Join | Login | Why Join?   
SQL Server, Oracle, DB2, Sybase, MySQL Help - SSWUG.ORG HACKER SAFE certified sites prevent over 99.9% of hacker crime.
Search SSWUG:   
 
Access to 591 free guest articles, discussions and more, just create your free SSWUG User ID:
Email address:  
This will be your login ID - we'll email you your password - you'll even receive the newsletter, opt-out at any time.
Email to Friend //  Discuss Article //  Rate Article //  Digg Article //  Add to Del.icio.us //  Add to Technorati

 

A Look At April's Mass SQL Injection Attack For ASP.Net / SQL Server Environments

Available for Members. This is an off-site link.  Please review our Terms of Service (bottom of page) for additional information.  See Related Articles


 Article Abstract:

(George P. Alexander Jr.) I was catching up with my feeds and took note of Defence In Depth's Robert Vamosi's interview with Jeremiah Grossman from WhiteHat Security on April's mass SQL Injection attack carried out on IIS web sites that ran with SQL Server as backend . What caught my attention was the fact that so far, attackers would go for specific sites. But this time around, they used a sophisticated tool that would scan the entire web for potentially weak sites running ASP.Net and therefore, quite possibly SQL Server and use a generic SQL Server feature on all those sites to wreck serious damage. The interview is an eye opener to the massive efforts required in cleaning up the effects of compromised web sites because of this hacking tool: "Where it gets worse is it's going to be the cleanup effort. The cleanup after this compromise it's going to require database administrators going back to their database and manually pulling out the infected database tables or reverting to a back up. Either way it's going to take days, weeks, and possibly months to actually clean up the code." If you remember or were aware, April '08 ended with one of the worst SQL Injection attacks on a massive scale - affecting over half a million web sites. Though April was when this exploit gained notoriety creating much shock and awe, the process started way back in January. This continued even in May. Affected sites included not just off-the mill destinations but popular government web sites from the US, UK and many other state web sites apart from organizations like the United Nations and other legit web sites. The inner workings of this attack goes as follows: hackers would look for .aspx pages that would contain query strings and load it with encoded T-SQL.

 Read this article...

 Related Articles - For Members.
SQL Server 6.5 Security Modes
Security Mandates: DBMS Row Level Security
Security and the .NET
Using security procedures to troubleshoot SQL Server problems
Enhance Your Transaction Flexibility With Embedded Stored Procedures
Alter View, Create Function: Security for Assemblies Part I
Regulatory Compliance 101 for the Overworked DBA
DB2 UDB security: Security plug-ins using the GSS-API security mechanisms (SPKM / LIPKEY)
Security Overview (Sample Chapter)
Security for developers



Key (Please note):
(R) - registration may be required for access at the target site
($) - target site may require paid membership for access to this or other content


No Comments/Feedback Posted Yet. Post Your Comments/Feedback

Email to Friend //  Discuss Article //  Rate Article //  Digg Article //  Add to Del.icio.us //  Add to Technorati

   




 

[ Register ] [ Webcasts ] [ Podcasts ] [ Newsletter Archive ] [ RSS/Feeds ]
[ About ] [ Advertise ] [ Contact ] [ Privacy ] [ Terms of Service ]
[ Link to SSWUG ] [ List Server Archives ] [ Recent Orig. Content ]
(c) 1997-2009, Bits on the Wire, Inc.  (0)

Some names and products covered by SSWUG are the registered trademarks of their respective owners.
DAA10354WWW004