Windows IT Pro is the leading independent community for IT professionals deploying Microsoft Windows server and client applications and technologies.
  
  
  Advanced Search 


July 17, 2008

Government and Business Web Sites Fall Victim to Attacks

RSS
Subscribe to Windows IT Pro | See More Security Articles Here | Reprints | Or get the Monthly Online Pass—only $5.95 a month!

Regardless of lots of mainstream media attention, some administrators of government and big business websites remain oblivious to ongoing SQL injection attacks. As a result, even more sites have become pawns that serve up malware to unsuspecting visitors.

According to data recently released by security solution provider Finjan, in July the company "detected over 1,000 unique Website domains" that were compromised by SQL injection attacks. Web pages on each of the sites contained code that could cause malware to become installed on a visitor's computer.

Among the more recent victims are several government sites, including the city of Marysville in California, the Department of Culture and Tourism of Bahia in Brazil, the city and county of San Francisco, the National Health Service in the UK, and the South African Medical Association.

Many big businesses aren't minding their security either. Coca Cola, Snapple, BMW, the Baltimore Times, and the University of California were all found to also have been hacked via SQL injection attacks.

Finjan said that the malware served up by the sites tries to exploit several different vulnerabilities, and when successful such an attack leads to the installation of a Trojan on a user's system.

In response to Finjan's latest quarterly Web Trends Security Report, company CTO Yuval Ben-Itzhak said, "Over the course of the last 18 months we have been watching the profit-driven Cybercrime market maturing rapidly. It has evolved into a booming business, operating in a major shadow economy with an organizational structure that closely mimics the real business world. This makes businesses today even more vulnerable for cybercrime attacks, especially considering the maturity of the cybercrime market and its well-structured cybercrime organizations."

End of Article



Reader Comments

You must be a registered user or online subscriber to comment on this article. Please log on before posting a comment. Are you a new visitor? Register now




Top Viewed ArticlesView all articles
Command Prompt Tricks

One reader shares his tip for setting up the command prompt to reflect a remote path. ...

WinInfo Short Takes: Week of November 9, 2009

An often irreverent look at some of the week's other news, including some more Windows 7 sales momentum, some Sophos stupidity, Microsoft's cloud computing self-loathing, more whining from the browser makers, Zoho's "Fake Office," and much, much more ...

Understanding File-Size Limits on NTFS and FAT

A general confusion about files sizes on FAT seems to stem from FAT32's file-size limit of 4GB and partition-size limit of 2TB. ...


Security Whitepapers Reducing the Costs and Risks of Branch Office Data Protection

Solving Desktop Management Challenges in Healthcare

Solving Desktop Management Challenges in Education

Related Events SQL Server Unleashed EMEA

DevConnections, Microsoft® ASP.NET Connections, SharePoint Connections and SQL Server Connections

Check out our list of Free Email Newsletters!

Security eBooks Spam Fighting and Email Security for the 21st Century

Understanding and Leveraging Code Signing Technologies

A Guide to Windows Certification and Public Keys

Related Security Resources Introducing Left-Brain.com, the online IT bookstore
Looking for books, CDs, toolkits, eBooks? Prime your mind at Left-Brain.com

Discover Windows IT Pro eLearning Series!
Clear & detailed technical information and helpful how-to's, all in our trademark no-nonsense format


Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro DevProConnections IT Job Hound
Left-Brain.com Technology Resource Directory asp.netPRO ITTV Windows SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 © 2009 Penton Media, Inc. Terms of Use | Privacy Statement