Hacker
Compromised sites attempt to install a password-stealing Trojan

SQL attack hits 500,000 websites

Sans warns of growing danger

Written by Shaun Nichols in California

They have hit city websites, commercial sites and even government websites

Donald Smith Sans Institute

Security researchers have uncovered a new SQL attack which has compromised more than half a million web pages.

"They have hit city websites, commercial sites and even government websites, " wrote Sans researcher Donald Smith.

"This type of injection pretty much voids the concept of 'trusted' or 'safe' websites."

Security firm F-Secure said that at least 510,000 pages have fallen victim to the attack.

The compromised sites have been embedded with code that redirects the user to a third-party site at which eight different exploits attempt to install a password-stealing Trojan.

F-Secure and Sans Institute urged administrators to block access to the domains hosting the malware exploit.

The Sans Internet Storm Center recommended blocking access to hxxp:/www.nihaorr1.com and the IP it resolves to 219DOT153DOT46DOT28 at the edge or border of the network.

F-Secure also recommended that administrators of hosting servers check their logs for possible attacks.

The outbreak is the latest in a rash of large-scale attacks this year. In March, a pair of attacks, one infecting 10,000 pages and another compromising 200,000 pages, were uncovered by researchers.

reader comments

related articles

Infosec Video Lounge Part 2

Infosec video lounge in association with Microsoft Part Two 24 Apr 2008

 

Infosec Europe 2008 Special Report

The latest news and views from Europe's number one information security event 01 May 2008

Infosec: Security tops government IT agenda

Citrix report highlights main priorities 24 Apr 2008

Infosec: Surfers wary of using credit cards online

Confidence plummets as attacks soar 24 Apr 2008

Tibet attack Trojan identified

'Fribet' also connected to SQL attacks 11 Apr 2008

New SQL attacks emerge

Chinese sites targeted en masse 11 Aug 2008

Hackers 'seeding' legitimate websites

SQL injection attacks colonising big name sites 09 Jun 2008

related whitepapers

today's top stories

WiMax: Threat or opportunity?

We examine the merits of WiMax and its benefits relative to other wireless technologies in our latest video 13 Oct 2008

Learning from the credit crunch to avoid a broadband crunch

While it might be the most pressing issue de jour , the financial system isn’t the only area where government needs to... 10 Oct 2008

How careerism can warp IT procurement

Many working in IT put their career interests before those of their employer when weighing up purchasing options 10 Oct 2008

The definitive guide to software development

Five key trends and five best practice tips to help you improve your programming capabilities 09 Oct 2008

Computing podcast - IT implications of the banking crisis, and the FSA clamps down on IT security

We discuss the effect of shotgun mergers and acquisitions on financial services IT staff, and examine the industry regulator's plan to fine directors for information security breaches 09 Oct 2008

Most commented stories

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job


IT Salary Checker

Check salary here

Advertisement

White papers

Search white papers

Top categories

VPN, Extranet and Intranet Solutions

WAN/ LAN Solutions

Network Security

Interoperability-Connectivity

Grid/ Utility Computing

Latest poll

Are you worried about your job prospects in IT over the next 12 months?

Are you worried about your job prospects in IT over the next 12 months?

Will the economic crisis affect your job prospects?

Previous poll results

Latest audio and video articles

Remote workerVideo

WiMax: Threat or opportunity?

We examine the merits of WiMax and its benefits relative to other wireless technologies in our latest video 13 Oct 2008

programming codeVideo

The definitive guide to software development

Five key trends and five best practice tips to help you improve your programming capabilities 09 Oct 2008

Latest in-depth articles

Financial Services Authority buildingAnalysis

FSA threatens executives with fines

Senior management to be held accountable for security lapses at banks 09 Oct 2008

Comment

Broadband must be a spending priority

For the economic health of the nation, the government would do better to bankroll an optical fibre rollout rather than prop up profligate banks 09 Oct 2008

Advertisement

Primary Navigation