|
Mass SQL Injection Attack Hits 1 Million Sites |
|
|
|
Source: Dark Reading - Posted by Alex
|
A mass-injection attack similar to the highly publicized LizaMoon attacks this past spring has infected more than 1 million ASP.NET Web pages, Armorize researchers said today. According to database security experts, the SQL injection technique used in this attack depends on the same sloppy misconfiguration of website servers and back-end databases that led to LizaMoon's infiltration.
"This is very similar to LizaMoon," says Wayne Huang, CEO of Armorize, who, with his team, first reported of an injected script dropped on ASP.NET websites that load an iFrame to initiate browser-based drive-by download exploits on visitor browsers to the site.
Read this full article at Dark Reading
Only registered users can write comments. Please login or register. Powered by AkoComment! |