New mass SQL injection attack could be forming

Yet another massive SQL injection attack may be underway, according to the SANS Internet Storm Center.

Based on a Google search of the malicious string being used, more than 4,000 websites have been infected, SANS handler Mark Hofman said in a post Friday. That's a rapid rise from Thursday, the day the ambush was first detected, when only about 80 sites appeared to be compromised.

Impacted sites appear to be running Microsoft Internet Information Services (IIS) or Microsoft SQL web servers, and are using software from ASP.NET or ColdFusion, Hofman said.

Visitors to hacked sites, which are vulnerable because they haven't fully patched their applications and the databases that support them, are being redirected to pages trying to push rogue anti-virus programs or another payload.

"The hex will show in the IIS log files, so monitor those," Hofman wrote. "Make sure that applications only have the access they require, so if the page does not need to update a (database), then use an account that can only read."

He also recommended blocking access to the malicious redirect site.

Similar waves of SQL injection attacks have been common for years, including a major one that occurred earlier this year.

Sign up to our newsletters

More in News

House Intelligence Committee OKs amended version of controversial CISPA

Despite the 18-to-2 vote in favor of the bill proposal, privacy advocates likely will not be satisfied, considering two key amendments reportedly were shot down.

Judge rules hospital can ask ISP for help in ID'ing alleged hackers

The case stems from two incidents where at least one individual is accused of accessing the hospital's network to spread "defamatory" messages to employees.

Three LulzSec members plead guilty in London

Ryan Ackroyd, 26; Jake Davis, 20; and Mustafa al-Bassam, 18, who was not named until now because of his age, all admitted their involvement in the hacktivist gang's attack spree.