Warning, new nasty worm on the loose, be very careful
Hi folks
Raise the alarm, it seems a nasty new worm is on the loose. Sadly too late for me, my SQL database has been infected twice in the past ten days, and even if I have some backup I lost some data :-(
I identified the culprit as Jpdog.3322 and it comes as a javascript code. Now it’s really serious thing, last week when I google it, I had 6 pages of results, now today more than 11000 results and going on strongly. If you search for it, you will see that nobody has really offered so far a remedy to eradicate this stuff. Most of the results I can find here are lots and lots of website affected. I have no clue how to escalate the issue to Microsoft. I tried with Symantec and Avast but so far no reply. Our databases were damaged, the worm has modified the content of most of the text fields, making the data totally useless. I was thinking first of a flaw in IE, but for this project, my users are requested to use Firefox only. I then thought about SQL injection, but this is quite unlikely regarding the way that the data is managed. The SQL Server 2005 software runs with Windows 2008 Server.
The origin of this is not clear but it looks all back to China.
Thanks for the help if you have any clue. I will surely secure more my database, not sure if I can get rid of sa login at all? My users are logged under another account anyway but be very careful.
It looks innocent at first but it could make your data totally obsolete, or even worst, spread around without your knowledge. Great now I am stuck with a big issue just before Christmas, not cool :-(
UPDATE: I am now using URLScan Filter from Microsoft which should be part of the default IIS in my opinion
Check here for this tool