All the latest UK technology news, reviews and analysis

Websense warns of major SQL attack on iTunes and others

by Iain Thomson

30 Mar 2011

Be the first to comment

  • Tweet this

Internet monitoring firm Websense is warning of a huge SQL attack that has succeeded in infecting over 28,000 legitimate internet sites.

Dubbed LizaMoon after the originating domain lizamoon.com, the attack injects a single line of code into web sites that link the viewer to a well-known fake security software site at defender-uqko.in.

The attacking domain and the linking site are currently offline, but Websense said this could change at any time at the whim of the attacker. The lizamoon.com domain was set up three days ago using data which appears to be faked.

Websense has spotted some of the code in iTunes URLs, but said that Apple's security policies would have blocked any attack.

"The way iTunes works is that it downloads RSS/XML feeds from the publisher to update the podcast and list of available episodes. We believe that these RSS/XML feeds have been compromised with the injected code," Websense said in a blog post.

"The good thing is that iTunes encodes the script tags, which means that the script doesn't execute on the user's computer. So good job, Apple."

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

35%

0%

10%

55%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Symanteccloud

Social networking: a guide for IT managers

Social networking is almost ubiquitous. This white paper examines the benefits and risks and it looks at the different ways companies can reconcile them

Riverbed

Mitigating the risks of IT change

The importance of understanding your infrastructure

Flash Developer- actionscript, AJAX, JSON

Flash Developer- Actionscript 3.0, AJAX, JSON, computer...

Business Analyst, Risk platform, Equity Derivs, Investment Bank

Business Analyst - Risk platform - Equity Derivatives...

Java Developer - Algorithmic Trading - Global Trading Business

Java Developer - Algorithmic Trading - Global Trading...

Junior Treasury Project Manager, Tier One Investment Bank

Junior Middle Office Project Manager, Treasury, IB...

To send to more than one email address, simply separate each address with a comma.