Reports of a Distributed Injection Scan
We have received a report of a large distributed SQL Injection Scan from a reader. Behavior of scan is being reported as 9000+ Unique IPv4 Addresses and sends 4-10 requests to lightly fuzz the form field. Then the next IP will lightly fuzz the second form field within the same page and the next IP the next form field. Looks to be targeting MSSQL and seeking version.
The reader reports that this scan has been going on for several days.
Sample Payload:
%27%29%29%2F%2A%2A%2For%2F%2A%2A%2F1%3D%40%40version--
%27%2F%2A%2A%2For%2F%2A%2A%2F1%3D%40%40version--
%27%2F%2A%2A%2For%2F%2A%2A%2F1%3D%40%40version%29%29-
%29%29%2F%2A%2A%2For%2F%2A%2A%2F1%3D%40%40version--
%29%2F%2A%2A%2For%2F%2A%2A%2F1%3D%40%40version--
The User Agent String for all of the attacking IPs is always
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
There does not seem to be a referrer page either.
If you are seeing this activity and can report it please let us know.
Richard Porter
--- ISC Handler on Duty
Comments
AB
Oct 6th 2012
1 decade ago
jono
Oct 8th 2012
1 decade ago
145 Unique IP Addresses, however they all belong to the same AS allocated to a provider in the US, (I presume the same one as AB mentioned)
Doesn't seem like the injections were successful. Will keep an eye out though.
Yin
Oct 10th 2012
1 decade ago
Mozilla/5.2+(Windows;+U;+Windows+NT+5.2;+en-EN)+Gecko/20090818+Firefox/3.5.6
Yin
Oct 10th 2012
1 decade ago
David
Oct 15th 2012
1 decade ago