Link Details

You pick the winners! Login and vote now.
Link 97173 thumbnail
User 318228 avatar

By spl0it
via rtraction.com
Published: Jul 22 2008 / 10:31

A new SQL injection hack seems to be out in the wild from verynx.cn. The SQL Injection hack uses a CHAR array to hide its payload which will insert some various html garbage along with a reference to a javascript file on the verynx.cn domain that will infect users when they visit your website. Luckily the domain with the offending javascript file now points to 127.0.0.1 which will help stop the spread of the virus. Unfortunately the botnet still seems to be spamming websites with the scripted attack leaving many entirely broken or loading extremely slow as each page might have hundreds of requests to the payload.
  • 25
  • 3
  • 2101
  • 635

Comments

Add your comment
User 318240 avatar

artnik replied ago:

-4 votes [show comment] Vote down Vote up Reply
User 111696 avatar

bloid replied ago:

3 votes Vote down Vote up Reply

Having pretend conversations with people you share an office with is pretty lame...

I'm so close to blocking this again...

User 278075 avatar

eabarquez replied ago:

0 votes Vote down Vote up Reply

Lol. How did you know?

User 111696 avatar

bloid replied ago:

0 votes Vote down Vote up Reply

bloid sees all ;-)

User 318228 avatar

spl0it replied ago:

0 votes Vote down Vote up Reply

I think perhaps he was a little irritated by your banning of my first link submission - no1 had made a comment or anything silly, simply 4 supporting colleagues had voted for the article and you blocked it for vote gaming.

User 318363 avatar

ellisgl.myopenid.com replied ago:

0 votes Vote down Vote up Reply

I don't see how it's so "new". It's an injection. All data that can be manipulated should be dealt with in the first place.

User 211643 avatar

zynasis replied ago:

0 votes Vote down Vote up Reply

exactly wat ellisgl.myopenid.com said.
its a plain old injection that alters something in your database. nothing new.

Add your comment


Html tags not supported. Reply is editable for 5 minutes. Use [code lang="java|ruby|sql|css|xml"][/code] to post code snippets.