Shaun Nichols in California, vnunet.com25 Apr 2008
ADVERTISEMENT
Security researchers have uncovered a new SQL attack which has compromised
more than half a million web pages.
"They have hit city websites, commercial sites and even government websites,
" wrote Sans researcher Donald Smith.
"This type of injection pretty much voids the concept of 'trusted' or 'safe'
websites."
Security firm F-Secure said that at least 510,000 pages have fallen victim to
the attack.
The compromised sites have been embedded with code that redirects the user to
a third-party site at which eight different exploits attempt to install a
password-stealing Trojan.
F-Secure and Sans Institute urged administrators to block access to the
domains hosting the malware exploit.
The Sans
Internet Storm Center recommended blocking access to hxxp:/www.nihaorr1.com
and the IP it resolves to 219DOT153DOT46DOT28 at the edge or border of the
network.
F-Secure also recommended that administrators of hosting servers check their
logs for possible attacks.
The outbreak is the latest in a rash of large-scale attacks this year. In
March, a pair of attacks, one infecting 10,000 pages and another compromising
200,000 pages, were uncovered by researchers.
C#, GUI Developer – Fixed Income – Investment Bank. My client is seeking a strong C# ASP.Net developer to join their Fixed Income area and operate within one of the top tier investment banks in ... more >
Technical Project Manager / SDLC West London, £75k - (Software Development, SDLC), RUP Serious opportunity for hands on Technical Project Manager to join a leading blue chip organisation based in an easily accessible area of ... more >
C# Developer - Nottingham 4 Month Contract Market Rates I have an exciting opportunity for a C# ASP.NETDeveloper working for an established client within Computer People. Working from their offices in Nottingham you’ll be providing ... more >