Mass SQL Injection Attack Hits 1 Million Sites

Status
Not open for further replies.

Hungry Man

New Member
Thread author
Jul 21, 2011
669
6
11
34
http://www.darkreading.com/database-security/167901020/security/news/231901236/mass-sql-injection-attack-hits-1-million-sites.html

A mass-injection attack similar to the highly publicized LizaMoon attacks this past spring has infected more than 1 million ASP.NET Web pages, Armorize researchers said today. According to database security experts, the SQL injection technique used in this attack depends on the same sloppy misconfiguration of website servers and back-end databases that led to LizaMoon's infiltration.
"This is very similar to LizaMoon," says Wayne Huang, CEO of Armorize, who, with his team, first reported of an injected script dropped on ASP.NET websites that load an iFrame to initiate browser-based drive-by download exploits on visitor browsers to the site.

Initial reports by Armorize showed that 180,000 Web pages had been hit by the offending script, but Huang told Dark Reading that a Google search resulted in returns for more than 1 million Web pages containing the injected code.
 
yes absolutely, the virtual world is not safe so you need virtual security
 
No site and no file should ever be considered trusted. That's what I've learned.
 
As an internet user we need to become more vigilant on every website we visit. Safe site doesn't mean a safe forever as hacks and compromised were occurred.
 
Status
Not open for further replies.

You may also like...