Microsoft denies fault for massive SQL attack

The company insists that there were no vulnerabilities specific to Windows which could have allowed a massive database attack affecting over half a million web pages.

Microsoft has denied that there is any vulnerability in its Internet Information Services (IIS) or SQL server after reports of a massive SQL injection infecting hundreds of thousands of web pages.

The automated attack was reported by F-Secure to have infected more than half a million websites, including those of the United Nations and the UK government. These had been hacked and modified to download malware to visitor's computers, resulting in many being shut down.

Microsoft denied it was due to any new or unknown vulnerabilities in ISS or SQL. It also said the Security Advisory that was published on 17 April which flagged up vulnerability in Windows was unconnected to the incident.

"The attacks are facilitated by SQL injection and are not related to issues related to IIS 6.0, ASP, ASP.Net or Microsoft SQL technologies," said Bill Sisk, a communications manager at Microsoft's Security Response Centre on the IIS blog.

It was claimed that attackers created an automated attack which took advantage of SQL injection vulnerabilities in web pages which did not follow security best practices for web application development.

Microsoft said that even though the attacks targeted sites hosted on IIS web servers, the vulnerabilities could be found on any platform.

Data security provider Secerno claimed that this was the first database threat that was equal in size and scope with well-known PC and virus attacks.

"What is different about this threat is that it automates attacks that were previously done by hand. This capability has increased both the threat level and the possible number of sites infected significantly," said Steve Moyle, chief technology officer at Secerno.

"The attack works by exploiting weaknesses on the web site to gain access to the website and essentially take it over. Once in control of the database, the SQL injection takes every piece of data and adds a link with a malicious Java script."

He added: "When a web visitor goes to a page and clicks on a link with the infected Java script, his computer becomes infected."

Featured Resources

BCDR buyer's guide for MSPs

How to choose a business continuity and disaster recovery solution

Download now

The definitive guide to IT security

Protecting your MSP and your customers

Download now

Cost of a data breach report 2020

Find out what factors help mitigate breach costs

Download now

The complete guide to changing your phone system provider

Optimise your phone system for better business results

Download now

Recommended

Nokia's Digital Automation Cloud will power WEG's Industry 4.0 project
automation

Nokia's Digital Automation Cloud will power WEG's Industry 4.0 project

26 Apr 2021
Defense Dept. expands vulnerability disclosure program to all publicly accessible defense systems
ethical hacking

Defense Dept. expands vulnerability disclosure program to all publicly accessible defense systems

5 May 2021
Security researchers take control of a Tesla via drone
ethical hacking

Security researchers take control of a Tesla via drone

5 May 2021
Best free malware removal tools 2021
Security

Best free malware removal tools 2021

5 May 2021

Most Popular

Dell patches vulnerability affecting hundreds of computer models worldwide
cyber security

Dell patches vulnerability affecting hundreds of computer models worldwide

5 May 2021
16 ways to speed up your laptop
Laptops

16 ways to speed up your laptop

29 Apr 2021
How to move Windows 10 from your old hard drive to SSD
operating systems

How to move Windows 10 from your old hard drive to SSD

30 Apr 2021