Web Attack Worm Infecting Hapless Sites
The Internet Storm Center, which tracks online threats, warns today that a worm is infecting vulnerable Web sites with a database attack.
IMPORTANT:
To see if your site has been hit, run the following Google search: "site:your company domain (ex. pcworld.com) winzipices.cn."
The worm uses a SQL Injection attack, according to the ISC, but it doesn't yet know just what vulnerability is targeted. The attack highlights the importance of keeping your site secure, something I wrote about last month. It's likewise critical to keep your own PC software up-to-date, as the ISC says visitors to infected sites can be hit via a known flaw in old Real Player software.
For more details, see the ISC post or a more detailed writeup from shadowserver.org.
































Add Your Comment