Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: SQL injections - an update SANS ISC InfoSec Forums

Watch ISC TV. Great for NOCs, SOCs and Living Rooms: https://isctv.sans.edu

Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!
SQL injections - an update

In an earlier story  we looked at an SQL injection that has infected close to 1.5 million sites.  The same search now only returns about 175K sites and many of those are discussing the injection.  The URLs I checked were all dead links, so well done everybody in cleaning up isle 3. 

With regards to the second set of SQL injections we talked about here  the number successful injections is still going up.  When I first came across these about 4.5k sites were injected,  now we are up to 33K.  Not a real success story for this particular attack.  The error with the 06014.html page is still not fixed.  The only variation I've seen so far is the target url which changes,  the rest is pretty much the same, the end game is still the stealing of WOW passwords.

People have reported that typically they get two hits from the one IP address and then it moves along. 

Keep an eye on your logs and consider implementing an IDS or use tools such as suhosin for PHP sites,  mod_security for apache, or any other url checking/sanitisation tool.

Mark - Shearwater

Mark

391 Posts
ISC Handler

Sign Up for Free or Log In to start participating in the conversation!