Press Releases

Unedited news and product information from vendors.

Rapid7 Announces Critical Vulnerability Check for Automated SQL Injection
May 13, 2008 (10:05 AM EDT)


BOSTON, May 13 /PRNewswire/ -- Rapid7, the leading provider of Unified Vulnerability Management (UVM) solutions for large enterprise deployments and small to medium businesses, announced today that NeXpose includes a check to detect web servers that have been hit by the recent automated mass SQL injection attacks. Web sites hit by this SQL injection attack have their web page contents modified to point to malware that is automatically downloaded by any visitor to the site. These sites are all vulnerable to SQL injection (or have recently been vulnerable) and were hacked by this automated hacker toolkit. In addition, by executing a Google search on the malware server name, hackers can find sites that have been already been exploited.

The "winzipices.cn" SQL injection attack is aimed at web applications based on Microsoft's IIS web server and SQL Server and has hit over 500,000 websites, including the United Nations, UK Government sites and the U.S. Department of Homeland Security. The automated attack takes advantage of the fact that Microsoft's SQL Server allows generic commands that don't require specific table-level arguments. The vulnerability is the result of poor data handling by the sites' creators, rather than a specific Microsoft flaw. The attack injects malicious JavaScript code into every text field in the database. The Javascript then displays in the site's pages and loads an external script that can compromise a user's PC.

According to Microsoft, there's no patch to fix the issue -- the vulnerability lies in custom ASP code that fails to follow well-established security practices for handling database input. Also, according to Microsoft, if your site has been affected, you will need to restore your database from a clean backup copy and start reviewing your code to make sure all input is properly sanitized. To accomplish this, first, companies need to scan for the vulnerability.

While NeXpose has long provided the ability to scan custom web applications for SQL injection flaws, the latest update to NeXpose provides an additional check to help locate servers that have been exploited by the mass SQL injection attacks. By crawling the website, companies can use NeXpose to identify and fix any web servers and databases affected by the attack. Leaving the exploit unnoticed and unfixed allows even the most junior hacker to find and exploit the corrupted site. Finding exploited web sites is as easy as executing a Google search for the malware name. Every web site that is affected will be listed in the Google search.

"Because this is an automated SQL Injection attack, this is a critical security issue for all companies using Microsoft IIS. Once an attacker has access to the underlying database via SQL injection, it is often possible for an attacker to escalate his privileges and attack the underlying operating system that hosts the database. These vulnerabilities open the door for hackers to easily access corporate networks and customer data," stated Tas Giakouminakis, CTO of Rapid7. "Because this is an automated attack, the list of exploits will continue to grow and we expect the automated attack to continue to evolve and for more and more servers to be targeted in the coming weeks."

ABOUT RAPID7

Rapid7 is the leading provider of Unified Vulnerability Management (UVM) Solutions. Rapid7 NeXpose UVM provides network, database and web application vulnerability management for enterprises deployments and small to medium businesses. Since introduced, NeXpose has been sold to corporate enterprises, Global 2000 companies, and government entities, and serves the full range of vertical markets across the U.S. and abroad. In addition, Rapid7 provides compliance products and services for PCI, HIPAA and Sarbanes Oxley. Rapid7 is headquartered in Boston, MA, with offices in California and the United Kingdom. For more information on the company and its product, NeXpose, visit http://www.rapid7.com .

Media Contact Information David Precopio Vice President of Marketing and Business Development Rapid7 LLC 857-288-7354 David_precopio@rapid7.com

CONTACT: David Precopio, Vice President of Marketing and Business David_precopio@rapid7.comDevelopment of Rapid7, +1-857-288-7354,

Web site: http://www.rapid7.com/