New Database Attack Hits UN, UK, and DHS Sites

Charles Johnsonfollow me on twitter
Mon Apr 28, 2008 at 3:43 pm PDT • Views: 222

Oops. Massive Attack: Half A Million Microsoft-Powered Sites Hit With SQL Injection.

A new SQL injection attack aimed at Microsoft IIS web servers has hit some 500,000 websites, including the United Nations, UK Government sites and the U.S. Department of Homeland Security. While the attack is not necessarily Microsoft’s fault, it is unique to the company’s IIS server.

The automated attack takes advantage to the fact that Microsoft’s IIS servers allow generic commands that don’t require specific table-level arguments. However, the vulnerability is the result of poor data handling by the sites’ creators, rather than a specific Microsoft flaw.

In other words, there’s no patch that’s going to fix the issue, the problem is with the developers who failed to follow well-established security practices for handling database input.

The attack itself injects some malicious JavaScript code into every text field in your database, the Javascript then loads an external script that can compromise a user’s PC.

Advertisement

349 comments

^ back to top ^

Name:

Pass:

Register Forgot Your Password? Re-send Confirmation (To log in, cookies must be enabled in your browser!)

Turn off ads by subscribing!
For about 33 cents a day, our subscription option turns off all advertisements at LGF!
Read more...


► LGF Headlines

  • Loading...

► Tweeted Articles

  • Loading...

► Tweeted Pages

  • Loading...

► Top 10 Comments

  • Loading...

► Bottom Comments

  • Loading...

► Recent Comments

  • Loading...

► Tools/Info

► Tag Cloud

► Contact

You must have Javascript enabled to use the contact form.
Your email:

Subject:

Message:


Messages may be published in our weblog, unless you request otherwise.
Tech Note:
Using the Contact Form

More Partners

Compare Electricity Prices in your area. Texas Electricity is deregulated; you have the right to choose Texas Electric Rates from among many Texas Electric Companies.

Anti-idiotarian headquarters.

TwitterFacebook
LGF Pages
Recent Pages

Channeling Confucius
Astronomy Picture of the Day: Looking Back at an Eclipsed Earth
13 minutes ago
Views: 12 • Comments: 0
Tweets: 0 • Rating: 0

Aigle
Ha'aretz, Lost in Translation
2 hours, 29 minutes ago
Views: 75 • Comments: 3
Tweets: 0 • Rating: 0

Randall Gross
Government Employment Drops Under Obama, but Media Run With Romney Myth Anyway
4 hours, 19 minutes ago
Views: 146 • Comments: 0
Tweets: 6 • Rating: 1

researchok
French Philosopher Alain Badiou on the Real Expression of Love: 'If You Limit Yourself to Sexual Pleasure It's Narcissistic'
8 hours, 24 minutes ago
Views: 91 • Comments: 0
Tweets: 0 • Rating: 0

Haywood Jabloeme
Closing the Racial and Generational Divides
12 hours, 13 minutes ago
Views: 94 • Comments: 0
Tweets: 0 • Rating: 1

Aziz Poonawalla
I Speak for Myself: All-American
16 hours, 10 minutes ago
Views: 140 • Comments: 0
Tweets: 0 • Rating: 5

Mostly sane, most of the time.
So wake up and notice already
2 days, 11 hours ago
Views: 294 • Comments: 0
Tweets: 2 • Rating: 7

Daniel Ballard
Late Afternoon Light-Kalanchoe
3 days, 16 hours ago
Views: 270 • Comments: 0
Tweets: 0 • Rating: 5

Eclectic Infidel
City College of San Francisco Budget Update
3 days, 16 hours ago
Views: 323 • Comments: 0
Tweets: 0 • Rating: 1

MichaelJ
Apple TV Slated to Debut in December?
4 days, 22 hours ago
Views: 372 • Comments: 0
Tweets: 0 • Rating: 1

 Frank says:

My music makes the mind think -- Time magazine Dec.20/93, page 73