The time now is 05/18/08 - 03:25
Log in: Username: Password:
Search forums for:
  

SQL Injections - Threat for thousands of sites and gamers

Post new topic   Reply to topic
Author Message
windshell
Administrator


Joined: 15 Nov 2006
Posts: 1368



PostPosted: 05/02/08 - 05:47    Post subject: SQL Injections - Threat for thousands of sites and gamers Reply with quote

The dynamic nature of websites, powered by back-end databases made thousands of them possible targets for injections of malicious code.

Three domains have been found to host malicious exploits that hit users while they searching the Internet. Those sites are: nmidahena.com, aspder.com and nihaorr1.com. Links to this content are turning up in thousands of links to otherwise innocent websites, thanks to almost unstoppable outbreak of SQL injection attacks.

Approximately 510,000 pages are affected by the attacks on a variety of sites.

Point of this attacks is that the bad people want to drop a gaming Trojan on victims’ systems. With ten million players alone on World of Warcraft, and thousands more on other online games, such Trojans could grab login credentials and steal billing information or in-game valuables.

It’s been found that those attacks now seek out all of the text fields in the database, adding a link to malicious JavaScript to them. The attackers especially look for .asp and .aspx pages.

Any site that offers the ability of content upload, from blogs to forum, could be at risk from the attacks. It’s been suggested however, that webmasters often check their server logs for a section of the injection code they listed in this latest post about the attacks. If it's present, the database needs to be cleaned up, and the application fixed to sanitize incoming content.


News source:

ientry.com
Back to top
r1ky
Super Moderator


Joined: 18 Jul 2007
Posts: 2234
Location: Behind you...



PostPosted: 05/02/08 - 06:16    Post subject: Reply with quote

this is bad this is bad this is bad this is bad this is bad this is bad

I don't want to be hacked:(
Back to top
Odus
Super Moderator


Joined: 06 Oct 2007
Posts: 2042
Location: The 4th Dimension



PostPosted: 05/02/08 - 07:24    Post subject: Reply with quote

Was this why uploading screenshots was disabled or was that part of script errors from database loss?
Back to top
windshell
Administrator


Joined: 15 Nov 2006
Posts: 1368



PostPosted: 05/02/08 - 07:25    Post subject: Reply with quote

Nope, I think it's due to database issues.
Back to top
asdasdasd
Luke Warm
Luke Warm


Joined: 11 Feb 2008
Posts: 233



PostPosted: 05/04/08 - 11:57    Post subject: Reply with quote

i know that people use sql inject exploits on forums such as ipb and phbb and such.
Back to top
mr_bigman
Supporter


Joined: 25 Mar 2008
Posts: 58



PostPosted: 05/06/08 - 16:06    Post subject: Reply with quote

im curious, are you saying that SQL injection is a *new* threat?
Back to top
Display posts from previous:   
Post new topic   Reply to topic
Page 1 of 1

Related topics:
Michigan nuclear plant explosion, thousands die!
WTS Full S3 HU Warlock, epic flyer, thousands of arena pts..