SQL attack hacks wide range of sites

CA among victims of major attack linking sites to malware.

Huge numbers of legitimate websites - perhaps as many as 100,000 according to some reports - fell victim to hackers over the last couple of weeks thanks to SQL injection problems leaving sites vulnerable.

ISSD 2010 conference

The hacks redirect traffic to sites in China, where click-fraud is used to turn the traffic into profits, and also attempt to drop data-stealing malware onto vulnerable systems.

Starting on December 28th, hackers probed sites for vulnerability to the hack, which may have been caused by some faulty SQL code on sites created using Dreamweaver. The tide of compromises began to go recede around January 5th, but many sites are thought to remain unpatched. Among sites affected are major corporations, including security firm CA - which is thought to have had an infected site for a brief time - government agencies and educational institutions.

More detailed reports of the rash of hacking are in The Register here and in Information Week here.

08 January 2008

Tags: ca, click fraud, malware, sql injection, vulnerability.    del.icio.us  digg this! digg this


Poll

Do you use the same password(s) across multiple websites?
I use the same password for all sites
I have a number of passwords but use the same for some sites
I use a different password for each site
I don't sign up to any sites that require a password

Leave a comment
View 4 comments

Jobs Recruit Sidebar

VB100 certification

VB100 This month VB's test team put 26 products to the test on Windows Server 2008. John Hawes has the full results.
See full results.

Virus Bulletin currently has 191,005 registered users.