Thousands of web servers hit by SQL attack

Internet security firm Secure Computing has issued a warning of an SQL injection attack that appears to have infected several thousand web servers, including government and financial services sites.

According to a blog on the company's TrustedSource information site, the attack began late last Friday. It targets machines running Microsoft SQL Server.

The post said that web servers running back-end Sybase databases could also be exploited.

Sybase largely uses the same SQL syntax and table structure as SQL Server.
 
Visitors to infected web servers could be sent one of many different forms of malware, TrustedSource warned.

“Similar to phishing, this attack takes advantage of the website visitor's trust in the site they are visiting," the post said. "Instead of phishing for information, however, malware is sent to the client, which the client has a higher likelihood of accepting being from a trusted site."
 
This type of attack SQL attack could be used to launch phishing attacks on sites requesting financial information, or any other type of attack where the visitors' trust can be exploited, warned TrustedSource.
 
“As of today, this attack is still working and ongoing. We are seeing evidence of successful exploitation attempts across hundreds of web pages," the post said. "These web pages are associated with websites from around the world and supplying various content including government sites, sales sites, real estate sites, and financial information sites, among others."

 

More in News

Privacy-bolstering "Apps Act" introduced in House

The bill would provide consumers nationwide with similar protections already enforced by a California law.

Microsoft readies permanent fix for Internet Explorer bug used in energy attacks

Microsoft is prepping a whopper of a security update that will close 33 vulnerabilities, likely including an Internet Explorer (IE) flaw that has been used in targeted website attacks against the U.S. government.

Weakness in Adobe ColdFusion allowed court hackers access to 160K SSNs

Up to 160,000 Social Security numbers and one million driver's license numbers may have been accessed by intruders.