On CBS.com: Enter For Chance to Tour Set of MEDUM
BNET Business Network:
BNET
TechRepublic
ZDNet

May 16th, 2008

Redmond Magazine Successfully SQL Injected by Chinese Hacktivists

Posted by Dancho Danchev @ 3:10 pm

Categories: Microsoft, People's Republic of China, Viruses and Worms

Tags: SQL Injection, Chinese Hacktivists, Redmond Magazine, Dancho Danchev

Irony at its best. It appears that Redmond - The Independent Voice of the Microsoft IT Community, formerly known as Microsoft Certified Professional Magazine is currently flagged as a badware site, and third-party exploit detection tools are also detecting internal pages as exploit hosting ones, in this particular case Mal/Badsrc-A. What is Mal/Badsrc-A? Mal/Badsrc-A is a malicious web page also known as HTML.XORER, that has been compromised to load a script from a malicious website.

Redmond Magazine SQL Injected

Redmond’s site is part of yet another massive and naturally automated SQL injection attack, whose main malicious URL appears to be down when last checked. Who’s behind it, and was Redmond’s magazine targeted on purposes? Chinese hacktivists attempting to SQL inject as many sites as possible seem to have come across Redmond’s site with no specific intention to do so, comment spammed it, and left a message on the malicious domain (wowyeye.cn) which is descriptive enough to speak for itself:

“The invasion can not control bulk!!!!If the wrong target. Please forgive! Sorry if you are a hacker. send email to kiss117276@163.com my name is lonely-shadow TALK WITH ME! china is great! f**k france! f**k CNN! f**k ! HACKER have matherland!”

Two more related sites are affected as well, namely, Redmond Developer News and Redmond Channel Partner Online. To bottom line -  despite that wowyeye.cn/ m.js is currently down, it managed to get injected at 49,900 sites, which like the majority of sites that were participating in the most recent tidal wave of successful SQL injection attacks, continue to remain vulnerable to copycats introducing new malicious domains within the vulnerable sites.

Redmond Magazine SQL Injected

It is also important to emphasize on the fact that this is a lone gunman operation, and not necessarily one backed up by a botnet such as Asprox, which got some publicity for its involvement in automated SQL injections attacks. Whether or not a standalone SQL injecting tool was used (screenshots included), the concept of using botnets which would create their hitlists from public search engines’ indexes (screenshots included) and automatically SQL inject or Remotely File Include them, has been around for years with the availability of such scanning modules available for the botnet masters to take advantage of.

Redmond Magazine SQL Injected

And now that the probability of locating and successfully exploiting vulnerable sites is increasing due to the success rate of previous campaigns, what we would be dealing with for the next couple of months are the copycats who just memorized a new buzz word — SQL injection — and efficiently execute massive unethical web applications pen-testing all over the Web.

Dancho DanchevDancho Danchev is an independent security consultant and cyber threats analyst, with extensive experience in open source intelligence gathering, malware and cybercrime incident response. He's been an active security blogger since 2007, and maintains a popular security blog. See his full profile and disclosure of his industry affiliations.

Email Dancho Danchev

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 16 Talkback(s)
RE: Redmond Magazine Successfully SQL Injected by Chinese Hacktivists
430828<"> (Read the rest)
Posted by: teddycaguioa@... Posted on: 12/21/08 You are currently: a Guest | | Terms of Use
But MSFT...  Jeremy W | 05/16/08
Its hard to pin it on MS...  storm14k | 05/16/08
I could say the same for web developers who use Linux/Unix...  Grayson Peddie | 05/16/08
Are you for real?  Pliny the Elder | 05/16/08
Wow... So the owners of the websites don't know how to validate input?  Grayson Peddie | 05/16/08
"Developers" Instead of "Owners"  Grayson Peddie | 05/16/08
Stop blaming the victim  j.daniluk@... | 05/17/08
Read the story again very carefullly.  odubtaig | 05/17/08
The term "hacktivist" should go away  John L. Ries | 05/16/08
The developers used "modern" techniques  jorwell | 05/17/08
well said... coders and programmers!!  dragon@... | 05/17/08
Different case these days.  odubtaig | 05/17/08
In the database case  jorwell | 05/17/08
RE: Redmond Magazine Successfully SQL Injected by Chinese Hacktivists  teddycaguioa@... | 12/21/08
RE: Redmond Magazine Successfully SQL Injected by Chinese Hacktivists  teddycaguioa@... | 12/21/08
RE: Redmond Magazine Successfully SQL Injected by Chinese Hacktivists  teddycaguioa@... | 12/21/08

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

Enterprise Applications

  • Check out some of the easiest and most powerful ways to boost productivity while saving money on your application infrastructure. See ZDNet's comprehensive Enterprise Application resource center, now!
  • New Online Dashboard
  • Read about top issues IT decision-makers face every day, plus get cost effective solutions to real life IT problems. Oracle Topline