MSIE 0-day Spreading Via SQL Injection
By secgeeks - Posted on December 12th, 2008
1557
vote
from sans diary here:
"One of our readers submitted this log entry, which shows a typical SQL injection exploit. The "new" part is that the javascript injected in this case is trying to exploit the MSIE 0-day:
In this case, the SQL injection is delivered as a cookie, not a GET parameter.
I broke up the strings for readability and inserted spaces around the malicious URL. As usual with these kinds of exploit, the script will load another script which will load another script ultimatley leading to the IE exploit."
you can read more here.
Trackback URL for this post:
http://secgeeks.com/trackback/2620
















Recent comments
30 weeks 5 days ago
33 weeks 2 days ago
1 year 2 weeks ago
1 year 2 weeks ago
1 year 2 weeks ago
1 year 18 weeks ago
1 year 34 weeks ago
2 years 25 weeks ago
2 years 26 weeks ago
2 years 28 weeks ago