Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » Mass SQL injection
Search Topic:
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
Just a request to the other posters... »
« Is my spyware protection overkill?  
AuthorAll Replies

mysec
Premium
join:2005-11-29

reply to amungus
Re: Mass SQL injection

See also:

»isc.sans.org/diary.html?storyid=4393
»www.shadowserver.org/wiki/pmwiki···20080507

Note that these are Remote Code Execution exploits. The hacked pages have multiple iframes, each exploiting a different vulnerability, hoping to find an opening on the user's computer.

said by amungus See Profile :

Any good tips, besides re-coding things, to mitigate such an attack?

Since most exploits these days have the end result of installing a trojan, one's security should include something to prevent downloading by remote code execution any executable not already installed on your computer.

I was able to get two of the exploits to run, showing how they can be blocked:

SQL exploit test


Forums » Up and Running » Security » SecurityJust a request to the other posters... »
« Is my spyware protection overkill?  


Wednesday, 07-Jan 18:51:40 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 9 years online! © 1999-2009 dslreports.com.
page compression OFF
Most commented news this week
· [160] New Comcast Throttling System 100% Online
· [110] After 10 Years Of Service, Charter Declares Home 'Unserviceable'
· [105] iTunes Dumps The DRM
· [70] AT&T, Verizon Stocks Tumble
· [54] Feds Start Wait List For DTV Converter Coupons
· [52] Cable To Grab 75% Of New Subs In 2009
· [38] Netflix Via LG HDTVs
· [37] DOCSIS 3.0 Gets Faster
· [36] New Zealand's 'One Strike' Piracy Law
· [35] ISPs Won't Admit Participation In New RIAA Plan
Most people now reading
· MLPPP: Fail - ERX06 [TekSavvy]
· [Rant] cops and illegal searches [Rants, Raves, & Praise]
· anyone else getting high pings and slow speeds now? [TekSavvy]
· [ Professions] Northrend Herbalism and Mining Tracks [World of Warcraft]
· aluminium wiring? [Home Repair & Improvement]
· 3.0.8 Patch Notes [World of Warcraft]
· Bandwidth Limits - All discussion here [Comcast HSI]
· How to download windows 7 beta [Microsoft help]
· Can't order UVerse and then cancel TV later [AT&T U-verse]
· Linux Access question [All Things Unix]