Playstation website suffers SQL injection attack
by Steven Williamson
on 3 July 2008, 10:15
Quick Link: HEXUS.net/qan3g
Add to My Vault:
Please log in to view Printer Friendly Layout |
|
Sophos say that:
"Visiting the affected PlayStation site runs a script that pretends to do an online security scan of your computer, and presents a bogus warning message that your PC is infected with a variety of different pieces of malware. Users frightened by the scareware 'warnings' might rush to spend money on useless software."
Graham Cluley, senior technology consultant says that the malicious code currently just tries to scare visitors to Sony's PlayStation site with bogus malware warnings, but it could just as easily install a keylogging Trojan.
"Most would never expect that surfing to a website like this could potentially infect them with malware. If users do not have sufficient protection in place then they might find that before they know it they have been scared into handing their credit card details over to a bunch of cyber-criminals," said Curley.
The problem isn't exclusive to the Playstation site, many other sites have also suffered from the same attack.
"It is essential that all websites, especially when they are high profile like this or receiving a large level of traffic, have been properly hardened to prevent hackers from injecting malicious code on to what should be legitimate webpages," warned Sophos.
Source :: Yahoo news