SQL attack hacks wide range of sites
CA among victims of major attack linking sites to malware.
Huge numbers of legitimate websites - perhaps as many as 100,000 according to some reports - fell victim to hackers over the last couple of weeks thanks to SQL injection problems leaving sites vulnerable.

The hacks redirect traffic to sites in China, where click-fraud is used to turn the traffic into profits, and also attempt to drop data-stealing malware onto vulnerable systems.
Starting on December 28th, hackers probed sites for vulnerability to the hack, which may have been caused by some faulty SQL code on sites created using Dreamweaver. The tide of compromises began to go recede around January 5th, but many sites are thought to remain unpatched. Among sites affected are major corporations, including security firm CA - which is thought to have had an infected site for a brief time - government agencies and educational institutions.
More detailed reports of the rash of hacking are in The Register here and in Information Week here.
08 January 2008
Tags:
ca, click fraud, malware, sql injection, vulnerability.
del.icio.us
digg this
ARF published as IETF standard
Abuse report format helps auto-handling of email complaints
02 September 2010
Microsoft releases new fix for DLL vulnerability
Earlier workaround believed to be too complex for most users.
01 September 2010
Malicious tweets link to fake TweetDeck update
Twitter resets passwords for accounts that appear to have been hacked.
01 September 2010
94% of Internet users befriend unknown 'good-looking woman'
Sensitiva data shared after two-hour chat. (1 comment)
31 August 2010
Investment boost for Quick Heal
Indian security firm gets hefty cash injection.
27 August 2010

Quick Links
![]() |
Poll
When do you install software updates?Leave a comment
View 12 comments

2 hours ago
6 hours ago
Malware Prevalence
| Autorun |
|
|---|---|
| Conficker/Downadup |
|
| VB |
|
| Agent |
|
| FakeAlert/Renos |
|
Virus Bulletin currently has 208,232 registered users.



