Geekpedia Programming Tutorials






Half A Million Poorly Coded Sites Attacked

Half A Million Poorly Coded Sites Attacked

On Monday, April 28th 2008 at 09:17 PM
By Andrew Pociu (View Profile)

Microsoft SQL ServerA massive SQL injection attack affected over half a million web sites that use Microsoft SQL Server. The attack was faciliated through a SQL injection; the worm searches for URLs with the extension "asp" or "aspx" that have a query string, and it injects malicious JavaScript and HTML code into every paramater of that query string.

The attack is rather traditional and doesn't involve any security holes in the server or database software. The difference, according to Jeremiah Grossman - CTO of White Hat Security, lays in "the size and the level of sophistication."

Microsoft said they will not release a patch because the cause doesn't lay in a security hole but in the poor coding practices of the web developers. These developers, according to Microsoft, have failed to filter out the user-input data coming from web forms and query strings (through GET and POST requests) before inserting it in the SQL query. Microsoft has encouraged programmers to review their coding practices and read the guide entitled Improving Web Application Security: Threats and Countermeasures.

Google, in an attempt to decrease the success of the attack, has temporarily removed the sites that appeared to be infected from its index.

Digg Digg It!     Del.icio.us Del.icio.us     Reddit Reddit     StumbleUpon StumbleIt     Newsvine Newsvine     Furl Furl     BlinkList BlinkList

Comment Current Comments
by k3n on Thursday, May 15th 2008 at 09:30 PM

I'm surprised there aren't more of these attacks, given the lousy state of most sites today.


Comment Comment on this news article
Name: Email:
Message:
Comment Related News
In Contest, Mac OS X Hacked In Over A Minute

In Contest, Mac OS X Hacked In Over A Minute

On Saturday, March 29th 2008 at 04:04 PM by Andrew Pociu


Comment Popular News
Bill Gates Gives Teary Farewell Speech

Bill Gates Gives Teary Farewell Speech

On Tuesday, July 1st 2008 at 06:51 PM by Andrew Pociu

2009 Chrysler Cars To Feature Wi-Fi

2009 Chrysler Cars To Feature Wi-Fi

On Saturday, June 28th 2008 at 10:33 PM by Andrew Pociu

Latest Tech Bargains

Advertisement

Free Magazine Subscriptions

Today's Pictures

Today's Video

Other Resources

Latest Download

Latest Icons