11/04/2020
Urgent Cyber Alert!
We have been monitoring a massive global cyber-attack. Specifically the attacks are primarily SQL Injection attacks aimed at SQL, PostgreSQL, MySQL and others.
The attack is implemented through thousands of Zombie machines and appears to be originating in Russia, China and Iran, but includes systems in Germany, Netherlands, Poland, Czech Republic, Ukraine, Brazil as well as what appears to be several compromised machines within certain Microsoft Networks.
We recommend due diligence by companies, website owners and anyone managing servers. These attacks are looking for vulnerabilities in webform and dynamic websites, where variables have not been properly secured to prevent SQL injections or XSS.
Here are a few examples coming from IP address 45. 146. 164. 157 out of Russia: -2165)/**/AS/**/GYZn/**/WHERE/**/6410=6410/**/OR/**/1946=(SELECT/**/(CASE/**/WHEN/**/(1946=1946)/**/THEN/**/1946/**/ELSE/**/(SELECT/**/9111/**/UNION/**/SELECT/**/3545)/**/END))--/**/TsBN"
-1862)/**/AS/**/jiSG/**/WHERE/**/5781=5781/**/OR/**/8307=(SELECT/**/(CASE/**/WHEN/**/(8307=7482)/**/THEN/**/8307/**/ELSE/**/(SELECT/**/7482/**/UNION/**/SELECT/**/8774)/**/END))--/**/TYsm"
-6178\")/**/AS/**/ZGVG/**/WHERE/**/9822=9822/**/OR/**/1345=(SELECT/**/(CASE/**/WHEN/**/(1345=2356)/**/THEN/**/1345/**/ELSE/**/(SELECT/**/2356/**/UNION/**/SELECT/**/6906)/**/END))--/**/RJKj
These attacks can be very dangerous to your networks, websites, databases and servers. Take precautions now.