levitra

Liza Moon Mass SQL Injection Attack

Up to now LizaMoon attack infects millions of websites

The LizaMoon mass-injection campaign is still ongoing and more than 500,000 pages have a script link to lizamoon.com according to preliminary Google Search results. We have also been able to identify several other URLs that are injected in the exact same way, so the attack is even bigger than we originally thought. All in all, a search on Google returns more than 1,500,000 results that have a link with the same URL structure as the initial attack. Google Search results aren’t always great indicators of how prevalent or widespread an attack is as it counts each unique URL or page, not domain or site, but it does give some indication of the scope of the problem if you look at how the numbers go up or down over time.

Additional injected URLs:

Here’s a list of domains that we have identified so far (with help from blog comment posters; thanks for that guys!).

hxxp://lizamoon.com/ur.php
hxxp://tadygus.com/ur.php
hxxp://alexblane.com/ur.php
hxxp://alisa-carter.com/ur.php
hxxp://online-stats201.info/ur.php
hxxp://stats-master111.info/ur.php
hxxp://agasi-story.info/ur.php
hxxp://general-st.info/ur.php
hxxp://extra-service.info/ur.php
hxxp://t6ryt56.info/ur.php
hxxp://sol-stats.info/ur.php
hxxp://google-stats49.info/ur.php
hxxp://google-stats45.info/ur.php
hxxp://google-stats50.info/ur.php
hxxp://stats-master88.info/ur.php
hxxp://eva-marine.info/ur.php
hxxp://stats-master99.info/ur.php
hxxp://worid-of-books.com/ur.php
hxxp://google-server43.info/ur.php
hxxp://tzv-stats.info/ur.php
hxxp://milapop.com/ur.php
hxxp://pop-stats.info/ur.php
hxxp://star-stats.info/ur.php
hxxp://multi-stats.info/ur.php
hxxp://google-stats44.info/ur.php
hxxp://books-loader.info/ur.php
hxxp://google-stats73.info/ur.php
hxxp://google-stats47.info/ur.php
hxxp://google-stats50.info/ur.php

List updated: 4/1/2011 12:16pm PT

Questions & Answers about the LizaMoon mass-injection

Q: Why is this called LizaMoon?
A: One of the first domains we saw involved in this campaign was created on March 25, 2011 was called lizamoon.com.

Q: How many pages have been affected by this?
A: With the complications of search algorithms and how they count results it’s hard to say. Google Search returns more than 1.5 million results. A Bing Search returns about 900,000 results but the same reservation about their algorithm and how they count results applies. We believe the number of sites infected are significantly smaller.

Q: How does the script get added to the compromised sites?
A: We’re still looking into that. We know that it uses SQL Injection to do it and not XSS as some of our blog readers have suggested.

Q: How do you know it’s using SQL Injection?
A: We have been contacted by people who have seen the code in their Microsoft SQL databases. Initially we only received reports of users running Microsoft SQL Server 2000 and 2005 being hit but since then we have also received reports of websites using Microsoft SQL Server 2008 being injected as well.

Q: Could this mean that there’s a vulnerability in Microsoft SQL Server 2003 and 2005?
A: No. Everything points to that this is a vulnerability in a web application. We don’t know which one(s) yet but SQL Injection attacks work by issuing SQL commands in unsanitized input to the server. That doesn’t mean it’s a vulnerability in the SQL Server itself, it means that the web application isn’t filtering input from the user correctly.

Q: What happens when I visit a site that contains the injected script?
A: Your PC will get redirected to a rogue AV site, displaying fake information about your PC being infected.

Q: Will I get redirected over and over again if I visit a compromised site?
A: No, the script only redirects you once.

Q: When will the LizaMoon attack be over?
A: Not anytime soon. We’re still seeing references to Gumblar, which was a mass-injection attack found in 2009.

News from websense

Categories

About Us

Established in January 2008, TheWesDesign.com is a Singapore & Malaysia based Web Design Freelance Website that specialises in create website, e-Commerce system & solutions.

From start to finish, concept to website; our attention to the finest detail and professional... read more

Featured works

Property For Investment

Property For Investment

Stay tuned