Stories
Slash Boxes
Comments
typodupeerror delete not in

Hot Comments

+-   New SQL Injection Attack Fuses Malware and Phishin on Tuesday August 12 2008, @10:06AM PainMeds

Submitted by PainMeds on Tuesday August 12 2008, @10:06AM
security
PainMeds writes "According to a recent post in Secure Computing's research blog, a new SQL injection attack has infected thousands of MSSQL-based web servers over the weekend, effectively turning them into malware delivery systems. The attack apparently rewrites the server's web pages to include javascript which, in turn, pushes malware to the website visitor as if it were from the genuine website. From the blog, "Similar to phishing, this attack takes advantage of the website visitor's trust in the site they are visiting. Instead of phishing for information, however, malware is sent to the client, which the client has a higher likelihood of accepting being from a trusted site... These web pages are associated with web sites from around the world and supplying various content- including government sites, sales sites, real estate sites, and financial information sites among others." An example of the attack has been included in the post. Unlike most malware attacks, this attack appears to originate from the website the user is actually visiting."
submission

This discussion was created for logged-in users only, but now has been archived. No new comments can be posted.
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
 Full
 Abbreviated
 Hidden
More
Loading... please wait.
"I have more information in one place than anybody in the world." -- Jerry Pournelle, an absurd notion, apparently about the BIX BBS