Tycoon Talk
Become a Big fish!
The number 1 forum for online business!
Post topics, ask questions, share your knowledge.
Tycoon Talk is part of Freelancer.com - find skilled workers online at a fraction of the cost.

ASP.NET Forum


You are currently viewing our ASP.NET Forum as a guest. Please register to participate.
Login



Closed Thread
Possible SQL Injection attack...i think!!!
Old 10-22-2009, 12:49 PM Possible SQL Injection attack...i think!!!
Novice Talker

Posts: 8
Name: Greg
Trades: 0
Hi,

I just came across a piece of script that has been put into my source code throughout the site...and not by me!!!. Im using ASP pages and sql 2000 db.

Im not sure how they did it but im fearing this could get more serious and end up them hitting my db. Here is example(kind of) of the script im finding...

Code:
<script src="Http://www.domainname.com /a /a .php></script>
HELP!!!!
The Mighty Dub is offline
View Public Profile
 
 
Register now for full access!
Old 10-22-2009, 02:11 PM Re: Possible SQL Injection attack...i think!!!
Brian07002's Avatar
Defies a Status

Posts: 2,138
Name: ...
Location: ...
Trades: 0
Not sure about what that could be, but I wouldn't count it out as an attack on your website.
__________________
Made2Own

Please login or register to view this content. Registration is FREE
Brian07002 is offline
View Public Profile
 
Old 10-22-2009, 02:39 PM Re: Possible SQL Injection attack...i think!!!
frih's Avatar
Super Talker

Posts: 139
Name: abhi
Location: http://www.techbusy.org/
Trades: 0
Well, it is not just your site, may be the whole server is under attack. Ask your webhost for this.
__________________

Please login or register to view this content. Registration is FREE
|

Please login or register to view this content. Registration is FREE


Please login or register to view this content. Registration is FREE
frih is offline
View Public Profile Visit frih's homepage!
 
Old 10-22-2009, 03:02 PM Re: Possible SQL Injection attack...i think!!!
chrishirst's Avatar
Missing! presumed drunk.

Posts: 41,516
Name: Chris Hirst
Location: Blackpool. UK
Trades: 0
It is a cracking/infiltration attemp. Change your FTP password straight away and inform your host as it may be some other client on the server if you are on shared hosting
__________________
Chris. ->> Links are advertising NOT optimising!! <<-
A foolish consistency is the hobgoblin of little minds
Thought for today:- I SEO the only industry where all the cowboys are Indians?
chrishirst is online now
View Public Profile Visit chrishirst's homepage!
 
Old 10-22-2009, 03:39 PM Re: Possible SQL Injection attack...i think!!!
alex021's Avatar
Super Talker

Posts: 118
Name: Alex
Trades: 0
change your ftp passwords and scan your pc for viruses/spyware
__________________

Please login or register to view this content. Registration is FREE


Please login or register to view this content. Registration is FREE
---
Please login or register to view this content. Registration is FREE
---
Please login or register to view this content. Registration is FREE
alex021 is offline
View Public Profile
 
Old 11-07-2009, 11:12 AM Re: Possible SQL Injection attack...i think!!!
Banned

Posts: 421
Location: Boston, MA
Trades: 1
I see similar thing with a unix server, php scripts; somebody was adding pron links on all pages. you should consult with your hosting company asap and check all your scripts.
webcosmo is offline
View Public Profile Visit webcosmo's homepage!
 
Old 11-17-2009, 10:56 PM Re: Possible SQL Injection attack...i think!!!
Extreme Talker

Posts: 206
Name: vikas
Trades: 0
are you using some scripts like wordpress .. older version of these script are pron to sql injection script
__________________

Please login or register to view this content. Registration is FREE
Collection of free online books and free ebooks
Please login or register to view this content. Registration is FREE
- Free online pdf books and free pdf eBooks
vikas1234 is offline
View Public Profile
 
Old 11-19-2009, 03:18 PM Re: Possible SQL Injection attack...i think!!!
Junior Talker

Posts: 4
Name: frank
Trades: 0
This does look like an SQL injection attack. If you're using an older version of WordPress, this was recently a common exploit. Here is some info about how to fix it if you're using WordPress: http://www.wpbeginner.com/news/wordp...latest-attack/
__________________

Please login or register to view this content. Registration is FREE
speak66 is offline
View Public Profile
 
Old 11-28-2009, 09:06 AM Re: Possible SQL Injection attack...i think!!!
Novice Talker

Posts: 7
Trades: 0
its not sql injection.. just change your FTP pass and scan your PC, or reinstall your windows
__________________

Please login or register to view this content. Registration is FREE
//
Please login or register to view this content. Registration is FREE
//
Please login or register to view this content. Registration is FREE
//
Please login or register to view this content. Registration is FREE
//
Please login or register to view this content. Registration is FREE

dex505 is offline
View Public Profile Visit dex505's homepage!
 
Old 12-22-2009, 12:44 AM Re: Possible SQL Injection attack...i think!!!
Novice Talker

Posts: 14
Trades: 0
First is it in your data rows? Also are you filtering Apostrophies ( ' ) when on your select and update statements?

If it is in your data, this yes it is injection and to correct it you can do a replace update function in a sql query then make sure you do a replace(str,"'","''") function on your page requests.
jayrob is offline
View Public Profile
 
Closed Thread     « Reply to Possible SQL Injection attack...i think!!!
 

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off





   
RSS Feed  Feeds: RSS   JS   XML
RSS Feed  Feeds for this forum: RSS   JS   XML



Page generated in 0.35951 seconds with 12 queries