Posts

Showing posts from June, 2008

Solution to flyzhu.9966.org

A website that I was helping to maintain recently got itself infected with something pointing to flyzhu.9966.org. Searching google for more information on flyzhu brings up tonnes of infected sites but no clear information about flyzhu except that it is some sort of SQL injection attack. The urgency of the matter meant that I turned to specialist sites such as the antivirus companies to try to find more information about how to disinfect or protect against flyzhu. However, the search had not yield much tangible results. No antidote or system patch was found to specifically address the flyzhu problem. The most likely solution to flyzhu ended up to be the one that will require the most significant work; sanitising parameter values before using them to construct the SQL statements for execution. This solution brings up the realisation that the vendor whom had been contracted to create the website was delivering substandard coding that is vulnerable to SQL injections. Flyzhu infection would