SQL Attacks Inject Government Sites in U.S., UK
Dan Goodin writes on The Register:
A new round of SQL injection attacks has infected millions of web pages belonging to businesses and government agencies, including those that belong to the National Institutes of Health and Education Department in the US and the UK Trade & Investment.More here.
This search shows at least 1.45 million infected pages and queries here and here out some of the US and UK government websites that have been hit by the attack. Not exactly reassuring to know that government-run websites are open to such a basic attack.
We strongly recommend not clicking on the infected sites unless you know what you're doing. Punters unfortunate to land on infected pages that are still live can wind up at sites "where a CGI script starts the road of pain," according to this post from SANS.