Published:
Rapid7 Announces Critical Vulnerability Check for Automated SQL Injection
BOSTON, May 13 /PRNewswire/ -- Rapid7, the leading provider of Unified
Vulnerability Management (UVM) solutions for large enterprise deployments and
small to medium businesses, announced today that NeXpose includes a check to
detect web servers that have been hit by the recent automated mass SQL
injection attacks. Web sites hit by this SQL injection attack have their web
page contents modified to point to malware that is automatically downloaded by
any visitor to the site. These sites are all vulnerable to SQL injection (or
have recently been vulnerable) and were hacked by this automated hacker
toolkit. In addition, by executing a Google search on the malware server
name, hackers can find sites that have been already been exploited.
The "winzipices.cn" SQL injection attack is aimed at web applications
based on Microsoft's IIS web server and SQL Server and has hit over 500,000
websites, including the United Nations, UK Government sites and the U.S.
Department of Homeland Security. The automated attack takes advantage of the
fact that Microsoft's SQL Server allows generic commands that don't require
specific table-level arguments. The vulnerability is the result of poor data
handling by the sites' creators, rather than a specific Microsoft flaw. The
attack injects malicious JavaScript code into every text field in the
database. The Javascript then displays in the site's pages and loads an
external script that can compromise a user's PC.
According to Microsoft, there's no patch to fix the issue -- the
vulnerability lies in custom ASP code that fails to follow well-established
security practices for handling database input. Also, according to Microsoft,
if your site has been affected, you will need to restore your database from a
clean backup copy and start reviewing your code to make sure all input is
properly sanitized. To accomplish this, first, companies need to scan for the
vulnerability.
While NeXpose has long provided the ability to scan custom web
applications for SQL injection flaws, the latest update to NeXpose provides an
additional check to help locate servers that have been exploited by the mass
SQL injection attacks. By crawling the website, companies can use NeXpose to
identify and fix any web servers and databases affected by the attack.
Leaving the exploit unnoticed and unfixed allows even the most junior hacker
to find and exploit the corrupted site. Finding exploited web sites is as
easy as executing a Google search for the malware name. Every web site that
is affected will be listed in the Google search.
"Because this is an automated SQL Injection attack, this is a critical
security issue for all companies using Microsoft IIS. Once an attacker has
access to the underlying database via SQL injection, it is often possible for
an attacker to escalate his privileges and attack the underlying operating
system that hosts the database. These vulnerabilities open the door for
hackers to easily access corporate networks and customer data," stated Tas
Giakouminakis, CTO of Rapid7. "Because this is an automated attack, the list
of exploits will continue to grow and we expect the automated attack to
continue to evolve and for more and more servers to be targeted in the coming
weeks."
ABOUT RAPID7
Rapid7 is the leading provider of Unified Vulnerability Management (UVM)
Solutions. Rapid7 NeXpose UVM provides network, database and web application
vulnerability management for enterprises deployments and small to medium
businesses. Since introduced, NeXpose has been sold to corporate enterprises,
Global 2000 companies, and government entities, and serves the full range of
vertical markets across the U.S. and abroad. In addition, Rapid7 provides
compliance products and services for PCI, HIPAA and Sarbanes Oxley. Rapid7 is
headquartered inBoston, MA, with offices inCalifornia and theUnited
Kingdom. For more information on the company and its product, NeXpose, visit
http://www.rapid7.com.
Media Contact Information
David Precopio
Vice President of Marketing and Business Development
Rapid7 LLC
857-288-7354
David_precopio@rapid7.com
SOURCE Rapid7
Copyright © 2008, PRNewswire
Copyright © 2008, NewsBlaze,
Daily News
Tags: ,CPR,ITE,HTS,PDT,MA-Rapid7-Announces
_ _Is your favorite bookmark site missing?
Ask for it.