Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security > Incidents

May 8th, 2008, 14:28 GMT · By

New SQL Injection Worm Found Loose on the Web

SHARE:

Adjust text size:


Google Web Search showing infected sites
Enlarge picture
Not long after a mass attack JavaScript injection was reported to have infected hundreds of thousands of websites, a new SQL injection Worm was found loose on the web. According to the ISC
(Internet Storm Center) website, a total of 4,000 websites have been found infected, after a quick run at a Google search. The report on the above mentioned site clearly states that is unwise to visit the websites mentioned as being infected. They are to be considered dangerous and harmful for your own computer.

The domain name "winzipices.cn" can be found in all of the infected websites HTML source. Searching for the above mentioned domain, on a Google search engine, can get your computer infected, even if you are looking at the "cached" page. It seems that the worm was started somewhere in mid-April, if not earlier. At the moment, the fellows at ISC can provide users with a specific information about how the worm gets into the victims' databases. All they can say is that the worm puts in some scripts and iframes capable of taking visitors to the infected websites.

Users who have reached these infected sites have most likely been infected through a general vulnerability found in the Real Player. Users are to keep their computer software up-to-date, in order to ensure that they aren't affected by the new threat.

Shadowserver.org has detailed how the new threat is working with specific details. Like ISC, the fellows at Shadowserver.org have specifically informed their users NOT to visit any of the presented websites. If the exploits are successful, the users' PCs will be infected with a file dubbed "test.exe", which downloads from a specific IP address, also found on the above mentioned website. The downloaded malware application seems to react in a manner similar to other Chinese malware applications.
FILED UNDER:
SQL
injection
worm
malware

TELL US WHAT YOU THINK:

2,766 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Military Servers Vulnerable to Trojan Attacks

F-Secure Debuts Internet Security 2009 Beta

Hackers Compromise Webcams to Spy on Teens

Troj/Dloadr-BKU - Yet Another EXE Downloader

Duncan MacMalware, the New Online Highlander

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM