Ten thousand servers hit in SQL injection hack

By Tim Conneally | Published May 19, 2008, 4:24 PM

A brute force SQL injection onslaught that began on May 13 has infected a reported 10,000 servers, infecting thousands of Chinese and Taiwanese sites with malware.

Originating from 1,000 servers in a single Chinese facility, the attackers are said to be using automated queries to Google's search engine to identify Web sites with exploitable vulnerabilities. Furthermore, the attacks do not target a single vulnerability, but have shown up through more than ten different holes: MS06-014 (CVE-2006-0003), MS07-017 (CVE-2007-1765), RealPlayer IERPCtl.IERPCtl.1 (CVE-2007-5601),GLCHAT.GLChatCtrl.1 (CVE-2007-5722), MPS.StormPlayer.1 (CVE-2007-4816), QvodInsert.QvodCtrl.1, DPClient.Vod (CVE-2007-6144), BaiduBar.Tool.1 (CVE-2007-4105), VML Exploit (CVE-2006-4868) and PPStream (CVE-2007-4748).

Wayne Huang, CEO of Web application security tools maker Armorize Technology, called the attack "very well designed."

Only last month, a rash of SQL Injection hacks took place on database-driven Web sites that used ASP to generate results. That particular outbreak affected over half a million sites.

Oftentimes, sites are vulnerable to SQL attacks due to negligent coding. Another example of this took place last month when it was made public that Oklahoma's Department of Corrections site was extremely vulnerable. In what could scarcely even be called a "hack," a user could access the site's database through a series of simple SQL commands, subsequently accessing the 10,597 social security numbers and offense records of everyone contained therein.

Armorize Technology reports that SQL attacks saw an exponential leap in frequency between 2004 and 2005, but have since been on the decline, cross-site scripting attacks have been steadily increasing since 2005.

Comments

View comments by with a score of at least

In terms of percentage, there are probably more PHP/Perl/Ruby/Java developers who code out of passion & hobby than there are ASP & VB developers.

Score: 0

|

"infecting thousands of Chinese and Taiwanese sites with malware."

What's the difference between now and every day? I thought it was pretty inherent that if it was one of the two, the "malware" was kind of implied? No? :P

Score: 0

|

Same thing like Black American, Hispanic American, White American, Asian American, etc. It's call divide and conquer.

Score: 0

|

Google Chrome 4: Yes, it's fast, but is it usable?

As Betanews readers have responded to our stories about Chrome's JavaScript superiority...Does that mean we'd actually use this browser? Well...

Video: Netflix on PlayStation 3

Netflix has come to the PlayStation 3 via Blu-ray and BD-Live.

Verizon Wireless launches new Android, Chocolate, and ruggedized phones

The lower-priced Eris joins the Droid, while the Chocolate gets a touchscreen and more music playback.

Early sales figures for Windows 7 nicely high, but do we know why?

Fans of triple-digit surges in figures quoted by Betanews will love this one, as it appears Microsoft rediscovered how to pull off a software launch.

Myka announces its latest Linux-based 'net top box'

Myka's ION brings Boxee, XMBC, and much more to HDTVs.

What hath Mac wrought? A remembrance after a quarter-century

The reason there's a Macintosh today is not because of some brilliant flash of engineering genius, but because Apple had the audacity to learn from its mistakes.

Early build of Moblin 2.1 improves connectivity, but not device support

The Linux Foundation's Atom-centric OS yesterday received a major overhaul with the project release of Moblin 2.1 for netbooks and nettops.

The iPhone's China syndrome: Sales of 5,000 and climbing

There's actually a country where Apple's device is not a godsend, where sales can be measured in the dozens.

New European counterpart to FCC will ensure 'a more neutral net'

Late Thursday night, the ruling telecom administrators of the EU's member nations signed away their final authority to a new entity overseen by the EC.

Sophos study suggests Windows 7 UAC's default setting is self-defeating

Without any anti-virus installed, a Sophos test showed, User Account Control was only capable of thwarting just one malware package out of ten samples chosen.

Indiscreet tweet trips awareness of Web SSL vulnerability

A group of high-level security engineers had been making progress on thwarting a low-level threat to the Web, until somebody blurted it all out on Twitter.