1
peterr
New SQL injection attacks
  • 2008/9/26 13:17

  • peterr

  • Just can't stay away

  • Posts: 518

  • Since: 2004/8/5 9


I've noticed some entries in our web servers log, that are new in format. As there were for Smartsection, I contacted Marcan from SmartFactory, who has been very helpful in advising about this problem.

It's not a Smartsection issue, but a new type of SQL injection attack.

Try this Google search:

http://www.google.com/search?hl=en&client=firefox-a&rls=org.mozilla%3Aen-US%3Aofficial&hs=VCr&q=DECLARE%2520%40S%2520CHAR%284000%29%3BSET%2520%40S%3DCAST&btnG=Search

some very helpful ways to address the problem. We use protector, but I'm not sure protector will know about this or pickup that there are problems. The logs we have returned a "200" , and this is an issue I have raised before, that a "200" doesn't always means 'all is well'.

If the XOOPS developers are looking to develop a similar module as protector and have it as included in a standard XOOPS release, then there would be certain words/phrases being passed in URL's, that this new module could look for. This webmaster world thread shows how .htaccess can address the problem.

http://www.webmasterworld.com/apache/3731562.htm

HTH

Peter



NO to the Microsoft Office format as an ISO standard.
Sign the petition

2
ghia
Re: New SQL injection attacks
  • 2008/9/26 16:26

  • ghia

  • Community Support Member

  • Posts: 4953

  • Since: 2008/7/3 1


According the web robot abuse blog the hack
Quote:
doesnt look like they are atacking PHP they are atacking ASP Cold Fusion and Perl
.

Nevertheless, they recommend a good .htaccess script from Hacking & Security. It acts as a kind of Firewall against various kinds of SQL injections.

Advantage is that with this approach, the attack is countered by Apache itself. So nor XOOPS or Protector are disturbed or challenged.

I recommend that everyone should merge it in his .htaccess if possible!

Login

Who's Online

257 user(s) are online (155 user(s) are browsing Support Forums)


Members: 0


Guests: 257


more...

Donat-O-Meter

Stats
Goal: $100.00
Due Date: Apr 30
Gross Amount: $0.00
Net Balance: $0.00
Left to go: $100.00
Make donations with PayPal!

Latest GitHub Commits