
07-31-2012
|
 |
Moderator
|
|
Join Date: Sep 2006
Location: Emerald Isle
Posts: 82,943
Thanks: 24
Thanked 176 Times in 46 Posts
|
|
|
SQL injection, lilupophilupop-style, (Tue, Jul 31st)
It's been a while since we published the diary about the lilupophilupop SQL injection( https://isc.sans.edu/diary.html?storyid=12127) that back in January had infected LOTS of web sites. But guess what, they are b-aaa-ck, and are trying pretty much the same thing:
which decoded looks as usual:
Searching for the injected lasimp04risioned URL via Google shows that bad guys don't seem to be as 'successful' with this attack as last time, but this can change. If you have additional information from your web server logs, especially also information on which server or content management system is being targeted this time, please let us know.
Thanks to ISC reader Mike for sharing the excerpt from his web logs!
(c) SANS Internet Storm Center. http://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
More...
|