BusinessWeek website attacked and hosts malware

Folks from Sophos have discovered that the website of BusinessWeek, the world famous weekly magazine, has been attacked by hackers in an attempt to infect its readership with malware.

Hundreds of webpages in a section of BusinessWeek’s website which offers information about where MBA students might find future employers have been affected.  According to Sophos, hackers used an SQL injection attack – where a vulnerability is exploited in order to insert malicious code into the site’s underlying database – to pepper pages with code that tries to download malware from a Russian web server.

At the time of writing, the code injected into BusinessWeek’s website points to a Russian website that is currently down and not delivering further malicious code.  However, it could be revived at any time, infecting hundreds of MBA students looking for high-earning jobs.  Sophos informed BusinessWeek of the infection last week, although at the time of writing the hackers’ scripts are still present and active on their site.

Here is a video showing the infection: