Hi Glenn,

Looks like it can be any number of attack vectors.

Your infrastructures are highly vulnerable (NT and IIS 4) and may
contain lots of vulnerabilities you're not aware of. Moreover, your
custom developed CMS which is probably ASP based may have application
security vulnerabilities. Have you tried to search your user's computers
hosts files for this domain (this may prove as an interesting attack
vector). I would highly recommend segregating this application and its
infrastructure from the internet (If possible).

Looks like an SQL injection attack.

Take a look in your MS-SQL database at the affected entries and I bet
you'll see the nmidahena reference.

Since this is a widespread, automated attack that has affected other
sites, it's unlikely it was targeted at your specific organization or
custom CMS. Give your codebase a thorough audit for SQL injection

On Mon, 2008-04-14 at 16:03 -0700, Glenn Gillis wrote:
> On Sunday, 2008-April-13 at 01:07:38.030 UTC, the CMS database of the
> U.S.-based NGO I work for mysteriously had a JavaScript URL appended
> the titles of much of the content on our website:
> <script src=></script>
> NB: the last modified dates for all of the content containing a
> reference to this script are identical, right down the 1/100 second.
> The contents of the script apparently attempts to open an iframe to a
> non-existent domain, "":
> document.writeln("<iframe width=\'10\' height=\'1\'
> src=\'http:\/\/\/1.htm\'><\/iframe>");
> I haven't found any reports of a new worm, etc. that might account for

> this, but when I Google "" I get over 100,000 hits for
> other sites on which this script is present.
> We are running a custom-developed CMS with MS-SQL Server 2000 as the
> backend, on Windows NT Server 4.0 SP6a and IIS 4.0 (Yes, I know! The
> Server is fully patched with whatever OS, IIS and SQL Server 2K
> released prior to NT4's end-of-life declaration by MS, for what it's
> Anyone have an idea what might have caused this?
