<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Security Fight Club &#187; SQL Injection</title>
	<atom:link href="http://www.securityfightclub.com/category/security/sql-injection-security/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.securityfightclub.com</link>
	<description>Brought to you by Awareness Technologies</description>
	<lastBuildDate>Sat, 05 Jun 2010 04:08:44 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Another round of SQL Injection attacks are happening RIGHT NOW&#8230;</title>
		<link>http://www.securityfightclub.com/another-round-of-sql-injection-attacks-are-happening-right-now/</link>
		<comments>http://www.securityfightclub.com/another-round-of-sql-injection-attacks-are-happening-right-now/#comments</comments>
		<pubDate>Fri, 11 Dec 2009 03:39:22 +0000</pubDate>
		<dc:creator>mrdenny</dc:creator>
				<category><![CDATA[Attack Scripts]]></category>
		<category><![CDATA[Databases]]></category>
		<category><![CDATA[External Threats]]></category>
		<category><![CDATA[SQL Injection]]></category>
		<category><![CDATA[SQL Server]]></category>

		<guid isPermaLink="false">http://www.securityfightclub.com/?p=177</guid>
		<description><![CDATA[That&#8217;s right you&#8217;ve heard it here first (ok, probably second or third, but at least in the top 10).  A hacking group is using SQL Injection attacks to break into websites in-mass and download malicious content from 318x.com.
As of December 10, 2009 over 132,000 websites have been compromised and are serving up the malicious content.  [...]]]></description>
			<content:encoded><![CDATA[<p>That&#8217;s right you&#8217;ve heard it here first (ok, probably second or third, but at least in the top 10).  A hacking group is using <a href="http://www.net-security.org/secworld.php?id=8604" target="_blank">SQL Injection attacks</a> to break into websites in-mass and download malicious content from 318x.com.</p>
<p>As of December 10, 2009 over 132,000 websites have been compromised and are serving up the malicious content.  The attack loads up an Iframe onto the websites via the data returned from the database which eventually leads the user (without there knowledge) to download data from 318x.com which then installats a rootkit-enabled variant of the Buzus backdoor trojan.  The full path of what happens can be found on the link above.</p>
<p>We&#8217;ve talked about the securing your website from SQL Injection attacks <a href="http://www.securityfightclub.com/gonzalez-tj-max-hacker-gets-15-25-years/" target="_blank">here</a>, <a href="http://www.securityfightclub.com/more-charges-filed-against-tjmax-hackers/" target="_blank">here</a> and <a href="http://www.securityfightclub.com/hackers-have-actually-broken-into-the-brazilian-power-grid/" target="_blank">here</a>, apparently there are tons of sites out there which haven&#8217;t been listening.</p>
<p>Denny</p>
]]></content:encoded>
			<wfw:commentRss>http://www.securityfightclub.com/another-round-of-sql-injection-attacks-are-happening-right-now/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Hackers have actually broken into the Brazilian Power Grid</title>
		<link>http://www.securityfightclub.com/hackers-have-actually-broken-into-the-brazilian-power-grid/</link>
		<comments>http://www.securityfightclub.com/hackers-have-actually-broken-into-the-brazilian-power-grid/#comments</comments>
		<pubDate>Thu, 19 Nov 2009 20:43:54 +0000</pubDate>
		<dc:creator>mrdenny</dc:creator>
				<category><![CDATA[External Threats]]></category>
		<category><![CDATA[SQL Injection]]></category>
		<category><![CDATA[SQL Server]]></category>
		<category><![CDATA[Utility Companies]]></category>

		<guid isPermaLink="false">http://www.securityfightclub.com/?p=172</guid>
		<description><![CDATA[About a week ago 60 Minutes covered a story about hackers breaking into the Brazilian power grid and causing power outages through out the country.  The common believe is that this story wasn&#8217;t actually correct.  However hackers appear to have liked the idea, and have done what was originally claimed in the story.
Google has a [...]]]></description>
			<content:encoded><![CDATA[<p>About a week ago 60 Minutes covered a story about hackers breaking into the Brazilian power grid and causing power outages through out the country.  The common believe is that this story wasn&#8217;t actually correct.  However hackers appear to have liked the idea, and have done what was originally claimed in the story.<span id="more-172"></span></p>
<p>Google has a <a href="http://translate.google.com/translate?js=y&amp;prev=_t&amp;hl=en&amp;ie=UTF-8&amp;u=http%3A%2F%2Fg1.globo.com%2FNoticias%2FTecnologia%2F0%2C%2CMUL1380926-6174%2C00-HACKERS%2BINVADIRAM%2BSITE%2BDIZ%2BONS.html&amp;sl=pt&amp;tl=en" target="_blank">translation of the article</a>, and the <a href="http://g1.globo.com/Noticias/Tecnologia/0,,MUL1380926-6174,00-HACKERS+INVADIRAM+SITE+DIZ+ONS.html" target="_blank">original can be found here</a>.</p>
<p>The power company is question claims that the blackout which hit 18 Brazilian states on Tuesday was not caused by the hackers.  However the timing out the attack and the outage is very suspicious.  This just goes to show that utilities needs to take even more care that other companies to secure there environments to ensure that the services which they provide remain online as peoples live depend on the power staying on.</p>
<p>Based on the results of testing against the sites as reported <a href="http://darkreading.com/blog/archives/2009/11/how_to_hack_a_b.html;jsessionid=N4RKLB425E4DDQE1GHPSKHWATMY32JVN" target="_blank">by Darkreading</a> the standard SQL Injection attack may have been used in this case to attack the site and break in.  One would think that a company as large as a countries power company would be able to have developers which wouldn&#8217;t allow SQL Injection attacks.</p>
<p>Denny</p>
]]></content:encoded>
			<wfw:commentRss>http://www.securityfightclub.com/hackers-have-actually-broken-into-the-brazilian-power-grid/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
