The malicious iFrame attack infected 1,000 web pages by exploiting vulnerabilities in web applications.
A new malware script surfaced on Friday that used a SQL injection attack to infect about 1,000 web pages with a malicious iFrame. The attack was a variation on last week's robint-us SQL mass infection, which similarly infected an estimated 7,000 Web pages.
Affected sites this time included the websites of Ameristar Casinos, Chicago's WBEZ public radio station, the Service Women's Action Network (for the second time), IndustryWeek, the European platform for food sovereignty, and Spain-holiday. Some of those sites continue to be infected.
Malicious iFrame attacks embed a malicious script in a web page, causing it to connect to a feeder site and download further malicious code. Different attacks then take different tacks, with the script either exploiting a browser vulnerability to run the malicious code automatically, or else attempting to trick a user into running it.
The new malware script points to http://2677.in/yahoo.js. According to security firm Sucuri, the attack script "loads malware from http://2677.in/ie.html, which then calls http://s11.cnzz.com to load the virus."
More info
Volut-ID | World News Articles
All news of interest and can provide an info for you, and so can assist in the search for new news.
About news gadgets, mobile phones
info about the latest mobile phone, from news, features, and the most mobile phone models in search of the world.
SQL Injection Attacks Return
Related Post
SQL Injection
- Safe3 Sql Injector v.8.1 released
- Fastest Online SQL Injection Dumper
- Fastest Online SQL Injection Dumper
- Barracuda Networks website Hacked
- Barracuda Networks website Hacked
- MySql.Com hacked
- MySql.Com hacked
- aidSQL SQL Injection Detection And Exploitation Tool
- aidSQL SQL Injection Detection And Exploitation Tool
- Trustwave's Global Security Report 2011: Web Application Risks
- Trustwave's Global Security Report 2011: Web Application Risks
- SQL Smuggling
- SQL Smuggling
- SqlInjector v1.0.2 released
- SqlInjector v1.0.2 released
- Blind Cat - Blind SQL Injection Exploitation tool
- Blind Cat - Blind SQL Injection Exploitation tool
- SQL Injection Attacks Return
- Hexjector v1.0.7.3 Special Edition
- Hexjector v1.0.7.3 Special Edition
- ExploitMyUnion v2.1
- ExploitMyUnion v2.1
- Safe3 SQL Injector
- Safe3 SQL Injector
Malware
- YARA v.1.5 released
- YARA v.1.5 released
- Botnets: Measurement, Detection, Disinfection and Defence
- Botnets: Measurement, Detection, Disinfection and Defence
- Symantec Report on Attack Kits and Malicious Websites
- Symantec Report on Attack Kits and Malicious Websites
- THE CYBER-CRIME BLACK MARKET: UNCOVERED
- THE CYBER-CRIME BLACK MARKET: UNCOVERED
- REMnux v.2.0 Released
- REMnux v.2.0 Released
- PandaLabs Annual Report 2010
- PandaLabs Annual Report 2010
- Zozzle: Low-overhead Mostly Static JavaScript Malware Detection
- Zozzle: Low-overhead Mostly Static JavaScript Malware Detection
- Koobface: Inside a Crimeware Network
- Koobface: Inside a Crimeware Network
- The Zeus malware R&D program
- The Zeus malware R&D program
- Kaspersky download site hacked to spread fake AV
- Kaspersky download site hacked to spread fake AV
- W32.Stuxnet Dossier
- W32.Stuxnet Dossier
- Stuxnet Under the Microscope
- Stuxnet Under the Microscope
- The Rise of PDF Malware
news
- Video Chat Present at Google's Android Phone Applications Talk Through
- Nokia launches QT SDK version 4.7
- Transformer Robot Now Comes In Real Life!
- Windows Update 7 Phone Promising Bing Mango Vision, Audio, Voice to SMS, Turn by Turn Navigation
- Via launches Quad-Core Processors New Most Powersave
- Miyu Uehara Dead, Suicide Suspected
- Avril Lavigne Demand Many thing to Appear In Indonesia
- Hina Allies: Meet Qaddafi Chieftains at the Hotel of the Same with Foreign Journalists Stay
- Microsoft Buy Skype 7 Billion U.S. Dollars
- Toyota Production Expected in June Upcoming Restored
- Find Out if You’re a Target in the Biggest U.S. BitTorrent Lawsuit Ever
- BHP L2201x Elite 21.5 Inch LCD Monitor SUPER THIN COOL Only 10 mm
- AMD Phenom X4 II 980 Black Edition 3.7 Ghz Newest speeding Up
- Ubuntu Light & Unity For Ubuntu Ubuntu Netbook Edition of Light & Fast
- Gnome 3 Latest Released New Interface Gives Linux Experience
- Russian Muslims Need Help Indonesia
- Super Cheap Computer, Only 25 U.S. Dollars
- Zam-Zam water Reportedly Contaminated
- Barracuda Networks website Hacked
- Barracuda Networks website Hacked
- GNOME 3.0 Has Been Officially Released
- The Social-Engineer Toolkit (SET) v1.3 Released
- The Social-Engineer Toolkit (SET) v1.3 Released
- MySql.Com hacked
- MySql.Com hacked
Labels:
Malware,
news,
SQL Injection
No response to “SQL Injection Attacks Return”
Leave a reply