Trojan horse
An SQL injection attack is delivering a 'potent Trojan cocktail' to unsuspecting users

Devastating SQL attack compromises 50,000 sites

Small businesses at risk, warns ScanSafe

Phil Muncaster

A new SQL injection attack has already snared over 50,000 legitimate web sites, and threatens to cause havoc for innocent internet users, according to new research from ScanSafe.

The security-as-a-service firm said in a blog post that it first detected the problem on Friday.

The attack exploits poor coding to insert a malicious iframe on the sites. When visited by a user, an infected site will begin to download what ScanSafe senior security researcher Mary Landesman described as "a potent Trojan cocktail consisting of backdoors, password stealers and a downloader".

The number of infected sites now stands at around 57,000, having jumped by around 9,000 in the past few days.

"These are smaller business sites which unfortunately don't have the aggressive support staff of their larger cousins but, when taken collectively, get very good traffic," she said.

Landesman advised firms to look for information on how to prevent such attacks on the web, where there are even scanning tools to help detect whether there are malicious iframes on a site.

"There is a great deal of information available to small web site operators. It's not something you need to hire expensive consultants to help with. If you've got moderate computer skills and can read and follow instructions, that should be enough, at least in terms of SQL injection attacks."

Microsoft's Developer Network has a useful article called Stop SQL Injection Attacks Before They Stop You.

  • Have your say
  • Send to a friend
  • Print
  • Digg
  • Reddit
  • Share

Do you agree?

Further reading

hackers

IBM launches new web app security tools

Integrated solution helps reduce code vulnerabilities and improve security management

Botnet

MessageLabs spots resilient new breed of botnets

Latest examples can recover from shut down in just 48 hours

East European cyber gangs target the banking sector

Funds transfer fraud reaching new levels

Ashley Greene pictures become latest malware threat

Users warned not to click on image links

Related white papers

Related jobs

Most watched

San Francisco

Views from the Valley: Oracle and HP square off over Hurd

A look at the major stories from the US

ViewSonic ViewPad 7

ViewSonic ViewPad 7 video

Hands on with 7in tablet that features phone capability and Android 2.2

Analysis and Reports

Storage-as-a-Service: Best efforts or best practice?
IDG research: IT professionals understand the fundamentals of managing and protecting data, but do not apply best practices

The seven security myths of Microsoft Windows 7
It is essential to separate myth from reality about the built-in security of Microsoft’s latest offering

Poll

VMworld 2010 poll

VMworld 2010 poll

How advanced is your firm's cloud computing strategy?

View poll results

White paper library

Attachmate

Smartstream

Keep up to date with the latest products, services and technologies from the world's leading IT companies; IThound.com brings you thousands of white papers, case studies and analyst reports.

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Spotlight

Windows XP

Dell sounds death knell for Windows XP

PC maker to stop offering Microsoft OS on new kit...

Salesforce Chatter

Salesforce Chatter coming to iPhones and BlackBerrys

Enterprise social networking tool to be available on the go

San Francisco

Views from the Valley: Oracle and HP square off over Hurd

A look at the major stories from the US

Nokia N8

Nokia unveils price and release date of N8 smartphone

Hotly anticipated device to retail for £429 SIM free from...

Primary Navigation