Ten thousand servers hit in SQL injection hack

By Tim Conneally | Published May 19, 2008, 4:24 PM

A brute force SQL injection onslaught that began on May 13 has infected a reported 10,000 servers, infecting thousands of Chinese and Taiwanese sites with malware.

Originating from 1,000 servers in a single Chinese facility, the attackers are said to be using automated queries to Google's search engine to identify Web sites with exploitable vulnerabilities. Furthermore, the attacks do not target a single vulnerability, but have shown up through more than ten different holes: MS06-014 (CVE-2006-0003), MS07-017 (CVE-2007-1765), RealPlayer IERPCtl.IERPCtl.1 (CVE-2007-5601),GLCHAT.GLChatCtrl.1 (CVE-2007-5722), MPS.StormPlayer.1 (CVE-2007-4816), QvodInsert.QvodCtrl.1, DPClient.Vod (CVE-2007-6144), BaiduBar.Tool.1 (CVE-2007-4105), VML Exploit (CVE-2006-4868) and PPStream (CVE-2007-4748).

Wayne Huang, CEO of Web application security tools maker Armorize Technology, called the attack "very well designed."

Only last month, a rash of SQL Injection hacks took place on database-driven Web sites that used ASP to generate results. That particular outbreak affected over half a million sites.

Oftentimes, sites are vulnerable to SQL attacks due to negligent coding. Another example of this took place last month when it was made public that Oklahoma's Department of Corrections site was extremely vulnerable. In what could scarcely even be called a "hack," a user could access the site's database through a series of simple SQL commands, subsequently accessing the 10,597 social security numbers and offense records of everyone contained therein.

Armorize Technology reports that SQL attacks saw an exponential leap in frequency between 2004 and 2005, but have since been on the decline, cross-site scripting attacks have been steadily increasing since 2005.

Comments

View comments by with a score of at least

In terms of percentage, there are probably more PHP/Perl/Ruby/Java developers who code out of passion & hobby than there are ASP & VB developers.

Score: 0

|

"infecting thousands of Chinese and Taiwanese sites with malware."

What's the difference between now and every day? I thought it was pretty inherent that if it was one of the two, the "malware" was kind of implied? No? :P

Score: 0

|

Same thing like Black American, Hispanic American, White American, Asian American, etc. It's call divide and conquer.

Score: 0

|

Not-so-mobile battery life: Time to force the issue

Carmi Levy | Wide Angle Zoom: If power efficiency is important when you buy a car or even a motorcycle, why shouldn't it matter for a smartphone?

Microsoft 'worked with Apple' for Silverlight on iPhone, says Goldfarb

By not making such a big deal out of trying to stream video to the iPhone, Microsoft got a big deal out of it, revealed the Silverlight product manager.

Microsoft's Ray Ozzie: 'Nobody's going to be 100% open'

The mobile apps ecosystems of the world may converge over time, led by apps being ported over across platforms, according to the Chief Software Architect.

Without its own 'iTablet' yet, is Apple missing the boat?

Steve Jobs is on record as dissing "single-purpose" devices like e-readers. But given their recent popularity, was that a mistake?

Apple invokes DMCA, claims Psystar is 'trafficking in circumvention devices'

In trying to close the book on possibly the last attempt at a Mac clone, Apple cites from its own landmark case...but may actually be misinterpreting it.

The fallacy of Facebook privacy

Carmi Levy | Wide Angle Zoom: If an insurance company learns something interesting about its client through the Internet, is that snooping?

Clicker.com cuts through the Web video chaos

In a world where homemade video and Hollywood movies travel the same pipeline, it's good to have a real search engine to cut through the clutter.

A case study in improving software: What Office 2010 can learn from Notion 3

A music composition product gambles with a complete overhaul, in an effort to make headway against two well-known competitors in a tough market.

Kindle 2 update adds battery life, native PDF reader

Amazon has pushed out an update to the Kindle 2 e-reader that lengthens battery life and adds a native PDF viewer.

Safari on iPhone gets competition from a $1 browser app

Apple likes to say it gives iPhone users a full browsing experience, but a new competitor tries to incorporate more desktop browser features.