Massive Sql Injection Ensues


Recommended Posts

17 July

Massive SQL Injection Ensues

7:21 am (UTC-7) | by Det Caraig (Technical Communications)

With the growing concern with numerous vulnerabilities, just this afternoon, Trend Micro Research Project Manager, Ivan Macalintal, stumbled on a somewhat regional fallout of this SQL injection in India threading through numerous compromised government, tourism, popular media, and other sites. We have identified the following new URLs leading to more malware that made it into unknowing users’ systems while visiting sites where the malicious script injection was found and identified:

http://lsg.kerala.gov.in

http://www.lsg.kerala.gov.in

http://www.bangaloremirror.com

http://www.mumbaimirror.com

http://www.kolkatamirror.com

http://www.mumbaipluses.com

http://education.indiatimes.com

http://www.kolhapurbusiness.com

http://www.bizxchange.in

http://timesascent.in

http://www.studio3india.com

http://www.timesascent.co.in

http://www.mumbaibusinessdirectory.in

http://www.tourindianow.org

http://www.bizxchange.in

http://www.maharashtradirectory.com

Based on Trend Micro threat analyst Joseph Pacamarra’s initial findings, the Trojan detected as TROJ_AGENT.HOZZ has only been seen so far in two domains, jatrja.com and js.tongji.linezing.com. Figure 1 below shows how users can get infected.

More details at trendlabs - http://blog.trendmicro.com/

Link to post
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

Loading...