New Database Attack Hits UN, UK, and DHS Sites

Charles Johnsonfollow me on twitter
Mon Apr 28, 2008 at 3:43 pm PDT • Views: 167

Oops. Massive Attack: Half A Million Microsoft-Powered Sites Hit With SQL Injection.

A new SQL injection attack aimed at Microsoft IIS web servers has hit some 500,000 websites, including the United Nations, UK Government sites and the U.S. Department of Homeland Security. While the attack is not necessarily Microsoft’s fault, it is unique to the company’s IIS server.

The automated attack takes advantage to the fact that Microsoft’s IIS servers allow generic commands that don’t require specific table-level arguments. However, the vulnerability is the result of poor data handling by the sites’ creators, rather than a specific Microsoft flaw.

In other words, there’s no patch that’s going to fix the issue, the problem is with the developers who failed to follow well-established security practices for handling database input.

The attack itself injects some malicious JavaScript code into every text field in your database, the Javascript then loads an external script that can compromise a user’s PC.

Advertisement

349 comments

^ back to top ^

Name:

Pass:

Register Forgot Your Password? Account Settings Re-send Confirmation (To log in, cookies must be enabled in your browser!)

Turn off ads by subscribing!
For about 33 cents a day, our subscription option turns off all advertisements at LGF!
Read more...


► LGF Headlines

  • Loading...

► Tweeted Articles

  • Loading...

► Tweeted Pages

  • Loading...

► Top 10 Comments

  • Loading...

► Bottom Comments

  • Loading...

► Recent Comments

  • Loading...

► Tools/Info

► LGF Hits

► Resources

► Never Forget

► Statistics

► Tag Cloud

► Contact

You must have Javascript enabled to use the contact form.
Your email:

Subject:

Message:


Messages may be published in our weblog, unless you request otherwise.
Tech Note:
Using the Contact Form

More Partners

Compare Electricity Prices in your area. Texas Electricity is deregulated; you have the right to choose Texas Electric Rates from among many Texas Electric Companies.

Any discrepancy in the data is irrelevant.

TwitterFacebook
LGF Pages
Recent Pages

Aigle
Judi Rudoren Enters the Scene: Tweets or Tea Leaves?
4 minutes ago
Views: 4 • Comments: 0
Tweets: 0 • Rating: 0

Aigle
New Online Newspaper in Israel
5 minutes ago
Views: 9 • Comments: 0
Tweets: 0 • Rating: 0

Turnabout is Fair Play
A 787 Dreamliner Drew the Boeing Logo Across the United States
20 minutes ago
Views: 16 • Comments: 0
Tweets: 0 • Rating: 0

Daniel Ballard
The Boy Who Played With Fusion
52 minutes ago
Views: 52 • Comments: 0
Tweets: 0 • Rating: 2

lawhawk
Assad Claims Referendum Will Ease Crisis; Brutal Crackdown Continues
57 minutes ago
Views: 42 • Comments: 0
Tweets: 0 • Rating: 0

wrenchwench
Mexico Issues Travel Warning for Los United Estates
1 hour, 1 minute ago
Views: 61 • Comments: 0
Tweets: 1 • Rating: 1

Daniel Ballard
Independent Voters Are Rejecting Romney
1 hour, 15 minutes ago
Views: 60 • Comments: 1
Tweets: 0 • Rating: 1

Channeling Confucius
6 Terrifying User Agreements You've Probably Accepted
1 hour, 56 minutes ago
Views: 74 • Comments: 0
Tweets: 0 • Rating: 1

Turnabout is Fair Play
The Muslim Brotherhood's Post-Mubarak Anti-Americanism
2 hours, 10 minutes ago
Views: 63 • Comments: 0
Tweets: 0 • Rating: 1

MichaelJ
Daring Fireball: Walter Isaacson's 'Steve Jobs'
2 hours, 25 minutes ago
Views: 79 • Comments: 0
Tweets: 0 • Rating: 0

 Frank says:

There is no such thing as a dirty word. Nor is there a word so powerful, that it's going to send the listener to a lake of fire upon hearing it.