Google: SQL-injection attack not as large as first thought

Google: SQL-injection attack not as large as first thought

Google research suggests Lizamoon attack isn't as big as security firm claimed.

An SQL-injection attack is now returning 1.5 million results over Google, but experts have raised doubts over the scale of the problem.

Last week, security firm Websense reported that hundreds of thousands of sites had been infected via an SQL-injection attack, which was dubbed "Lizamoon" after the name of the website it redirected users to, where it tries to trick them into installing fake antivirus.

 

Websense based its numbers on how many sites were infected by Googling for that web address, but some have said that method of counting isn't entirely accurate, and the attack isn't as big as first feared.

Instead of simply Googling for the URL, the search engine's principal engineer, Niels Provos, counted the sites with a functioning reference, leaving out those that had the code but didn't actually redirect users.

He found the Lizamoon attack actually peaked in October with 5,600 infected sites, but is currently "undergoing a revival". He compared it to the Gumblar attack of two years ago, which peaked at 62,000 infected sites.

Websense said the Google results method merely gave a sense of the scale of the attack.

"All in all, a search on Google returns more than 1,500,000 results that have a link with the same URL structure as the initial attack," Websense said in an updated blog post. "Google Search results aren't always great indicators of how prevalent or widespread an attack is as it counts each unique URL or page, not domain or site, but it does give some indication of the scope of the problem if you look at how the numbers go up or down over time."

However, Websense admitted that the number of sites actually infected was "significantly smaller" than search results suggested, but didn't offer any numbers.

This article originally appeared at pcpro.co.uk

Source: Copyright © PC Pro, Dennis Publishing

See more about:  google  |  sqlinjection  |  attack  |  first  |  thought
 
 

Readers of this article also read...

Terrafugia TF-X flying car concept takes to the skies 

Terrafugia TF-X flying car concept takes to the skies

 
Toshiba's new 2013 laptops unveiled 

Toshiba's new 2013 laptops unveiled

 
Watching Spock curse and sing about Bilbo Baggins is the best thing you'll do today 

Watching Spock curse and sing about Bilbo Baggins is the best thing you'll do today

 
New list of soon-to-be NBN-enabled suburbs released 

New list of soon-to-be NBN-enabled suburbs released

 
Best Android apps this week 

Best Android apps this week

 

Latest Comments

Latest Competitions

Win a PC copy of DEFIANCE plus a Hellbug figurine and messenger bag! 

Win a PC copy of DEFIANCE plus a Hellbug figurine and messenger bag!

Win a Defiance prize pack and join the fight now!
 

Latest Poll

Which broadband network do you think is the best choice for Australia?



or View results
The Coalition's.
  19%
 
Labor's.
  63%
 
Screw this I'm going back to smoke signals and string on a can.
  19%
TOTAL VOTES: 1652

Vote now
Ads by Google

From our Partners

PC & Tech Authority Downloads