Internet pogodio LizaMoon SQL Injection Attack; instalira skitnica Windows Stability Center

Internet pogodio LizaMoon SQL Injection Attack; instalira skitnica Windows Stability Center
Internet pogodio LizaMoon SQL Injection Attack; instalira skitnica Windows Stability Center

Video: Internet pogodio LizaMoon SQL Injection Attack; instalira skitnica Windows Stability Center

Video: Internet pogodio LizaMoon SQL Injection Attack; instalira skitnica Windows Stability Center
Video: CS50 2014 - Week 5 - YouTube 2024, Svibanj
Anonim

Sigurnosna tvrtka Web Sense otkrila je SQL injection napad koji usmjerava korisnika na instalaciju skitnica sigurnosnog softvera Centar za stabilnost sustava Windows, Broj pogođenih web stranica u vrijeme otkrića iznosio je oko 28.000, a od sada više od 500.000 web stranica je pogođeno napadom što znači da se napad kreće u alarmantno brzom ritmu.

Kao što je navedeno, napad se temelji na metodi SQL ubrizgavanja koja iskorištava nedovoljno kodirane aplikacije. Prema threapost.com,
Kao što je navedeno, napad se temelji na metodi SQL ubrizgavanja koja iskorištava nedovoljno kodirane aplikacije. Prema threapost.com,

In this case, the SQL injection attacks were used to insert malicious code into back end databases,which was then served up to unsuspecting users. The attack was dubbed “LizaMoon” in recognition of a malicious Web domain, registered shortly before the attacks began, that has been used to serve up malicious links. That domain was offline at the time this report was filed, but a handful of other Web domains are mirroring the attack.

Users who click on a link to a Web site that has been compromised and injected with the malicious code, a PHP file is pushed to the user’s computer that redirects the browser to a Web site that installs rogue antivirus software known as Windows Stability Center.

Ovaj videozapis objašnjava kako napad funkcionira.
Ovaj videozapis objašnjava kako napad funkcionira.

Države Web smisao:

The LizaMoon mass-injection campaign is still ongoing and more than 500,000 pages have a script link to lizamoon.com according to preliminary Google Search results.

We have also been able to identify several other URLs that are injected in the exact same way, so the attack is even bigger than we originally thought. All in all, a search on Google returns more than 1,500,000 results that have a link with the same URL structure as the initial attack. Google Search results aren’t always great indicators of how prevalent or widespread an attack is as it counts each unique URL or page, not domain or site, but it does give some indication of the scope of the problem if you look at how the numbers go up or down over time.

Oštećeni su i mnogi web-lokacije povezane s iTunesom, ali kao što su oznake skripte kodirane, one se ne mogu izvršiti.

Stoga, ako posjetite web mjesto i preusmjerite se na web mjesto sigurnosnog softvera, postoje šanse da je web mjesto na koje ste pristupili ugroženo. Što možete učiniti da biste zaštitili sebe, zatvorite prozor web-mjesta i skenirate računalo s poznatim antivirusnim rješenjem kao što su Microsoft Security Essentials.

Preporučeni: