𝔖 Bobbio Scriptorium
✦   LIBER   ✦

Defacing websites via SQL injection

✍ Scribed by Johannes B. Ullrich; Jason Lam


Book ID
104392495
Publisher
Elsevier Science
Year
2008
Tongue
English
Weight
126 KB
Volume
2008
Category
Article
ISSN
1353-4858

No coin nor oath required. For personal study only.

✦ Synopsis


In early February 2007, security communities became aware of a major sports event website distributing malware. 1 It infected visitors through a well-known technique at the time, which was a VML exploit targeting Internet Explorer browsers. Any visitors running Internet Explorer without the VML patch could be infected with the trojan.