Microsoft denies fault for massive SQL attack
By Asavin Wattanajantra,
Microsoft has denied that there is any vulnerability in its Internet Information Services (IIS) or SQL server after reports of a massive SQL injection infecting hundreds of thousands of web pages.
The automated attack was reported by F-Secure to have infected more than half a million websites, including those of the United Nations and the UK government. These had been hacked and modified to download malware to visitor's computers, resulting in many being shut down.
Microsoft denied it was due to any new or unknown vulnerabilities in ISS or SQL. It also said the Security Advisory that was published on 17 April which flagged up vulnerability in Windows was unconnected to the incident.
"The attacks are facilitated by SQL injection and are not related to issues related to IIS 6.0, ASP, ASP.Net or Microsoft SQL technologies," said Bill Sisk, a communications manager at Microsoft's Security Response Centre on the IIS blog.
It was claimed that attackers created an automated attack which took advantage of SQL injection vulnerabilities in web pages which did not follow security best practices for web application development.
Microsoft said that even though the attacks targeted sites hosted on IIS web servers, the vulnerabilities could be found on any platform.
Data security provider Secerno claimed that this was the first database threat that was equal in size and scope with well-known PC and virus attacks.
"What is different about this threat is that it automates attacks that were previously done by hand. This capability has increased both the threat level and the possible number of sites infected significantly," said Steve Moyle, chief technology officer at Secerno.
"The attack works by exploiting weaknesses on the web site to gain access to the website and essentially take it over. Once in control of the database, the SQL injection takes every piece of data and adds a link with a malicious Java script."
He added: "When a web visitor goes to a page and clicks on a link with the infected Java script, his computer becomes infected."
advertisement
Latest Security Features
Who should be Britain’s cyber security czar?
Experts reveal what a UK head of cyber security would need to do, while we put forward possible candidates for the role.
- The reality of movie technology
- Do smartphones need security software?
- Protecting the London 2012 Olympic Games
- Focus on... Flexible working
- Cyber policing and surveillance in Britain today
- How an FBI agent transformed Microsoft security
- Can security concerns kill cloud computing?
- GhostNet: Did the Chinese government hack the world?
- How poor web security nearly lead to a jail term
Latest Security Reviews
HP BladeSystem c3000 review: blade server
Rating: ![]()
- CA ARCserve Backup r12.5 review
- FaceTime Communications USG530 - web filtering appliance review
- Guardium 7 – database security review
- Google Apps Premier Edition
- SmoothWall UTM-1000 review
- Lenovo ThinkPad USB Portable Secure Hard Drive
- LogRhythm LR-500-XM review
- EXCLUSIVE - eSoft ThreatWall 250
- Zebra RZ400 - RFID Printer
advertisement
Latest News Videos in Security
Video: Mobile security threats and Mac complacency
Part two: Eugene Kaspersky, chief executive and founder of Kaspersky Lab, talks about the increasing security threats mobile users are facing.
Whitepapers
Want more background on today's hottest IT trends?
Visit IT PRO's whitepaper library for more on virtualisation, encryption and other topics.
Register for IT PRO
You'll get exclusive member benefits including free whitepapers, downloads, Webinars and weekly newsletters full of the latest IT PRO news, reviews, insight and expertise.



Social Bookmark this article: What is this?