::Trend Micro Threat Resource Center::

30 December 2008

Chinese schools, search sites host malicious code

Two universities and two major search portals based in China fell prey to online attackers in the past week, with each site compromised to include malicious code that attempts to gain control of visitors' computers, a security firm said this week.

The compromised sites are:
  • China.com
  • Sohu.com
  • Huazhong normal University webpage
  • Pekin University webpage
Inserting malicious code into legitimate sites has become an increasingly popular way to infect Internet users' computers. Many of the attacks use flaws in a Web site's back-end database system, such as the recent flaw in Microsoft's SQL server, to add unauthorized code to vulnerable sites.

Earlier this year, attackers had used search-engine optimization (SEO) techniques to include malicious code in the searches cached on various major Web sites, including Wired.com and CNET Networks' online properties.

Read more here.