Page is a not externally linkable
- Code, Content, and Presentation
-- Databases
---- Sql Injection virus problem.


pageoneresults - 11:13 am on May 27, 2008 (gmt 0)


Here is a bit more information related to this sql injection hack. This is a must read for all Microsoft folks, as we are at the forefront again...

2008-04-28 - No New IIS Or Microsoft SQL Server Vulnerabilities, Despite Claims
[webmasterworld.com...]

2008-04-28 - Half a million sites hit by huge web hack
[techworld.com...]

2008-05-15 - Phishing botnet turns to SQL-injection attack
[techworld.com...]

It's so bad, in fact, that while security companies urged website administrators to check their server logs for evidence of a compromise, and told corporate security staffs to block several malware-hosting sites at their companies' perimeters, they didn't have much useful advice for end-users.

This was interesting...

After the Asprox botnet seeds its bots with the msscntr32.exe file, the attack tool launches and uses Google's search engine to find potentially-vulnerable pages. It then hits those pages with a SQL-injection attack and, if successful, plants a malicious IFRAME on the site.

Emphasis mine. Search Google for Goolag.


Thread source:: http://www.webmasterworld.com/databases_sql_mysql/3657200.htm
Brought to you by WebmasterWorld: http://www.webmasterworld.com