Slashdot Mirror


SQL Injection Attack Claims 132,000+

An anonymous reader writes "A large scale SQL injection attack has injected a malicious iframe on tens of thousands of susceptible websites. ScanSafe reports that the injected iframe loads malicious content from 318x.com, which eventually leads to the installation of a rootkit-enabled variant of the Buzus backdoor trojan. A Google search on the iframe resulted in over 132,000 hits as of December 10, 2009."

7 of 186 comments (clear)

  1. Re:hey by jo42 · · Score: 4, Funny

    dd if=/dev/zero of=/dev/sda bs=8192 will fix it.

  2. Re:hey by Yvan256 · · Score: 4, Funny

    Call a comedy club and get your computer on stage?

  3. Re:Details? by Yvan256 · · Score: 4, Insightful

    But a Trojan needs user access and approval to get installed. No OS on the planet can protect itself from a user with the admin password.

  4. Re:Details? by Bert64 · · Score: 4, Funny

    Windows 9x used to due a pretty good job, can't own a system once it's bluescreened.

    --
    http://spamdecoy.net - free throwaway anonymous email - avoid spam!
  5. Re:Windoze by TheNinjaroach · · Score: 5, Informative

    All I can tell (from TFA), is it affects Windows servers.

    SQL injection attacks affect any number of platforms. It's not a Windows problem, it's not a database problem, it's a "we hired cheap, unskilled developers" problem.

    Now the people who browse these sites and get hit with malware, that looks to be specific to Windows.

    --
    I went to eat some animal crackers and the box said, "Do not eat if seal is broken." I opened the box and sure enough..
  6. Obvious, but needs to be said by GreenTom · · Score: 4, Informative

    Add to windows\system32\drivers\etc\hosts:

    127.0.0.1 318x.com

    And you should be safe, for the moment.

  7. Re:Details? by LordKaT · · Score: 5, Insightful

    Even still, this blog post is fucking useless. What CMS? What input is not being validated? Is it an underlying problem with Drupal? Wordpress? Joomla? What version?

    On top of that, it doesn't give any recommendations for what end users could do to protect themselves. Does anti-virus software already detect it? Can you simply alter your hosts file? Disable Javascript?

    The blog post is completely fucking useless.