Hacker
Compromised sites attempt to install a password-stealing Trojan
R E L A T E D   C O N T E N T
Jargon Buster

ADVERTISEMENT

SQL attack hits 500,000 websites

Sans warns of growing danger

Shaun Nichols in California, vnunet.com 25 Apr 2008
ADVERTISEMENT

Security researchers have uncovered a new SQL attack which has compromised more than half a million web pages.

"They have hit city websites, commercial sites and even government websites, " wrote Sans researcher Donald Smith.

"This type of injection pretty much voids the concept of 'trusted' or 'safe' websites."

Security firm F-Secure said that at least 510,000 pages have fallen victim to the attack.

The compromised sites have been embedded with code that redirects the user to a third-party site at which eight different exploits attempt to install a password-stealing Trojan.

F-Secure and Sans Institute urged administrators to block access to the domains hosting the malware exploit.

The Sans Internet Storm Center recommended blocking access to hxxp:/www.nihaorr1.com and the IP it resolves to 219DOT153DOT46DOT28 at the edge or border of the network.

F-Secure also recommended that administrators of hosting servers check their logs for possible attacks.

The outbreak is the latest in a rash of large-scale attacks this year. In March, a pair of attacks, one infecting 10,000 pages and another compromising 200,000 pages, were uncovered by researchers.

See also:

Infosec Europe 2008Citrix report highlights main priorities  24 Apr 2008
Infosec video lounge in association with Microsoft Part Two  24 Apr 2008
Infosec Europe 2008Confidence plummets as attacks soar  24 Apr 2008
Infosec Europe 2008The latest news and views from Europe's number one information security event  01 May 2008

All Hacking
Tags: Sql, Trojan, Security

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
London, United Kingdom | MHRA
Senior Technical Analyst - £26,781 - £28,562 - London The Medicines and Healthcare products Regulatory Agency (MHRA) is the government agency which is responsible for ensuring that medicines and medical devices work, and are acceptably ... more >
London, United Kingdom | Royal Borough of Kensington and Chelsea
Web Content Manager - c.£40,000 plus bonus - London   As one of the country's best-performing councils, we're always looking for new ways to improve on excellence. Providing an innovative, high-quality internet site for our ... more >
Inverness, United Kingdom | NHS Scotland
CORPORATE SERVICES E-HEALTH DEPARTMENT  RAIGMORE HOSPITAL INVERNESS TECHNICAL DEVELOPMENT TEAM IT TECHNICAL SPECIALIST  £24,103 to £32,653 PA An exciting opportunity has arisen to join the technical development team within the eHealth Department. We are looking ... more >
Oxford, Oxfordshire, United Kingdom | University of Oxford
Senior Business Analyst - Oxford University - £34,793 - £45,397   Business Services & Projects (BSP) Are you an experienced Business Analyst with the skills to improve the efficiency of Oxford University's business systems? The ... more >
More job opportunities