<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://msmvps.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Asprox Botnet Installs SQL Injection Tool</title><link>http://msmvps.com/blogs/harrywaldron/archive/2008/05/16/asprox-botnet-installs-sql-injection-tool.aspx</link><description>A small botnet known as Asprox has been used in password stealing, spam, and phishing attacks. This week Asprox was modified to include a new SQL Injection tool. As recently shared, SQL injection attacks are more reflective of poorly programmed Internet</description><dc:language>en</dc:language><generator>CommunityServer 2008.5 SP2 (Build: 40407.4157)</generator><item><title>re: Asprox Botnet Installs SQL Injection Tool</title><link>http://msmvps.com/blogs/harrywaldron/archive/2008/05/16/asprox-botnet-installs-sql-injection-tool.aspx#1652601</link><pubDate>Fri, 31 Oct 2008 02:53:38 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1652601</guid><dc:creator>Applicure Technologies</dc:creator><description>&lt;p&gt;Here is the correct download link:&lt;/p&gt;
&lt;p&gt;&lt;a rel="nofollow" target="_new" href="http://www.applicure.com/affiliates/idevaffiliate.php?id=504"&gt;www.applicure.com/.../idevaffiliate.php&lt;/a&gt;&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1652601" width="1" height="1"&gt;</description></item><item><title>re: Asprox Botnet Installs SQL Injection Tool</title><link>http://msmvps.com/blogs/harrywaldron/archive/2008/05/16/asprox-botnet-installs-sql-injection-tool.aspx#1651121</link><pubDate>Fri, 17 Oct 2008 09:13:15 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1651121</guid><dc:creator>Jerry Mollany</dc:creator><description>&lt;p&gt;Our website was under attack with some kind of an injection.&lt;/p&gt;
&lt;p&gt;We tried to deal with it for 2 weeks with no success.&lt;/p&gt;
&lt;p&gt;We tested a few products and eventually, we found a tool name dotDefender that actually stop all those attacks and more of them that appeared in the log files.&lt;/p&gt;
&lt;p&gt;The main site where you can download dotdefender for 30 days is at: &lt;a rel="nofollow" target="_new" href="http://www.applicure.com"&gt;http://www.applicure.com&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Jerry M.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1651121" width="1" height="1"&gt;</description></item><item><title>re: Asprox Botnet Installs SQL Injection Tool</title><link>http://msmvps.com/blogs/harrywaldron/archive/2008/05/16/asprox-botnet-installs-sql-injection-tool.aspx#1650712</link><pubDate>Mon, 13 Oct 2008 16:59:43 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1650712</guid><dc:creator>Raviv Raz</dc:creator><description>&lt;p&gt;More details on ASPROX, SQL Injections at:&lt;/p&gt;
&lt;p&gt;&lt;a rel="nofollow" target="_new" href="http://chaptersinwebsecurity.blogspot.com/2008/07/asprox-silent-defacement.html"&gt;chaptersinwebsecurity.blogspot.com/.../asprox-silent-defacement.html&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;You can find download links for:&lt;/p&gt;
&lt;p&gt;- Injector: tests for ASPROX vulnerability on websites&lt;/p&gt;
&lt;p&gt;- dotDefender: protects web sites against ASPROX&lt;/p&gt;
&lt;p&gt;Raviv&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1650712" width="1" height="1"&gt;</description></item><item><title>re: Asprox Botnet Installs SQL Injection Tool</title><link>http://msmvps.com/blogs/harrywaldron/archive/2008/05/16/asprox-botnet-installs-sql-injection-tool.aspx#1649394</link><pubDate>Wed, 01 Oct 2008 15:05:52 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1649394</guid><dc:creator>Kamal</dc:creator><description>&lt;p&gt;Researching Asprox and Beanie seems to turn up everywhere, spammer....&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1649394" width="1" height="1"&gt;</description></item><item><title>re: Asprox Botnet Installs SQL Injection Tool</title><link>http://msmvps.com/blogs/harrywaldron/archive/2008/05/16/asprox-botnet-installs-sql-injection-tool.aspx#1648329</link><pubDate>Thu, 18 Sep 2008 11:59:59 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1648329</guid><dc:creator>lo;</dc:creator><description>&lt;p&gt;l;l&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1648329" width="1" height="1"&gt;</description></item><item><title>re: Asprox Botnet Installs SQL Injection Tool</title><link>http://msmvps.com/blogs/harrywaldron/archive/2008/05/16/asprox-botnet-installs-sql-injection-tool.aspx#1642745</link><pubDate>Wed, 30 Jul 2008 22:25:24 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1642745</guid><dc:creator>Beanie</dc:creator><description>&lt;p&gt;This virus took my site offline for 3 weeks and I had to seek an internet security company to fix my site.&lt;/p&gt;
&lt;p&gt;It cost me £50 but well worth it after the hastle I have had!!&lt;/p&gt;
&lt;p&gt;Hope this helps others:&lt;/p&gt;
&lt;p&gt;&lt;a rel="nofollow" target="_new" href="http://www.firestorm-online.com/trojans/asprox/"&gt;www.firestorm-online.com/.../asprox&lt;/a&gt;&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1642745" width="1" height="1"&gt;</description></item><item><title>re: Asprox Botnet Installs SQL Injection Tool</title><link>http://msmvps.com/blogs/harrywaldron/archive/2008/05/16/asprox-botnet-installs-sql-injection-tool.aspx#1639236</link><pubDate>Thu, 03 Jul 2008 11:56:48 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1639236</guid><dc:creator>Yossarian</dc:creator><description>&lt;p&gt;We recently had a bunch of sites hit by the SQL injection. It is a nightmare. It looks like we had one vulnerable querystring that we had overlooked. It took 3 days to find it as well. As it is all automated even if your site gets hacked and you clean the data you either need to take the site completely down or monitor it 24/7 until the vulnerabilities are discovered.&lt;/p&gt;
&lt;p&gt;We found the attacks would be occur hourly in some cases. &lt;/p&gt;
&lt;p&gt;I guess it is a lesson learned to triple check every querystring &amp;amp; sql statement.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1639236" width="1" height="1"&gt;</description></item></channel></rss>