SHARE
Follow this article on Twitter Facebook LinkedIn Bookmark and Share
Home >> Security >> Hacking and Viruses

How to not have your Web site hacked like Sony's

How to not have your Web site hacked like Sony's

By:  Brian Jackson  On: 06 Jul 2008 For: Network World Canada Creator

A SQL injection attack was used to plant malicious code on pages of two popular Sony Playstation games - SingStar Pop and God of War, reports security company Sophos. Hundreds of Web pages from other businesses have also been compromised.

The U.S. Sony Playstation Web site is the latest high-profile victim of a hacker attack on business sites that's spreading malware at breakneck pace, says a security vendor.

Sophos PLC reported that Sony had suffered an SQL injection attack July 2. Malicious code was planted on pages of two popular Playstation games – SingStar Pop and God of War.

The digital security company alerted Sony to the problem, and it was fixed as of early July 3, says Graham Cluley, senior technology consultant with Sophos headquartered in Abingdon, U.K.

While the Playstation site is now clean, hundreds of other Web sites have been compromised by the same attack, he says. Affected sites are wide ranging, says Cluley, "from Brazilian and Chinese government sites to a garden pond supplier in Canada."

The SQL injection attack is an old hacker trick that has found new life. Its usage in recent months has soared, as cyber criminals use automated programs to scour the Web for pages and sites vulnerable to such exploits.

The attacks have transformed thousands of credible business Web pages on sites such as MSNBC into malware-peddling portals.

Attacks have ballooned in recent months. There is now a new malware-infected Web page every five seconds, according to Sophos. That's three times the rate of infection compared to last year. Eight out of 10 Web sites suffering from the attack are legitimate business Web sites.

"There's been a spate of attacks being called by a botnet named Asprox," Cluley says. "It's using innocent people's computers to go on the Web and find vulnerable targets." An automated attack is to blame for the Sony hack, he adds. It wasn't launched by a person, but an automated program that stumbled upon the code vulnerability on the Playstation pages and took advantage.

The attacks don't exploit a specific software vulnerability, but take advantage of poor coding practices, according to a Microsoft Security Advisory. Companies that access and manipulate data in a relational database such as SQL Server from a Web site are at risk.

It comes down to a problem with a Web application, says Brian Bourne, president of Toronto-based security analyst firm CMS Consulting Inc. Developers are failing to do proper code checking to prevent the attacks. "They're not doing input validation," he explains. "They're not looking at it and saying 'hey, this is not regular user input' – that's the simple version."

But Web administrators have to shoulder the burden of blame too, Bourne adds. They're responsible for creating a layered security approach to protect against known and yet-to-be-discovered exploits.

The most common variety of the hack is a direct insertion of code into a place where a user inputs information. That gives hackers an opportunity to inject SQL commands that are executed blindly by the server.


Sign up for our Newsletters












Print |  Views: 771   |   Rating:offoffoffoffoff  (0 votes)
Rate this article on a scale of
1 to 5 stars,5 being the best.




Brian Jackson Brian Jackson is a contributor to the International Data Group (IDG) News Service, which publishes global technology stories from bureaus around the world to more than 300 publications in more than 60 countries.

Related Content

Obama campaign hopes for better Web security
Obama campaign hopes for better Web securityTwo months after their Web site was hacked, the organizers of Barack Obama's presidential campaign are looking for a network security expert to help lock down their Web site. "Obama for America is looking for a network security expert who wants to play a key role in a historic political campaign," reads the ad, posted to the Barackobama.com Web site.
eBay IT exec warns of application layer attacks
eBay IT exec warns of application layer attacksSpeaking at this week’s Infosecurity Canada conference, the online auction site’s security director Dave Tyson singled out what he sees as the most significant threat to security at major organizations. Plus: A U.K. firm’s cautionary tale
IBM executive targets online criminals
IBM executive targets online criminalsKris Lamb, director of X-Force, IBM's primary security research organizaiton talks about what he sees as the most critical challenges and opportunities facing enterprise IT security managers today.
Protect yourself from the Internet Explorer bug
avg technologies nv of amsterdam announced this week version 8.0 of its security software has blocked 5,000 hacking attempts by miscreants exploiting a bug in the data binding features of microsoft internet explorer.avg version 8.0 includes rea
BitDefender claims it can remove Conficker
bitdefender llc of bucharest, romania announced software designed to counter the latest version of conficker worm, also known as downadup.a beta version of downadup removal tool can be downloaded from this web site.the most recent version, dubbed w
blog comments powered by Disqus