Mass SQL Injection Attack Hits 1 Million Sites

Status
Not open for further replies.

Hungry Man

New Member
Thread author
Jul 21, 2011
669
http://www.darkreading.com/database-security/167901020/security/news/231901236/mass-sql-injection-attack-hits-1-million-sites.html

A mass-injection attack similar to the highly publicized LizaMoon attacks this past spring has infected more than 1 million ASP.NET Web pages, Armorize researchers said today. According to database security experts, the SQL injection technique used in this attack depends on the same sloppy misconfiguration of website servers and back-end databases that led to LizaMoon's infiltration.
"This is very similar to LizaMoon," says Wayne Huang, CEO of Armorize, who, with his team, first reported of an injected script dropped on ASP.NET websites that load an iFrame to initiate browser-based drive-by download exploits on visitor browsers to the site.

Initial reports by Armorize showed that 180,000 Web pages had been hit by the offending script, but Huang told Dark Reading that a Google search resulted in returns for more than 1 million Web pages containing the injected code.
 

imsoadude

Level 3
Verified
Feb 21, 2011
838
Wow thats insane, you really have to be careful when visiting trusted sites now.
 
D

Deleted member 178

yes absolutely, the virtual world is not safe so you need virtual security
 

Hungry Man

New Member
Thread author
Jul 21, 2011
669
No site and no file should ever be considered trusted. That's what I've learned.
 

PenTester

New Member
Jul 30, 2011
114
I think this is same news about asp site infection.
http://malwaretips.com/Thread-350-000-Web-Pages-Fall-Victim-to-ASP-Mass-Infection
 

jamescv7

Level 85
Verified
Honorary Member
Mar 15, 2011
13,070
As an internet user we need to become more vigilant on every website we visit. Safe site doesn't mean a safe forever as hacks and compromised were occurred.
 
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top