Slashdot Mirror


Mass Hack Infects Tens of Thousands of Sites

An anonymous reader writes "Tens of thousands of Web sites have been compromised by an automated SQL injection attack, and although some have been cleaned, others continue to serve visitors a malicious script that tries to hijack their PCs using multiple exploits, security experts said this weekend. Hacked sites included both .edu and .gov domains, the SANS Institute's Internet Storm Center reported in a warning posted last Friday. The ISC also reported that several pages of security vendor CA's Web site had been infected. Roger Thompson, the chief research officer at Grisoft, pointed out that the hacked sites could be found via a simple Google search for the domain that hosts the malicious JavaScript. On Saturday, said Thompson, the number of sites that had fallen victim to the attack numbered more than 70,000. 'This was a pretty good mass hack,' said Thompson, in a post to his blog." By Sunday a second round of the same attack had infected over 90,000 servers.

4 of 259 comments (clear)

  1. Re:Okay Hands Up... by renegadesx · · Score: 1, Troll

    An above poster (and some fan of paedophelia and wife bashing) seem to think its M$ SQL Servers that got hit

    At the same time it could just be flaming

    --
    Make SELinux enforcing again!
  2. Re:Good acts of violence by zaydana · · Score: 0, Troll

    But what about when you have to clean up a nice girl's computer?

    I say congrats to the guys who made this, and keep up the good work!

  3. Re:this kinda of crap anin't gonna stop until: by element-o.p. · · Score: 0, Troll
    Huh. Kinda sounds like...:

    #!/usr/bin/perl -Tw
    use strict;
    ...

    That's one of the big reasons I like Perl so much :)
    --
    MCSE? No, sir...I don't do Windows. Yes, I am an idealist. What's your point?
  4. Re:Phew! Nothing to see here! by Mister+Whirly · · Score: 0, Troll

    Wow, your informative well thought out post was so incredible, I just had a brain aneurysm processing the wealth of intelligence it contained. You obviously understand programming, especially platform-independent programming, so well it is scary. It is just not fair that one AC should have so much divine knowledge.

    Or you could just be a total trolling choad who has no concept of back-end and front-end when it comes to databases.

    --
    "But this one goes to 11!"