to block access to the domains hosting the malware exploit.

The Sans Internet Storm Center recommended blocking access to hxxp:/www.nihaorr1.com and the IP it resolves to 219DOT153DOT46DOT28 at the edge or border of the network.

F-Secure also recommended that administrators of hosting servers check their logs for possible attacks.

The outbreak is the latest in a rash of large-scale attacks this year. In March, a pair of attacks, one infecting 10,000 pages and another compromising 200,000 pages, were uncovered by researchers.

Copyright © 2008 vnunet.com

   


Ads by Google





Product Reviews

Star Rating
The Tumbleweed MailGate appliance offers solid email protection and management in one device.
Star Rating
Sendmail Sentrion DS 3.0 is a rack-mounted email authentication appliance used strictly for applying digital...
Star Rating
Cryptzone’s Secured eMail Enterprise v3.2 is a desktop client application that integrates into Microsoft...
Star Rating
Marshal’s MailMarshal SMTP is a software-based approach to email content management.
Star Rating
The Entelligence Messaging Server v9.1 is an appliance-based email gateway that provides encryption and...
ITNews Survey
TopTopics
(11292) -  iphone
(9148) -  microsoft
(5215) -  telstra
(4034) -  gates
(3922) -  online
(3045) -  linux
(2185) -  mobile
(2115) -  security
(1848) -  sony
(1730) -  supercomputer
(1575) -  intel
(1543) -  web
(1464) -  office
(1433) -  computing
(1407) -  management