Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security

March 31st, 2011, 16:16 GMT · By

LizaMoon Mass Injection Attack Spreads Rapidly

SHARE:

Adjust text size:


LizaMoon attack injects over 1.5 million websites
Enlarge picture
A recently announced mass injection attack dubbed LizaMoon is spreading rapidly and managed to infect over 1.5 million web pages in just a few days.

The mass compromise was announced by Websense on Tuesday, at which time it had already affected some 28,000 pages and made its way onto iTunes.

One interesting aspect of the attack was that by the time researchers spotted the infection, the domain hosting rogue code, lizamoon.com, was already inactive.

While this has not changed, the infection took massive proportions and started using new domains, including worid-of-books.com, alexblane.com, alisa-carter.com and t6ryt56.info.

"We’re seeing compromised websites that were previously inserted with a script leading to lizamoon(dot)com/ur.php already modified to connect to tadygus(dot)com/ur.php. The said URL also resolves to the same IP server as the 4 previously mentioned URLs," Trend Micro researchers warn.

The attack uses SQL injection techniques to insert rogue code into the databases of PHP and ASP websites alike. There is most likely a great deal of automation behind this.

The infections lead to a scareware distribution site that displays fake antivirus alerts in order to convince users to download a rogue application called Windows Stability Center.

At this time, the malicious application has a fairly low detection rate on Virus Total (13/43). After installation it starts displaying all sorts of alerts and advises users to buy a license to fix the problems.

This is obviously a scam and there are no infections, or at least none that this application can remove. Unfortunately, distributing such programs is one of the most profitable cyber criminal activities.

Scareware attacks can take different forms, many of which involve the Web. Because of this, users are advised to always use an up-to-date antivirus that is capable of scanning Web traffic.

TELL US WHAT YOU THINK:

1,944 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:

New Mass SQL Injection Attack Infects Thousands of PagesTrojan Distributed in New Mass Injection Attack via Java DownloaderPolymorphic Injection Attack Targets WordPress BlogsWebsites Hosted at Go Daddy Under Siege in Mass Injection Attacks

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM