May 19, 2008

Update: Mass SQL injection attack targets Chinese Web sites

Attack has implanted malware in thousands of Web sites in China and Taiwan

Web sites across China and Taiwan are being hit by a mass SQL injection attack that has implanted malware in thousands of Web sites, according to a security company in Taiwan.

First detected on May 13, the attack is coming from a server farm inside China, which has made no effort to hide its IP addresses, said Wayne Huang, chief executive officer of Armorize Technologies, in Taipei.

"The attack is ongoing, ... even if they can't successfully insert malware, they're killing lots of Web sites right now, because they're just brute-forcing every attack surface with SQL injection, and hence causing lots of permanent changes to the victim Web sites," Huang said.

In a SQL injection attack, an attacker attempts to exploit vulnerabilities in custom Web applications by entering SQL code in an entry field, such as a login. If successful, such an attack can give the attacker access to data on the database used by the application and the ability to run malicious code on the Web site.

A screenshot of a Web site belonging to the Mackay Memorial Hospital in Hsinchu, Taiwan, showed the rendering of the site had been affected and displayed the SQL string injected by the attack, Huang said.

Thousands of Web sites have been hit by the attack, he said, noting that 10,000 servers alone were infected by malware last Friday. Most of the affected servers are located in China, while some are located in Taiwan, Huang said. The attackers appear to be using automated queries to Google's search engine to identify Web sites vulnerable to the attack, he said.

Among the sites hit by the attack on Friday were Soufun, a real estate Web site, and Mycar168, a site for automobile enthusiasts.

The attackers aren't targeting a specific vulnerability. Instead they are using an automated SQL injection attack engine that is tailored to attack Web sites using SQL Server, Huang said. The attack uses SQL injection to infect targeted Web sites with malware, which in turn exploits vulnerabilities in the browsers of those who visit the Web sites, he said, calling the attack "very well designed."

The malware injected by the attack comes from 1,000 different servers and targets 10 vulnerabilities in Internet Explorer and related plugins that are popular in Asia, Huang said.

The vulnerabilities are MS06-014 (CVE-2006-0003), MS07-017 (CVE-2007-1765), RealPlayer IERPCtl.IERPCtl.1 (CVE-2007-5601),GLCHAT.GLChatCtrl.1 (CVE-2007-5722), MPS.StormPlayer.1 (CVE-2007-4816), QvodInsert.QvodCtrl.1, DPClient.Vod (CVE-2007-6144), BaiduBar.Tool.1 (CVE-2007-4105), VML Exploit (CVE-2006-4868) and PPStream (CVE-2007-4748).

Mass SQL injection attacks have increasingly become a security threat. In January, tens of thousands of PCs were infected by an automated SQL injection attack. That attack was tailored to target Microsoft's SQL Server.

Correction: This story as originally posted  incorrectly stated the nature of a mass SQL injection attack in January. The article has been amended.

Close

On Twitter now

Security

Powered by Twitter

On Twitter now

White Paper

D2D Virtual Tape Library Replication Primer

This whitepaper explains the terminology and concepts behind Data Replication technologies and establishes some sizing rules through worked examples. Learn the new paradigm in disaster tolerance—protect data anywhere.

Download now »

Trial

Free 30-Day Desktop Virtualization Trial

Download a free 30–day trial and experience how XenDesktop delivers a pristine, on–demand desktop experience to users on whatever device they choose, while cutting IT complexity and costs.

Download now »

White Paper

Why Your Firewall, VPN, and IEEE 802.11i Aren't Enough to Protect Your Network

The emergence of WLANs has created a new breed of security threats to enterprise networks.

Included in HP ProCurve WLAN solutions is security technology that alleviates threats from WLANs through:
* Monitoring wireless activity inside and out of the enterprise
* Classifying WLAN transmissions into harmful and harmless
* Preventing transmissions that pose a security threat to the enterprise network
* Locating participating devices for physical remediation

Download now »

Sign up to receive Security Resource Alerts

Subscribe to the Security Central Newsletter

Stay informed of the latest security threats and fixes.

White paper

Comprehensive Data Protection for Storage Appliances

With the continuous expansion of data capacity, completing the full cycle of a scheduled scan can be a very time consuming process. Find out how to efficiently secure EMC Celerra with centralized virus scanning, virus pattern file updates, event reporting and antivirus configuration.

Download now! »

White paper

Secure Celerra Environments with Minimal Overhead

A single virus-infected file in a storage system can be responsible for infecting large amounts of data. This white paper details the architecture and product features of Trend Micro's data storage security solution, ServerProtect, and discusses how it has been designed to protect EMC Celerra file servers with minimal overhead.

Download now! »
White paper

Keep Linux Servers Free from Malware

The increase in Linux popularity has increased the frequency and sophistication of malware attacks. Learn how you can protect your Linux environment with real-time protection that is certified by all major Linux vendors.

Download now! »

White paper

Centrally Managed Virus Protection for Windows and NetWare

With the emergence of mixed threat attacks, a failure on a single server can quickly impact the entire network. Learn how a technology that is designed to remove and block infected files on application and file servers prevents the virus from reaching users and keeps your Windows network free from malware.

Download now! »
©1994-2009 Infoworld, Inc.