Skip to navigation
   
Asavin Wattanajantra's Blog

SQL injection botnets now used for large-scale fraud

By Asavin Wattanajantra in Editorial

Posted in botnet, fraud, RSA on August 20, 2009 at 2:10 pm

Permalink | Author Profile

In my last blog I wrote about how SQL injection attacks were used in the case in America where 130 million debit and credit card details were stolen.

To make things a little bit more clearer, SQL injection attacks are where an hacker attacks the database of a website and executes unauthorised commands by taking advantage of insecure code.

Albert Gonzales and others were alleged to have used this technique after researching their payment processing systems.

I asked RSA security expert Uri Rivner by email about how they would have used it to get such a large number of card numbers.

He said: “The SQL self-expanding botnet was a stroke of breakthrough creativity, and I’d say its timing was just right for the fraud community.

“In the past couple of years, Trojans - once the tools of the very savvy high end of cyber crime - have become cheaper and easier to use, but there was one thing missing: scale.

“In order to really capitalise on Trojan technology, fraudsters had to look for ways to distribute their malware to a huge amount of victims.”

He said that criminals now had the scalability they needed, and used the example of a mammoth phishing operation called RockPhish that had a change of heart and migrated to Asprox - an SQL injection botnet.

12345
Not yet rated
Loading ... Loading ...

 

Meeting EMC and RSA in Las Vegas (and watching the Goo Goo Dolls)

By Asavin Wattanajantra in Editorial

Posted in EMC, RSA, las vegas, Security on May 16, 2008 at 3:45 pm

Permalink | Author Profile

Ah the press trip. The journalist’s reward for crap pay and long hours. And how about it - I’m going to Sin City tomorrow.

I’m covering the huge EMC World Conference in Manderlay Bay, so I’ll be hearing guys like Joe Tucci talking about storage for EMC and more interestingly for me thanks to my security beat Arthur Coviello talking about the security aspects for RSA.

12345
Rated: 60% (2 votes)
Loading ... Loading ...

 

   
Tag cloud

Olympics kill bendy smartphone government Wherecloud Firefox downloading Google Digg Mozilla paranoia Twitpocalypse PR SQL injection remote working internet phone Beijing staff sony playstation Nintendo Sega Sinclair Spectrum gaming Mario Sonic rickrolling website Lewis hamilton Second Life pod casting hackers funny Black Hat IM poking satnav data breaches Google Maps Scrabble fire death FBI RPG multimedia Google Street View BERTI hatred morph YouTube privacy Farmville replies lapto offline swear words Spotify streaming flexible working MMORPG military surveillance ID cards sightings nokia flaw medials social media news Nintendo DNSSEC Sega Transformers science app brainwaves filters malware David Blunkett trend micro James Bond pride software brain growth alcohol legal control Google Reader Mafia Wars ENISA mobile Facebook Twitter IT PRO hack Republicans Friendfeed flashmob fun BlackBerry Kindle Dark Market tool phishing Bill Gates Klingon browser murder broadband opinion cybercrime Kaminsky university of portsmouth Sophos RSS robots alibi virtual worlds cyber crime World of Warcraft Clampi illegal Sonic uSwitch research video Mario status crime map Google journalism future credit card data old school DNS crime NHS feed video games unlimited teenagers hype Pirate Bay iPhone Steve Jobs Terminator Christmas human clones vote worm ducks Flurry Star Trek update Digital Britain spam ASA eBooks music Fraud top ten tips instant messaging traffic Amazon Microsoft hacking Daily Mail tech Apple password Hitwise Cisco pirate
Advertisement
Advertisement