The malicious iFrame attack infected 1,000 web pages by exploiting vulnerabilities in web applications.
A new malware script surfaced on Friday that used a SQL injection attack to infect about 1,000 web pages with a malicious iFrame. The attack was a variation on last week's robint-us SQL mass infection, which similarly infected an estimated 7,000 Web pages.
Affected sites this time included the websites of Ameristar Casinos, Chicago's WBEZ public radio station, the Service Women's Action Network (for the second time), IndustryWeek, the European platform for food sovereignty, and Spain-holiday. Some of those sites continue to be infected.
Malicious iFrame attacks embed a malicious script in a web page, causing it to connect to a feeder site and download further malicious code. Different attacks then take different tacks, with the script either exploiting a browser vulnerability to run the malicious code automatically, or else attempting to trick a user into running it.
The new malware script points to http://2677.in/yahoo.js. According to security firm Sucuri, the attack script "loads malware from http://2677.in/ie.html, which then calls http://s11.cnzz.com to load the virus."
More info
Volut-ID | World News Articles
All news of interest and can provide an info for you, and so can assist in the search for new news.
About news gadgets, mobile phones
info about the latest mobile phone, from news, features, and the most mobile phone models in search of the world.










No response to “SQL Injection Attacks Return”
Leave a reply