Attacks/Breaches
4/1/2011
04:12 PM
Connect Directly
RSS
E-Mail
50%
50%

LizaMoon SQL Injection Attack Hits Websites

The scareware sends users to a bogus Web page warning them that their PCs are infected with malware and tries to sell them an anti-virus application.

10 Massive Security Breaches
(click image for larger view)
Slideshow: 10 Massive Security Breaches
Hundreds of thousands of website URLs have been compromised in a massive malware attack that tries to trick people into buying fake anti-virus software to remove bogus infections, security experts said.

Dubbed LizaMoon, unidentified perpetrators of the scareware campaign inject script into legitimate URLs, so when people try to access the website, they get redirected to a page warning them that their PCs are infected with malware that can be removed by downloading a free AV application called Windows Stability Center. The software eventually will find bogus threats that will require victims to buy a more robust product, using their credit cards.

Security firm Websense says a Google search shows more than 1.5 million URLs with the nasty script. Because Google counts unique URLs and not domains or websites, the number is likely inflated. "It's safe to say it's in the hundreds of thousands," Websense said Thursday in a blog post. The attack is worldwide, with U.S. PC users making up roughly half those getting redirected to the bogus warning page.

LizaMoon, named after the first domain Websense discovered with the malicious script March 29, is believed to be a SQL injection, which is when hackers get their script into a Microsoft SQL Server database that then adds it to a site's URL. SQL injections is one of the most common forms of attacking Web sites and back end databases.

LizaMoon code has been found in SQL Server 2003 and 2005. Websense does not believe hackers are exploiting a vulnerability in the database. They are more likely penetrating Web systems used by the sites, such as outdated content management and blog systems. Security experts are still trying to determine exactly how the SQL injection occurs.

Fortunately, people heading to a hijacked URL are only redirected once. If the bogus warning page is ignored, then people can go on their way without being continuously sent to the same page.

Websense said the first domain may have been infected with the LizaMoon script as early as Oct. 21, 2010, but the evidence is inconclusive. The first confirmed case that Websense knows of was in December 2010. That infection was identified as LizaMoon until Thursday.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading Must Reads - September 25, 2014
Dark Reading's new Must Reads is a compendium of our best recent coverage of identity and access management. Learn about access control in the age of HTML5, how to improve authentication, why Active Directory is dead, and more.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-6856
Published: 2014-10-02
The AHRAH (aka com.vet2pet.aid219426) application 219426 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

CVE-2014-6857
Published: 2014-10-02
The Car Wallpapers HD (aka com.arab4x4.gallery.app) application 1.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

CVE-2014-6858
Published: 2014-10-02
The Mostafa Shemeas (aka com.mostafa.shemeas.website) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

CVE-2014-6859
Published: 2014-10-02
The Daum Maps - Subway (aka net.daum.android.map) application 3.9.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

CVE-2014-6860
Published: 2014-10-02
The Trial Tracker (aka com.etcweb.android.trial_tracker) application 1.1.9 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Chris Hadnagy, who hosts the annual Social Engineering Capture the Flag Contest at DEF CON, will discuss the latest trends attackers are using.