The Last HOPE
-->
         
         
Email us! Subscribe to Liquidmatrix!

New SQL Attack Making The Rounds

A new SQL Injection attack is making the rounds. There is a great analysis of the attack over on Shadowserver Foundation.

From Shadowserver:

As predicted, the attacks against ASP and ASP.NET pages via SQL injection have continued. This time the domain name “winzipices.cn” is in the spotlight. It has managed to find itself in the source of over 4,000 pages according to Google. ISC has also has a short diary today mentioning this attack here. It turns out this is also something we have been taking a look at now for a few days. With that being said, we would like to share some information that can help protect end users and organizations.

It would appear that our attackers in this instance are taking advantage of the same issues we have discussed in some of our recent postings. However, we do know that the malware and malicious file trail here are different than the last few attacks.

For the full analysis read on.

Article Link

Tag It: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Digg
  • del.icio.us
  • Slashdot
  • Technorati
  • SphereIt
  • StumbleUpon
  • Fark
  • YahooMyWeb
  • Furl
  • Spurl
  • Ma.gnolia
  • NewsVine
Related Articles:

  • SQL Injection Cheat Sheet
  • Top 15 free SQL Injection Scanners
  • WordPress “admin-ajax.php” SQL Injection
  • Oracle Products Multiple Vulnerabilities
  • Oracle Products Multiple Vulnerabilities
  • Leave a Comment