Google: SQL-injection attack not as large as first thought
By Nicole Kobie
Posted on 4 Apr 2011 at 09:22
An SQL-injection attack is now returning 1.5 million results over Google, but experts have raised doubts over the scale problem is.
Last week, security firm Websense reported that hundreds of thousands of sites had been infected via an SQL-injection attack, which was dubbed "Lizamoon" after the name of the website it redirected users to, where it tries to trick them into installing fake antivirus.
Google Search results aren't always great indicators of how prevalent or widespread an attack is
Websense based its numbers on how many sites were infected by Googling for that web address, but some have said that method of counting isn't entirely accurate, and the attack isn't as big as first feared.
Instead of simply Googling for the URL, the search engine's principal engineer, Niels Provos, counted the sites with a functioning reference, leaving out those that had the code but didn't actually redirect users.
He found the Lizamoon attack actually peaked in October with 5,600 infected sites, but is currently "undergoing a revival". He compared it to the Gumblar attack of two years ago, which peaked at 62,000 infected sites.
Websense said the Google results method merely gave a sense of the scale of the attack.
"All in all, a search on Google returns more than 1,500,000 results that have a link with the same URL structure as the initial attack," Websense said in an updated blog post. "Google Search results aren't always great indicators of how prevalent or widespread an attack is as it counts each unique URL or page, not domain or site, but it does give some indication of the scope of the problem if you look at how the numbers go up or down over time."
However, Websense admitted that the number of sites actually infected was "significantly smaller" than search results suggested, but didn't offer any numbers.
From around the web
advertisement
- Laptop bag reviews: nine tested
- Sony VAIO T Series Ultrabook review: first look
- Revealed: the military standards and robots HP uses to test its laptops
- Windows 8: multi-monitors and double standards?
- Why is TalkTalk's year-old porn filter suddenly big news?
- Why are laptop screens so far behind mobiles?
- HP EliteBook Folio review: first look
- The shoebox-sized all-in-one printer
- Forget the Ultrabook: here comes the HP Sleekbook
- HP Spectre XT review: first look
- Why you have to be left in the dark on OS patches
- Publishing your email address isn't a security disaster
- Why antivirus is fighting a losing battle in your office
- Four year olds used to steal their parents' data
- An acceptable use policy for your kids
- Paying for your crimes with Bitcoin
- Pavement hacking: What it is and how to avoid it
- Google's risky pre-loaded pages
- Mac under attack: how secure is Apple's OS?
- Has your browser been hijacked?
advertisement
