Mozillla Firefox, LizaMoon SQL Injection Virus and You.
We've read about the virilent LizaMoon SQL injection virus but until now, I really haven't had that much concern over it, because I'm not running a SQL database, right?
Wrong.
Lookit [sic] what I found something trying to gain access to information in the following directory:
(I've replaced user-specific information with something in [ ] brackets. You'll have to insert the information specific to your system.)
[%systemdrive%]\Users\[yourname]\AppData\Roaming\Mozilla\Firefox\Profiles\[profilename].default
content-prefs.sqlite
cookies.sqlite
downloads.sqlite
formhistory.sqlite
permissions.sqlite
places.sqlite
search.sqlite
signons.sqlite
webappsstore.sqlite
That's right! SQL lite files. Can they be infected? I don't know. The infection is just to insert SQL command scripts into a SQL database manager and it would certainly seem that any SQL database of any kind is fair game. Typically you have to click on something to get this virus to download and install into your computer, by the accounts I've read, but then you click on a lot of things for various reasons on the Web....
I don't have the bandwidth to do an investigation at the moment. I did what everyone should do and that is submit any file you think may have been infected to your anti-virus manufacturer. If you're using freeware or don't have an anti-virus, here's a link:
http://www.agnitum.com/support/submit_files.php
Good luck!
JOHN


Comments