Showing posts with label Webshell. Show all posts
Showing posts with label Webshell. Show all posts

Tuesday, 20 October 2015

American Company Claims Chinese Espionage Via SQL Injection


An American security company claims it has detected several cases of Chinese cyber espionage via SQL Injection, but concrete details and evidence are given. Does mention Crowd Strike in the blog posting about the cyber espionage frequent own security product.

About three weeks ago, China and the United States decided not to bother with the steal intellectual property via the internet. According Crowd Strike has seen the number of attacks in which the "high degree of certainty" could state that carried out by Chinese attackers. In which this assumption is based not reported by Crowd Strike.

Many of the attacks directed against companies in the technology and pharmaceutical sectors, Web servers via SQL Injection could be hacked. SQL Injection is a problem that has been known since the end of 1998, but is still found in many websites. Through SQL Injection attackers can communicate with the database behind a website and perform various tasks, which should not actually be executed.

In this way, it is possible, among other in order to steal the contents of databases, for example, user names, email addresses, and whether or not encrypted passwords. In this case the attacker SQL Injection eventually use to install a Webshell. Through this Webshell can be obtained access to the internal network of the victim. Despite the report hopes Crowd Strike which progress could be made, and norms and values ​​can be established countries.

Sunday, 23 August 2015

Thousands Of Hacked WordPress Sites Spread Ransomware


In recent weeks attackers have hacked more than 2600 unique WordPress sites and provide malicious code that attempt to infect visitors with ransomware. The hacked WordPress sites are all running version 4.2 of the software or older, says security firm Zscaler.

The attack on the WordPress sites consists of several steps. First, the site is accepted in full. So the attackers add a Webshell, and steal the credentials of the administrator. Is then added an iframe to the website that visitors to the WordPress site unnoticed a page with the Neutrino-exploitkit late charge. The iframe code only to users of Internet Explorer is shown. A cookie will prevent victims of the iframe code are offered several times.

To infect users makes the Neutrino-exploitkit using a malicious Flash file. In case Flash Player not installed on the computer, the user is offered an old Flash installation file, and the malicious file is loaded. Do not know how the installer will install exactly Zscaler allows the analysis of the attack.

In case the attack is successful, the ransomware CryptoWall-installed on the computer. This ransomware encrypts files on the computer and asks users a certain amount for decrypting. According to analyst John Mancuso WordPress remains an attractive target for cyber criminals. WordPress is a very popular free content management system used by more than 60 million websites, including about 23% of the Top 10 million websites on the internet.