Re: [Full-disclosure] Redmond Magazine SQL Injected by Chinese Hacktivists

2008-05-18 Thread Stuart Dunkeld
Funnily enough, I noticed this yesterday when looking for some info on Virtual Server. Google has ~ 45,000 hits for wowyeye.cn/m.js but only a small minority are marked as malicious sites.. Other pages on redmondmag.com - for example

Re: [Full-disclosure] Redmond Magazine SQL Injected by Chinese Hacktivists

2008-05-18 Thread Nate McFeters
So far from what I've read I've only heard talk of this as SQL injection to update tables and put in these malicious links, but I've heard no talk of data exfiltration... Has anyone heard about data being stolen as a result of this widespread attack? Nate On 5/17/08, Stuart Dunkeld [EMAIL

[Full-disclosure] Redmond Magazine SQL Injected by Chinese Hacktivists

2008-05-17 Thread Dancho Danchev
Hello, It appears that Redmond - The Independent Voice of the Microsoft IT Community, formerly known as Microsoft Certified Professional Magazine is currently flagged as a badware site, and third-party exploit detection tools are also detecting internal pages as exploit hosting ones, in this