Skip to content Skip to sidebar Skip to footer
×

Did you know you can cook bread with steam?

Yatırımsız Deneme Bonusu

Yatırımsız deneme bonusunun ne olduğunu, nasıl alındığını ve faydalanma yöntemlerini öğrenin. Risk almadan bonus avantajlarından yararlanın!Online bahis ve casino dünyası giderek genişlerken, kullanıcılarına sunduğu avantajlar da artmaya devam ediyor. Yatırım yapmadan kazanç elde etme şansı sunan yatırımsız deneme bonusu, bu avantajlar arasında en cazip olanlardan biri olarak öne çıkıyor. "Yatırımsız Deneme Bonusu" adını verdiğimiz bu…

Read more

MSI’s Upcoming Slate Has Laptops For Gamers, Digital Creators And Astronauts

World-leading laptop manufacturer MSI has unveiled an impressive lineup of laptops for 2020 that appeal to a wide range of users. Leading the way are its flagship laptops, the GE66 Raider and GS66 Stealth, representing quite different takes on the gamer aesthetic. The GE66 Raider Aurora Edition is “the fusion of sci-fi and resplendency,” according to MSI.…

Read more

LG Gram Pre-Packed With Windows 11

Not only are all LG Gram laptops set to be shipped with Windows 11 already onboard to make life easier for customers, the company say previous LG Gram models can be upgraded to it by visiting the Microsoft website. “Shipping LG gram laptops with Windows 11 immediately after the OS launch is an example of our…

Read more

© 2026 Appliancenews. All Rights Reserved.

Fake Security Alert Brings Down Tens Of Thousands Of Web Sites

High tech criminals have crashed hundreds of thousands of web sites around the world including Australia, according to security research company Websense.

Using fake securtity software, the criminals attack web sites by sending out a piece of code, that generates a fake security alert that exploits security loopholes on other sites.

The criminals then insert a link to the website so that visitors to the infected sites are prompted with a message telling them that they have a virus on their computer.

Patrik Runald, senior manager for security research at Websense said that the scale of the attack was “worrying”

The BBC said that  Websense has been tracking the attack since it started on 29 March. The initial count of compromised sites was 28,000 sites but this has grown to encompass many times this number as the attack has rolled on across several Countries.

Websense dubbed it the Lizamoon attack because that was the name of the first domain to which victims were re-directed. The fake software is called the Windows Stability Center.

The re-directions were carried out by what is known as an SQL injection attack. This succeeded because many servers keeping websites running do not filter the text being sent to them by web applications.

The fake security software warns about non-existent viruses on victims’ PCs

By formatting the text correctly it is possible to conceal instructions in it that are then injected into the databases these servers are running. In this case the injection meant a particular domain appeared as a re-direction link on webpages served up to visitors.

 

Early reports suggested that the attackers were hitting sites using Microsoft SQL Server 2003 and 2005 and it is thought that weaknesses in associated web application software are proving vulnerable.

Ongoing analysis of the attack reveals that the attackers managed to inject code to display links to 21 separate domains. The exact numbers of sites hit by the attack is hard to judge but a Google search for the attackers’ domains shows more than three million weblinks are displaying them.

Security experts say it is the most successful SQL injection attack ever seen.

Generally, the sites being hit are small businesses, community groups, sports teams and many other mid-tier organisations.

Currently the re-directs are not working because the sites peddling the bogus software have been shut down.

Also hit were some web links connected with Apple’s iTunes service. However, wrote Websense security researcher Patrick Runald on the firm’s blog, this did not mean people were being redirected to the bogus software sites.

“The good thing is that iTunes encodes the script tags, which means that the script doesn’t execute on the user’s computer,” he wrote.

Leave a comment

0.0/5