[113732] in North American Network Operators' Group

home help back first fref pref prev next nref lref last post

Re: Malicious code just found on web server

daemon@ATHENA.MIT.EDU (Mike Lewinski)
Mon Apr 20 13:23:37 2009

Date: Mon, 20 Apr 2009 11:23:25 -0600
From: Mike Lewinski <mike@rockynet.com>
To: "nanog@nanog.org" <nanog@nanog.org>
In-Reply-To: <6cd462c00904201005m1d94a4fcs89d05aff6294c750@mail.gmail.com>
Errors-To: nanog-bounces@nanog.org

Paul Ferguson wrote:

> Most likely SQL injection. At any given time, there are hundreds of
> thousands of "legitimate" websites out there that are unwittingly harboring
> malicious code.

Most of the MS-SQL injection attacks we see write malicious javascript 
into the DB itself so all query results include it. However, I'm not 
sure how easy it is to leverage to get system access - we've seen a 
number of compromised customer machines and there didn't appear to be 
any further compromise of them beyond the obvious. In the OP's case it 
sounds like static HTML files were altered. My bet is that an ftp or ssh 
account was brute forced.

Mike



home help back first fref pref prev next nref lref last post