Web Attacks Focus on SQL Injection, Malware on Credentials

Web Attacks Focus on SQL Injection, Malware on Credentials
Attackers continue to focus on bread-and-butter tactics, according to a quarterly threat report.

Attackers continued to stick to a well-known playbook for the second quarter of 2019, focusing on attacking websites using SQL injection attacks and stealing passwords and credentials via malware and phishing attacks, according to the latest quarterly threat report from security firm WatchGuard. 


While the company saw a slight decline in many threat metrics — with antivirus detections declining 6% between quarters and more sophisticated threats declining 2% — each of the top 10 network attacks on WatchGuard's list increased in volume, with the frequency of the top attack, SQL injection, jumping by a factor of 12. Overall, the two types of SQL injection attacks included on the list counted for more than a third of all network attacks detected by the firm's devices. 


Only two of the other top 10 attacks — exploits focused on vulnerabilities in Adobe Flash and Shockwave — were not Web-based threats, the report found.


"The top network attacks have remained Web-based attacks for many, many quarters — either a direct vulnerability in Web server software; a Web-client attack, where it is a drive-by download that affects the client; or a Web-application attack on a vulnerability in either a framework that you installed or in your custom code," says Corey Nachreiner, chief technology officer at WatchGuard.


In addition to focusing on attacking Web applications, attackers aimed to harvest credentials from compromised machines and users. The top threat, Mimikatz, is an open source tool originally created in 2014 as a project to learn coding but whose purpose is to harvest several different types of credentials, including plain-text password, hashes, kerberos tickets, and PIN codes.


In addition, a phishing attack that aims to harvest users' credentials also made the top 10 threat list. "The trend of authentica ..

Support the originator by clicking the read the rest link below.