Another domain to look for in SQL injection attacks is dbrgf.ru, still calling script.js. Checking your proxy logs for ".ru/script.js" is a good idea at the moment.
It might also be worth checking for the string "google-analitycs" as the attacks redirect through a subdomain containing that mis-spelled phrase.
Asprox: dbrgf.ru
Posted by
Conrad Longmore
at
11:51
Friday, 23 January 2009
Labels:
Asprox,
SQL Injection,
Trojans,
Viruses
Subscribe to:
Post Comments (Atom)
RSS Feed

0 comments:
Post a Comment