NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home / News / Security / Incidents

Incidents


New SQL Injection Worm Found Loose on the Web

4,000 websites have been reported to be infected

By Traian Teglet, Technology News Editor

8th of May 2008, 14:28 GMT

Adjust text size:


Google Web Search showing infected sites
Enlarge picture
Not long after a mass attack JavaScript injection was reported to have infected hundreds of thousands of websites, a new SQL injection Worm was found loose on the web. According to the ISC
(Internet Storm Center) website, a total of 4,000 websites have been found infected, after a quick run at a Google search. The report on the above mentioned site clearly states that is unwise to visit the websites mentioned as being infected. They are to be considered dangerous and harmful for your own computer.

The domain name "winzipices.cn" can be found in all of the infected websites HTML source. Searching for the above mentioned domain, on a Google search engine, can get your computer infected, even if you are looking at the "cached" page. It seems that the worm was started somewhere in mid-April, if not earlier. At the moment, the fellows at ISC can provide users with a specific information about how the worm gets into the victims' databases. All they can say is that the worm puts in some scripts and iframes capable of taking visitors to the infected websites.

Users who have reached these infected sites have most likely been infected through a general vulnerability found in the Real Player. Users are to keep their computer software up-to-date, in order to ensure that they aren't affected by the new threat.

Shadowserver.org has detailed how the new threat is working with specific details. Like ISC, the fellows at Shadowserver.org have specifically informed their users NOT to visit any of the presented websites. If the exploits are successful, the users' PCs will be infected with a file dubbed "test.exe", which downloads from a specific IP address, also found on the above mentioned website. The downloaded malware application seems to react in a manner similar to other Chinese malware applications.

TAGS:

SQL | injection | worm | malware
Read by 1,749 user(s) | Add comment | Link to this article TWEET THIS


Article rating:
Good (3.5/5) 7 vote(s)    

Subscribe to news | Print article | Send to friend

© Copyright 2001-2009 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


Military Servers Vulnerable to Trojan Attacks

F-Secure Debuts Internet Security 2009 Beta

Hackers Compromise Webcams to Spy on Teens

Troj/Dloadr-BKU - Yet Another EXE Downloader

Duncan MacMalware, the New Online Highlander

Honest Hacker Cracks F1 Malaysian Site

User opinions:

No user comments yet.
Be the first to express your opinion using the form below!

Share your opinion:

Your Name:
Your Email Address:
(will not be used for commercial purposes)
Solve this to prove you're not a bot: =
Your review/opinion:

 




Windows tabGames tabDrivers tabMac tabLinux tabScripts tabMobile tabHandheld tabGadgets tabNews tab

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM