AfterDawn: Tech news

SQL injection attack hits hundreds of thousands of websites

Written by James Delahunty @ 02 Apr 2011 2:20 User comments (7)

SQL injection attack hits hundreds of thousands of websites Hundreds of thousands of websites have been hit by a code-injection attack that targets a problem with an unknown (so far) web application.
Websense has dubbed the widespread attack as "LizaMoon" after the website its researchers were initially directed to by the malicious code. The attack seems to have largely affected small website so far, with no reports of major corporate or government websites showing signs of being compromised.

Users visiting any hacked site are redirected to a prompt showing a bogus security warning, and may end up downloading "Windows Stability Center", a scareware application that provides fake scans and results on an infected system and gives the user a chance to buy a license to remove the fake threats.

Websense was contacted by people who found the code in their Microsoft SQL databases, using SQL Server 2000, 2005 and 2008. This does not mean there is a vulnerability in Microsoft SQL Server, Websense Security Labs stressed, but instead points the finger at a web application that is still, right now, unknown.



Mass code-injection attacks are not uncommon, but researchers are already calling this the largest of its kind. It is not likely to go away quickly either, as compromised sites will have to remove the malicious code and then update the vulnerable web application, whenever there is even a fix for it.

WebSense Security Labs posted the following video, which shows what happens to a system that is used to access a hacked URL.

Previous Next  

7 user comments

12.4.2011 06:23

"Unknown" web application? Right... :-D

Come on guys, it's April 2nd now.

22.4.2011 06:37

I'm writing a paper on SQL injections and plan on including this as a case study, it's not an April fool's joke is it?

32.4.2011 15:59

I dunno. April 1st was the wrong time to post this if it's real news. Seeing the antiquated (and security-hole-ridden) IE6 used in the video made me think this is not legitimate news. (At least not recent legitimate news.) Seems like some reports of it are dated March 31st though, so I'm not sure.

43.4.2011 02:54

Some simple common sense will protect you and your PC....
Only 17 of 43 AV (antivirus) engines can detect it...
+1,500,000 URLs had inserted Javascript link to lizamoon.com "Ukraine or Russia"
http://www.technewsworld.com/rsstory/72191.html?wlc=1301818476
http://www.toptechnews.com/story.xhtml?story_id=77980&full_skip=1

This message has been edited since its posting. Latest edit was made on 03 Apr 2011 @ 4:33

53.4.2011 04:30

No, this is not an April fools joke and it is still on-going.

63.4.2011 16:23

I stand corrected. :-)

74.4.2011 06:14

In Other News:
SQL Slammer-Worm mysterious disappearance (January 2003 to March 2011)
http://goo.gl/fb/5hgGQ

Comments have been disabled for this article.

Latest news

VLC hits milestone: over 5 billion downloads VLC hits milestone: over 5 billion downloads (16 Mar 2024 4:31)
VLC Media Player, the versatile video-software powerhouse, has achieved a remarkable feat: it has been downloaded over 5 billion times.
1 user comment
Sideloading apps to Android gets easier, as Google settles its lawsuit Sideloading apps to Android gets easier, as Google settles its lawsuit (19 Dec 2023 11:09)
Google settled its lawsuit in September 2023, and one of the settlement terms was that the way applications are installed on Android from outside the Google Play Store must become simpler. In the future, installing APK files will be easier.
8 user comments
Roomba Combo j7+ review - Clever trick allows robot vacuum finally to tackle home with rugs and carpets Roomba Combo j7+ review - Clever trick allows robot vacuum finally to tackle home with rugs and carpets (06 Jun 2023 9:19)
Roomba Combo j7+ is the very first Roomba model to combine robot vacuum with mopping features. And Roomba Combo j7+ does all that with a very clever trick, which tackles the problem with mopping and carpets. But is it any good? We found out.
Neato, the robot vacuum company, ends its operations Neato, the robot vacuum company, ends its operations (02 May 2023 3:38)
Neato Robotics has ceased its operations. American robot vacuum pioneer founded in 2005 has finally called it quits and company will cease its operations and sales. Only a skeleton crew will remain who will keep the servers running until 2028.
5 user comments
How to Send Messages to Yourself on WhatsApp How to Send Messages to Yourself on WhatsApp (20 Mar 2023 1:25)
The world's most popular messaging platform, Meta-owned WhatsApp has enabled sending messages to yourself. While at first, this might seem like an odd feature, it can be very useful in a lot of situations. ....
18 user comments

News archive