Send to a friend Print

Risk Management

US-Cert warns of widespread SQL injection attacks

Author:
Posted:
16:22 11 Jan 2008
Topics:
Databases

The US Computer Emergency Readiness Team (US-Cert) has warned of widespread SQL injection attacks that are compromising websites.

The attacks are targeting websites across all sectors, said US-Cert. The compromised sites have been modified to include a malicious JavaScript file.

When a user unknowingly visits a compromised site, they are re-directed to a series of malicious web pages that attempt to exploit multiple client-side vulnerabilities in a number of applications, including Internet Explorer and RealPlayer.

To mitigate the risk, US-Cert is urging users and administrators to update RealPlayer, if they have it, to the latest version, and to disable ActiveX controls in their browsers.


Send to a friend Print
ADVERTISEMENT

Featured Blog

Attention UK IBM Shops In two weeks grab the chance to catch up on the latest technology, tools and techniques that IBM Collaboration...More All blogs
ADVERTISEMENT
SPONSORED LINKS
Advertisements