NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home / News / Security / Incidents

Incidents


Hundreds of Thousands of Websites Compromised

Mass attack JavaScript injection compromises a huge number of pages

By Bogdan Popa, Security and Search Engines Editor

24th of April 2008, 07:47 GMT

Adjust text size:


There is a huge number of compromised websites. Notice the link to the JavaScript included in the compromised websites' sources
Enlarge picture
Security companies around the world launched an alert concerning a new mass SQL infection which, by the first estimations, had already affected hundreds of
thousands of websites. And what's worse isn't necessarily the huge number of compromised pages, but the fact that among the affected ones, we can easily find UN and UK government websites. Most compromised pages can be found using web's search engines and searching for a certain term which I'm not going to disclose especially for security purposes.

According to security company Websense, when a visitor loads one of the compromised websites, it attempts to open a malicious JavaScript file called 1.js which is hosted on the main website. Although similar activities were spotted a few weeks ago, the attacks seem to be different, first of all due to the domain used.

"Once loaded, the file attempts 8 different exploits (the attack last April utilised 12). The exploits target Microsoft applications, specifically browsers not patched against the VML exploit MS07-004 as well as other applications. Ominously files named McAfee.htm and Yahoo.php are also called by 1.htm but are no longer active at the time of writing," Websense informs.

As mentioned, there are hundreds of thousands of compromised websites, most of them being searchable on Google or Yahoo. "There's another round of mass SQL injections going on which have infected hundreds of thousands of websites. Doing a Google search shows over 510,000 modified pages," security company F-Secure reports. Websense confirms the number of affected websites, too. "The number of sites affected is in the hundreds of thousands," it said.

Just as usual, users are advised to keep their antiviruses and firewall open, apply the latest patches and virus definitions and try to avoid websites that look suspicious and may attempt to drop malicious files on their computers.

TAGS:

google | security | javascript
Read by 1,357 user(s) | Add comment | Link to this article TWEET THIS


Article rating:
Good (3.6/5) 6 vote(s)    

Subscribe to news | Print article | Send to friend

© Copyright 2001-2009 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


Users Concerned about Google Account's Privacy

Google Rolls Out Anti-Phishing Filter

Is Internet Explorer Safer Than Firefox, Opera and Safari?

Social Security Numbers Found by Googling

Russia, Malware Producing Demon

User opinions:

No user comments yet.
Be the first to express your opinion using the form below!

Share your opinion:

Your Name:
Your Email Address:
(will not be used for commercial purposes)
Solve this to prove you're not a bot: =
Your review/opinion:

 




Windows tabGames tabDrivers tabMac tabLinux tabScripts tabMobile tabHandheld tabGadgets tabNews tab

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM