5 ms·
Mass Infection of IIS/ASP Sites
- juanufrj 16y agoMore details: http://isc.sans.edu/diary.html?storyid=8935 http://isc.sans.edu/diary.html?storyid=8935 http://nsmjunkie.blogspot.com/2010/06/anatomy-of-latest-mass-iisasp-infection.html http://nsmjunkie.blogspot.com/2010/06/anatomy-of-latest-mass... According to the articles, more than 100k sites hacked.
- kogir 16y agoYawn. Sql injection again. Can happen on any platform. Hint: Use SPs for all your data access and don't give your app direct access to the tables. Makes stuff like this infinitely less likely to work.
- maukdaddy 16y agoYou know...if it were that easy then this would be a solved problem. But it isn't that easy, especially in large, enterprise environments.
- rbanffy 16y agoBy using SPs you more or less double the effort to port your application away from whatever database you are using. Better to use an ORM.
- tptacek 16y agoYou mean, except for the part where ORM-based applications are usually still injectable.
- RyanMcGreal 16y agoDon't ORMs use parameterized queries by default?
- tptacek 16y agoYes, but they don't parameterize the sort order on every sortable table, or the limits used in pagination, or the custom join expressions ORM developers inevitably write.
- RyanMcGreal 16y agoThanks for clarifying. Every time I think I have a handle on website security, it turns out to be more complex and insidious than I thought.
- rbanffy 16y agoI am quite sure Django's ORM (the one I use every day) would properly protect limits and pagination.
- tptacek 16y agoThat's nice. Until you forget to quote_name a dynamically selected table name.
- rbanffy 16y agoWhy would you want to name a table dynamically?
- tptacek 16y agoThanks for helping make my point about real-world dev vs. on-paper dev. But, to be clear, you don't often create tables with dynamic names (though you will sometimes; for instance, to repeatedly load huge datasets, which comes up in time-series apps)... but you very often need to select which table to use at runtime based on user inputs. Again, in real-world apps. For what it's worth, I believe the same quote_name() mistake pops up with column names too. But you probably don't dynamically select those based on inputs either.
- deleted 16y ago
- johns 16y agoSame can be said for sprocs. Any popular ORM will have proper handling for parameters. In both cases you can't rely on the tool, you have to know what you're doing.
- tptacek 16y agoIt's true that stored procedures can be injectable, but it's extremely rare, and you can find the 0.1% of them that might be with a simple grep regex, unlike ORMs.
- rbanffy 16y agoIt all depends on how you abuse your ORM. There must be some ORMs where you can do it, but, gladly, I believe I am not using any of them.
- ronnier 16y agoStored procedures aren't even required. Just use parameterized queries.
- jgg 16y agoCan anyone give me a technical reason to deploy on a IIS and ASP platform instead of Apache/Nginx and one of the dozens of open source solutions for deploying a web application? From where I'm sitting, it seems to me the reasoning is "I drank the Microsoft Kool-Aid". Surely there's a better reason than that.
- bshep 16y agoMore like: "Management Drank the MS Kool-Aid" If your boss says you must use IIS then not much you can do.
- chrisbolt 16y agoIf management drinks the MS Kool-Aid, they're probably hiring people who drink the MS Kool-Aid.
- teilo 16y agoThat's not necessarily true. Microsoft lobbyists specifically target middle and upper management, and using arguments from authority, convince them that they must stay on Windows/IIS because it has better ROI.
- tptacek 16y agoFor most companies, IIS does have a better ROI than, say, Rails.
- poundy 16y agoI got hacked similarly on my blog and it went undetected when my wordpress code files were changed. Now I can detect the website/server is hacked using this php code http://www.webdigi.co.uk/blog/2009/how-to-detect-if-your-webserver-is-hacked-and-get-alerted/ http://www.webdigi.co.uk/blog/2009/how-to-detect-if-your-web... (like tripwire) This helped me a couple of times and once when a hack on my wordpress blog only showed different page links to the google bot!