Lizamoon SQL Injection Campaign ComparedSunday, April 3. 2011Trackbacks
Trackback specific URI for this entry
No Trackbacks
Comments
Display comments as
(Linear | Threaded)
Hi Niels,
Have I missed anything? As far as I know Gumblar and Martuz were NOT SQL injections. They used stolen FTP credentials to break into websites. I checked hundreds of infected site. Quite a few of them were pure html sites that didn't use any database. http://blog.unmaskparasites.com/2009/05/07/gumblar-cn-exploit-12-facts-about-this-injected-script/ I guess, it make more sense to compare LizaMoon with campaigns like Asprox http://www.m86security.com/labs/i/Another-round-of-Asprox-SQL-injection-attacks,trace.1366~.asp or things like this [intitle:script jsportal]
You are right, I corrected the blog post. Most of the Asprox activity was in 2008. If I can find the domain names it used back then, I will try to make an updated graph also showing Asprox. For determining the success of malware inections, comparing to Gumblar/Martuz seems fine though.
Sony has been hacked for the second time now and this time by lulzsecurity team with a sql injection. I find it just incredible that a company like sony can not fix a simple security problem even after the fiasco that followed the first hack. I think it shows a lack of insight of how important it is to set up a proper security of your site, network,...and I am not just talking about sony but in general. As your article suggest sql injextions which are a simple security problem have not been yet been fixed. Now every one seems to be focusing at hackers who pulled this who thing off instead on focusing on what they can do to prevent some thing like this happening to them and others.
The LulzSec hacking group leader was arrested in Australia at the end of April.
I forgot to mention the source.
http://www.abc.net.au/news/2013-04-24/lulz-security-hacking-leader-arrested-in-nsw/4648134 Add Comment
|
QuicksearchSecure DNS?ArchivesCategoriesShow tagged entriesSpyBye InstallationFollow these instructions to install SpyBye.
Proxy ConfigurationTo use SpyBye set your proxy to www.spybye.org:8080. Then visit http://spybye.org/.
The SwitchProxy Firefox extension might help. Blades And SwordsSearch Blades And Swords Resources
|