 mysec Premium join:2005-11-29
| reply to amungus Re: Mass SQL injection
See also:
»isc.sans.org/diary.html?storyid=4393 »www.shadowserver.org/wiki/pmwiki···20080507
Note that these are Remote Code Execution exploits. The hacked pages have multiple iframes, each exploiting a different vulnerability, hoping to find an opening on the user's computer.
said by amungus :Any good tips, besides re-coding things, to mitigate such an attack? Since most exploits these days have the end result of installing a trojan, one's security should include something to prevent downloading by remote code execution any executable not already installed on your computer.
I was able to get two of the exploits to run, showing how they can be blocked:
SQL exploit test
|