News

SQL Injection Attack Hits BusinessWeek Site

Security firm Sophos disclosed on Monday that BusinessWeek magazine's Web site had been hacked. The attack targeted Microsoft's enterprise SQL Server database via insecure Web pages.

More than one hundred HTML pages in a section designed to help graduating MBA students find job postings got hit by hackers, according to the U.K.-based software security firm. The havoc was caused by the injection of malicious JavaScript code into BusinessWeek's backend database. The code is thought to have originated from servers in Russia.

"All it takes is one vulnerable page," said Graham Cluley, senior technology consultant for Sophos, in an e-mail. "Hackers use search engines all the time to get an entry way into databases. For this reason, Web applications should have the lowest possible privileges."

Cluley cited a recent Sophos report that estimated there is a daily average of about 16,200 infected Web pages shuffled into the sites of trusted brands.

SQL injection attacks have become a concern for Windows enterprise professionals this year. In April, security consultancy White Hat identified isolated cases of SQL-based Web sites injected with malicious JavaScript code. Perhaps the worst of it was seen January when a widespread barrage of SQL injection attacks occurred.

At that time, tens of thousands of Windows Servers and SQL Servers supporting enterprise workstations were affected -- not to mention several thousand Web sites with .gov and .edu domain suffixes. Many of the problems were remedied before serious damage could be done.

Sophos recommends a few best practices to avoid vulnerability to SQL injection attacks. First, tighten up security in custom application code. Next, control access privileges to the enterprise database. Also, use server logs to monitor HTTP requests and query strings.

About the Author

Jabulani Leffall is an award-winning journalist whose work has appeared in the Financial Times of London, Investor's Business Daily, The Economist and CFO Magazine, among others.

comments powered by Disqus

Featured

  • Build Your First AI Applications with Local AI

    "AI right now feels like a vast space which can be hard to jump into," says Craig Loewen, a senior product manager at Microsoft who is helping devs unsure about making that first daunting leap.

  • On Blazor Component Reusability - From Day 0

    "We want to try to design from Day One, even Day Zero, with reusability in mind," says Blazor expert Allen Conway in imparting his expertise to an audience of hundreds in an online tech event on Tuesday.

  • Decision Tree Regression from Scratch Using C#

    Dr. James McCaffrey from Microsoft Research presents a complete end-to-end demonstration of decision tree regression using the C# language. Unlike most implementations, this one does not use recursion or pointers, which makes the code easy to understand and modify.

  • Visual Studio's AI Future: Copilot .NET Upgrades and More

    At this week's Microsoft Ignite conference, the Visual Studio team showed off a future AI-powered IDE that will leverage GitHub Copilot for legacy app .NET upgrades, along with several more cutting-edge features.

  • PowerShell Gets AI-ified in 'AI Shell' Preview

    Eschewing the term "Copilot," Microsoft introduced a new AI-powered tool for PowerShell called "AI Shell," available in preview.

Subscribe on YouTube