Archive for the sql injection Category

z360.net/a.js

Posted in sql injection on September 2, 2009 by s3cu

this injected script also has several associated domains

  • dd45h.8866.org/fkzd/16.htm
  • wm.1kfie.cn/x150/xx.html

One of the exploit downloads a rootkit from d.cdwsx.com/xx/x150.css [VT Analysis]

k.18xn.com/x.js

Posted in sql injection on September 1, 2009 by s3cu

active sql-injection attack.

Injected scripts and exploits iframe to several urls such as:

  • www.gehae.info/fox/index.html
  • www.haerh.info/mam.exe

the scripts generate some form of ‘time-based’ parameters that probably is only available for a brief period.

The trojan downloader from www.haerh.info get a list of evil programs from www.gehae.info/2.txt

a0v.org/x.js

Posted in sql injection on July 23, 2009 by s3cu

another round of sql-injection attacks.

x.js calls iframe src www.jejsaj.com/ya/index.html

jejsaj contains various exploits targeting among others

  • owc 0-day
  • realplayer
  • msvidctl.dll

the exploits download trojans from www.wowand.com

f1y.in/j.js

Posted in sql injection on July 11, 2009 by s3cu

another round of sql-injection attempt

Update: beware of this malicious script as it is making use of OWC 0-day.
Ref – http://isc.sans.org/diary.html?storyid=6811

218.213.77.96/a.js

Posted in sql injection on May 28, 2009 by s3cu

a recent round of sql-injected link.
Read more »

3b3.org/c.js

Posted in sql injection on April 16, 2009 by s3cu

This sql-injected script src has been around for some time.

The interesting point of this script is that it behaves differently if the injected site is from “.gov.cn” or “.edu.cn”. Code as shown below: Read more »

cn0093.cn/v.js

Posted in sql injection on March 9, 2009 by s3cu

following previous post, a new injected script has emerged that resolves to same IP.

v.js retrieves another iframe src www.vieio.cn/i.htm.

This exploitation kit tries to avoid detection by splitting each respective exploit into 2 files. One .htm and .js

tsnse.cn/i.js

Posted in sql injection on March 5, 2009 by s3cu

This sql-injected script calls iframe www.gomne.cn/yh.htm

Read more »

deabak.com/z.js

Posted in sql injection on February 26, 2009 by s3cu

this is a new script that are being sql-injected.

z.js contains a iframe from www.893500.cn/2/index.htm

Read more »

iwdown.com/inc/e.js

Posted in sql injection on January 22, 2009 by s3cu

this sql-injected URL contains iframes to www.advpoints.com.
Seems to be profiting thru referrals rather than injecting malware.