LizaMoon attack infects millions of websites

By Stacy Cowley, tech editor


NEW YORK (CNNMoney) -- Have you heard the scary news about 'LizaMoon,' a malicious code attack that has already infected more than a million websites?

Don't panic. This particular bit of hacker mischief is setting off alarms among online security watchdogs for its speed and scope, but built-in software safeguards mean few actual users will end up suffering.

The exploit drew headlines because it's affecting a surprisingly large number of websites -- nearly 4 million so far -- and because some of those sites feed into Apple's iTunes platform. Websense, the security software vendor that first broke the news about LizaMoon in its blog, played up the iTunes connection in its first warning about the attack.

But Apple (AAPL, Fortune 500) has iTunes designed to automatically neutralize this kind of threat. That means there's zero risk of an iTunes user's computer actually getting infected by this bit of malware. Websense acknowledged that in its latest LizaMoon update.

"Every time there's a mass-injection like this, and there really hasn't been anything this big before, we try to identify larger systems and sites that have been affected," the company wrote in its blog. "There are few systems out there bigger than iTunes, so when we saw that content on itunes.apple.com contained the injected link we wanted to make people aware of that, even if the script didn't work."

LizaMoon is what's called a SQL code injection attack, where a Web application vulnerability is exploited to inject malicious code into affected websites. If a Web surfer visits an affected site, they'll be redirected to a rogue website that tries to install a "scareware" file. The file generates messages warning the user that their computer is infected with viruses, and offers to sell them antivirus software in defense. Most actual, legitimate antivirus programs will detect and eliminate the malicious file.

And most websites have protections in place to prevent them from getting infected in the first place. While LizaMoon has infested million of websites, security experts say it's a run-of-the-mill threat that is mostly hitting obscure, low-traffic sites.

"Defense against your sites getting infected is the standard things we ought to be doing anyway," the SANS Internet Storm Center, a security monitoring site, wrote in its LizaMoon analysisTo top of page

Frontline troops push for solar energy
The U.S. Marines are testing renewable energy technologies like solar to reduce costs and casualties associated with fossil fuels. Play
25 Best Places to find rich singles
Looking for Mr. or Ms. Moneybags? Hunt down the perfect mate in these wealthy cities, which are brimming with unattached professionals. More
Fun festivals: Twins to mustard to pirates!
You'll see double in Twinsburg, Ohio, and Ketchup lovers should beware in Middleton, WI. Here's some of the best and strangest town festivals. Play
How to spend less on gas
Driving aggressively and letting your car idle drains fuel from your tank and money from your wallet. Play
Confessions of a Volt owner
After driving the Chevrolet Volt for 14 months and saving about $1,800 per year on gas, the electric car owner shares his experiences. Play
Playing the blame game on gas prices
From speculators to tensions in Iran, there's plenty of finger pointing when it comes to high gas prices. But investors like T. Boone Pickens says it's just plain old economics at work. Play
Index Last Change % Change
Dow 12,980.30 28.23 0.22%
Nasdaq 2,988.97 22.08 0.74%
S&P 500 1,374.09 8.41 0.62%
Treasuries 2.04 0.06 3.03%
Data as of 5:06am ET
Company Price Change % Change
Microsoft Corp 32.29 0.55 1.73%
Pfizer Inc 21.50 0.38 1.78%
Wal-Mart Stores Inc 58.81 -0.27 -0.46%
MetroPCS Communicati... 10.86 0.56 5.49%
Walgreen Co 32.77 -0.39 -1.18%
Data as of Mar 1
Sponsors

Sections

Which companies have the best reputations? Apple tops the list for the fifth year in a row. See who else made the top 50 this year and vote for your favorite company. More

According to a new analysis from the Tax Policy Center, wealthy Americans would see their taxes fall precipitously under Mitt Romney's new plan. More

Microsoft unveils consumer preview of Windows 8 to the public, allowing everyday users to test the company's new swing-for-the-fences OS. More

Dallas area physician Dr. Jacques Roy allegedly bilked Medicare for nearly $374 million in fake billings over five years. More

Credit unions hit a record number of members last year, as a growing number of consumers grew fed up with the fees at the nation's biggest banks and took their money elsewhere. More

Market indexes are shown in real time, except for the DJIA, which is delayed by two minutes. All times are ET. Disclaimer LIBOR Warning: Neither BBA Enterprises Limited, nor the BBA LIBOR Contributor Banks, nor Reuters, can be held liable for any irregularity or inaccuracy of BBA LIBOR. Disclaimer. Morningstar: © 2012 Morningstar, Inc. All Rights Reserved. Disclaimer The Dow Jones IndexesSM are proprietary to and distributed by Dow Jones & Company, Inc. and have been licensed for use. All content of the Dow Jones IndexesSM © 2012 is proprietary to Dow Jones & Company, Inc. Chicago Mercantile Association. The market data is the property of Chicago Mercantile Exchange Inc. and its licensors. All rights reserved. FactSet Research Systems Inc. 2012. All rights reserved. Most stock quote data provided by BATS.