Login|Japanese
August 26, 2009
 The China Syndrome

The recent SQL Injection attack campaign that was discussed this week in the press caught my attention a couple of weeks ago. The attack vector used is quite common these day, in fact, it has been very popular for about the past 18 months. However, during the 4 weeks that we have been monitoring this attack campaign, we have seen the attacks coming from 60 different servers which are all located in China. This is quite unusual as most previous campaigns had attack vectors coming from bots all over the globe.

Another concern gave me pause. As of yesterday (more than 4 weeks after the first infection attempt) the malware distribution sites at: http://a0v.org/ and http://js.tongji.linezing.com were still up and running, counting more than 1,250,000 downloads!

The latter site is hosted on a machine that bares the domain of "alimama.com." Interestingly enough, looking at Google's SafeBrowsing diagnostic information for both domains we see no current warnings about malicious activity.

Wondering through some of the web's back allies I've also recently found a list of Google Dorks that judging by the content, and the activity we see, may be the ones used by the infection agents to look for potential vulnerable sites and mount the SQL Injection attacks.My advice: be careful out there! SQL Injection is here to haunt us; we must have our defenses in place.

Marson_fig16b

- Amichai


Feed You can follow this conversation by subscribing to the comment feed for this post.
Comments

Verify your Comment

Previewing your Comment

This is only a preview. Your comment has not yet been posted.

Working...
Your comment could not be posted. Error type:
Your comment has been saved. Comments are moderated and will not appear until approved by the author. Post another comment

The letters and numbers you entered did not match the image. Please try again.

As a final step before posting your comment, enter the letters and numbers you see in the image below. This prevents automated programs from posting comments.

Having trouble reading this image? View an alternate.

Working...

Post a comment

Comments are moderated, and will not appear until the author has approved them.

« Imperva Security Podcast - Web App Security in the Cloud with Customer & Partner Savvis | Main | Imperva Webcast - Stealing Secrets - Malicious Insiders and Data Security, Stories from the Trenches »