MSMVPS.COM

The Ultimate Destination for Blogs by Current and Former Microsoft Most Valuable Professionals.
Welcome to MSMVPS.COM Sign in | Help
in Search

Harry Waldron - Microsoft MVP Blog

Security News and Best Practices for corporate and home users

Storm Worm - New Version uses SQL Injection Techniques

Lightning While the Storm worm botnet continues to spread using email techniques, SQL injection techniques are starting to be used as an approach to seed malware on vulnerable computers.  Folks should be careful with email in avoiding all attachments and website links, and stay up-to-date on security patches and AV protection.

Storm Storm Worm - New Version uses SQL Injection Techniques
http://blogs.zdnet.com/security/?p=1131
http://ddanchev.blogspot.com/2008/05/all-you-need-is-storm-worms-love.html

QUOTE: What has changed compared to previous campaigns? Storm Worm is back in the SQL injection attack phrase, with a malicious iframe injected at a small number of sites for the time being. Moreover, assessing the storm worm infected hosts can only be done if you spoof your browser UI, otherwise you will get no indication for any kind of malicious activity going on. Furthermore, despite that there are no exploits used at the infected hosts but, a heavily obfuscated HTML was detected in their injected domain which would load automatically upon someone visiting an already injected site. Lightning

Only published comments... May 20 2008, 06:14 PM by harry

Leave a Comment

(required) 
(optional)
(required) 
Submit
Powered by Community Server (Commercial Edition), by Telligent Systems