The time now is 07/25/08 - 01:46
Log in: Username: Password:
Search forums for:
  

SQL Injections - Threat for thousands of sites and gamers

Post new topic   Reply to topic
Author Message
windshell
Administrator
Administrator


Joined: 15 Nov 2006
Posts: 1578



PostPosted: 05/02/08 - 05:47    Post subject: SQL Injections - Threat for thousands of sites and gamers Reply with quote

The dynamic nature of websites, powered by back-end databases made thousands of them possible targets for injections of malicious code.

Three domains have been found to host malicious exploits that hit users while they searching the Internet. Those sites are: nmidahena.com, aspder.com and nihaorr1.com. Links to this content are turning up in thousands of links to otherwise innocent websites, thanks to almost unstoppable outbreak of SQL injection attacks.

Approximately 510,000 pages are affected by the attacks on a variety of sites.

Point of this attacks is that the bad people want to drop a gaming Trojan on victims’ systems. With ten million players alone on World of Warcraft, and thousands more on other online games, such Trojans could grab login credentials and steal billing information or in-game valuables.

It’s been found that those attacks now seek out all of the text fields in the database, adding a link to malicious JavaScript to them. The attackers especially look for .asp and .aspx pages.

Any site that offers the ability of content upload, from blogs to forum, could be at risk from the attacks. It’s been suggested however, that webmasters often check their server logs for a section of the injection code they listed in this latest post about the attacks. If it's present, the database needs to be cleaned up, and the application fixed to sanitize incoming content.


News source:

ientry.com
Back to top
r1ky
Super Moderator
Super Moderator


Joined: 18 Jul 2007
Posts: 2429
Location: <--



PostPosted: 05/02/08 - 06:16    Post subject: Reply with quote

this is bad this is bad this is bad this is bad this is bad this is bad

I don't want to be hacked:(
Back to top
The biggest online universe needs another star!
Maybe you are the one!?
» Enter the large universe of Anarchy Online and find out! «
Odus
Super Moderator
Super Moderator


Joined: 06 Oct 2007
Posts: 2587
Location: The 4th Dimension



PostPosted: 05/02/08 - 07:24    Post subject: Reply with quote

Was this why uploading screenshots was disabled or was that part of script errors from database loss?
Back to top
windshell
Administrator
Administrator


Joined: 15 Nov 2006
Posts: 1578



PostPosted: 05/02/08 - 07:25    Post subject: Reply with quote

Nope, I think it's due to database issues.
Back to top
asdasdasd
Supporter
Supporter


Joined: 11 Feb 2008
Posts: 635
Location: Vacation. Leaving July 1. Crawling back in September where I will see BloodyBaron bow down to me!



PostPosted: 05/04/08 - 11:57    Post subject: Reply with quote

i know that people use sql inject exploits on forums such as ipb and phbb and such.
Back to top
mr_bigman
Supporter
Supporter


Joined: 25 Mar 2008
Posts: 58



PostPosted: 05/06/08 - 16:06    Post subject: Reply with quote

im curious, are you saying that SQL injection is a *new* threat?
Back to top
CompleteGibberish
Administrator
Administrator


Joined: 09 Feb 2007
Posts: 6182



PostPosted: 05/20/08 - 12:35    Post subject: Reply with quote

No, he is not. It has been around some 5-6 years, but it is now mainstream targeting groups that could effect gamers
Back to top
Display posts from previous:   
Post new topic   Reply to topic
Page 1 of 1

Related topics:
Michigan nuclear plant explosion, thousands die!
WTS Full S3 HU Warlock, epic flyer, thousands of arena pts..

 





Warning: fopen(/home/sites/realpoor.com/htdocs/test_cache/SQL_Injections___Threat_for_thousands_of_sites_and_gamers_t151307.html) [function.fopen]: failed to open stream: No such file or directory in /home/sites/realpoor.com/htdocs/includes/page_tail.php on line 171

Warning: fwrite(): supplied argument is not a valid stream resource in /home/sites/realpoor.com/htdocs/includes/page_tail.php on line 172

Warning: fclose(): supplied argument is not a valid stream resource in /home/sites/realpoor.com/htdocs/includes/page_tail.php on line 173