Hi,
1) This is called Javascript injection attack.
Basically, the attacker launches an SQL injection attack against your website. SQL injection attacks try to exploit trust relationships between web applications and the databases that support them in order to add, remove or modify data in databases in ways it was never intended. In the case of your website, the intent of the SQL injection is to add a single line of HTML code to the database so that yourwebsite.com will present it to every user who visits the site.
The initial code has been an HTML "script" command, which is used to define a segment of code for your browser to run. The code segment to run is a malicious javascript hosted at (222.231.60.19) server.
2) Since your site got infected I suggest that you:
A. Take the site down to protect other Internet users.
B. Replace the contents of the site with a known clean backup
C. Change all password on the site (including FTP credentials)
D. Patch all the sites software
E. Reload the site.
3) To prevent such attack in the future, please check the following links:
http://www.breach.com/reso
http://msmvps.com/blogs/ha
http://msdn.microsoft.com/
http://msdn.microsoft.com/
4) Use a Website vulnerability scanner to detect any security flaws:
http://sectools.org/web-sc
http://www.beyondsecurity.
http://wapiti.sourceforge.
http://www.acunetix.com/vu
http://www.codescan.com/
5) You need to install a Web Application Firewall (Commercial / Open Source) to defend against such attacks, Check the following links:
http://www.modsecurity.org
http://guardian.jumperz.ne
http://www.aqtronix.com/?P
http://www.microsoft.com/d
http://www.networkworld.co
http://searchsoftwarequali
http://www.crn.com/it-chan
http://www.networkcomputin
www.citrix.com/english/ps2
http://www.breach.com/prod
http://www.networkcomputin
Good luck
Symantec Certified Specialist
Main Topics
Browse All Topics





by: slick_moePosted on 2009-06-22 at 14:39:30ID: 24686805
On the same day of this posting, I'm having the exact same problem on my website. Are you on a shared server?