Over 1.5 million pages affected by the recent SQL injection attacks
Summary: In an attempt to mitigate the impact of the recent waves of SQL injection attacks, and provide more transparency into the approximate number of affected pages, the Shadowserver Foundation is starting to maintain a list of all the malicious domains used in the continuing efforts by copycats to inject as many legitimate sites as possible. Currently counting over fifty malicious domains, and the corresponding number of affected pages by them, the total number is just over 1.
In an attempt to mitigate the impact of the recent waves of SQL injection attacks, and provide more transparency into the approximate number of affected pages, the Shadowserver Foundation is starting to maintain a list of all the
malicious domains used in the continuing efforts by copycats to inject as many legitimate sites as possible. Currently counting over fifty malicious domains, and the corresponding number of affected pages by them, the total number is just over 1.5 million.
Needless to say to stay away from these domains if you don't know what you're doing. The Shadowserver's announcement :
"Below is a list of domains used in the mass SQL injections that insert malicious javascript into websites. We've also included an approximate number of pages infected (according to Google). Note that these numbers decay with time. Some of these domains were injected long ago and have been cleaned. At their height, their numbers may have been larger."
Despite that some of the malicious domains are down, or in a process of getting shut down, as long as the long tail of SQL injection attacks is possible due to vulnerable sites at the far corner of the Web, the bad guys would simple keep re-introducing new domains within, or emphasize on increasing their life cycle by fast-fluxing them as we've already seen this happen.
Kick off your day with ZDNet's daily email newsletter. It's the freshest tech news and opinion, served hot. Get it.
Talkback
So...
Yes.
If that's so, then...
No.
Bad Programmers
Payton Byrd
http://blogs.ittoolbox.com/visualbasic/dotnet
amen !!
If something is systemic, ...
RE: Over 1.5 million pages affected by the recent SQL injection attacks
That and...
As the saying goes, a little knowledge is a dangerous thing.
(1)I know I'm abusing this word, but I don't really care.
RE: Over 1.5 million pages affected by the recent SQL injection attacks
Popular targets?
Of late I am hearing that the attacks are targeting IIS/SQL Server systems. This seems plausible to the extent that such systems are common and tend to be poorly secured ( if at all ) by rank amateur mouse actuator types, but is there a particular vulnerability with this platform?
RE: Over 1.5 million pages affected by the recent SQL injection attacks
RE: Over 1.5 million pages affected by the recent SQL injection attacks
SQL Injection is really a very big problem, the affected website will not be fixed easily regardless the time and money!
RE: Over 1.5 million pages affected by the recent SQL injection attacks