The time now is 07/09/08 - 12:19
Log in: Username: Password:
Search forums for:
  
 
H-Desk.com Forum Index

H-Desk.com - PC Security matters - Protect your PC privacy


SQL Injections - newest threat for thousands of sites


H-Desk.com Forum Index -> Security News

Post new topic   This topic is locked: you cannot edit posts or make replies.
Author Message
windshell
Site Admin


Joined: 18 Jan 2007
Posts: 59



PostPosted: 05/02/08 - 10:50    Post subject: SQL Injections - newest threat for thousands of sites Reply with quote

SQL Injections are newest threat for thousands of sites and online gamers

The dynamic nature of websites, powered by back-end databases made thousands of them possible targets for injections of malicious code.

Three domains have been found to host malicious exploits that hit users while they searching the Internet. Those sites are: nmidahena.com, aspder.com and nihaorr1.com. Links to this content are turning up in thousands of links to otherwise innocent websites, thanks to almost unstoppable outbreak of SQL injection attacks.

Approximately 510,000 pages are affected by the attacks on a variety of sites.

Point of this attacks is that the bad people want to drop a Trojan on victims’ systems. Victims are usually online gamers. With ten million players alone on World of Warcraft, and thousands more on other online games, such Trojans could grab login credentials and steal billing information or in-game valuables.

It’s been found that those attacks now seek out all of the text fields in the database, adding a link to malicious JavaScript to them. The attackers especially look for .asp and .aspx pages.

Any site that offers the ability of content upload, from blogs to forum, could be at risk from the attacks. It’s been suggested however, that webmasters often check their server logs for a section of the injection code they listed in this latest post about the attacks. If it's present, the database needs to be cleaned up, and the application fixed to sanitize incoming content.

News Source:

ientry.com
Back to top
Display posts from previous:   
Post new topic   This topic is locked: you cannot edit posts or make replies. All times are GMT

H-Desk.com Forum Index -> Security News

Page 1 of 1

Related topics:
How to get the newest video codec?
Deletemusic worm threatens MP3 collections via flash drives
Phishing threat to Google Gadgets
Kazaa Lite security threats
Am I paranoic - keyloggers threat on every page
eMule threat
Infected on site I have been thousands time before