Tycoon Talk
Become a Big fish!
The number 1 forum for online business!
Post topics, ask questions, share your knowledge.
Tycoon Talk is part of Freelancer.com - find skilled workers online at a fraction of the cost.

The Database Forum


You are currently viewing our The Database Forum as a guest. Please register to participate.
Login



Reply
Help! Will hire if needed...
Old 08-30-2008, 04:39 PM Help! Will hire if needed...
Junior Talker

Posts: 3
Trades: 0
I am a complete beginner at web design of any kind and was really enjoying a classical piano forum I set up using phpBB3. I had about 20 members and conversation was good and then I received this noticed from my web host:

Dear Richard,
Thank you for your message to the support team.

Please see most common queries for user richauv_richauv:

1.Time: 92% (19568 sec)
Amount: 83% (1080 queries)
Rows Examined/Sent: 4.37959e+09 / 0
Avg. Query Exec/Lock Time: 18 / 0 sec.
Used databases: [richauv_pianotechniqueforum]
Query example: use richauv_pianotechniqueforum; SELECT m.word_id FROM phpbb_search_wordmatch m, phpbb_search_wordlist w WHERE w.word_text IN ('100', '1954', '2fear', '3gpp', '403', '60s', '6packbabe', '9080', 'action', 'active', 'activities', 'address', 'adopting', 'adult', 'adulte', 'adulto', 'advance', 'advertising', 'aerobics', 'aficionado', 'africa', 'african', 'agency', 'air', 'airdrie', 'alexis', 'alley', 'alphacool', 'alta', 'altavista', 'altura', 'aluminum', 'amanda', 'amateur', 'amateurs', 'amber', 'american', 'amerikanischer', 'amor', 'amore', 'amoreena', 'amp', 'amsterdam', 'amy', 'anais', 'anal', 'analisis', 'analog', 'analysis', 'anal ... [too long]

You should fix these queries and agree to optimize/normalize your database.

Should you have any further questions, please feel free to contact us anytime, we are available 24/7.

They are reluctant to help me in fixing this problem. They use MySQL accessed through phpMyAdmin. If anyone can instruct me about preventing this type of forum spam, I would really appreciate it. If it's too complicated to teach a beginner, I would be willing to hire for help. Thanks!
richauv is offline
Reply With Quote
View Public Profile
 
 
Register now for full access!
Old 09-01-2008, 06:18 AM Re: Help! Will hire if needed...
chrishirst's Avatar
Missing! presumed drunk.

Posts: 41,517
Name: Chris Hirst
Location: Blackpool. UK
Trades: 0
Looks like a dictionary attack on the forum database, even the dumbest of hosts (and there are a lot) must realise that you are not in control of such queries.

There is probably a way to prevent queries with more than 'X' words in the search pattern being sent to the DB server. The phpBB forums would probably be the best starting point.
__________________
Chris. ->> Links are advertising NOT optimising!! <<-
A foolish consistency is the hobgoblin of little minds
Thought for today:- I SEO the only industry where all the cowboys are Indians?
chrishirst is offline
Reply With Quote
View Public Profile Visit chrishirst's homepage!
 
Old 09-01-2008, 07:45 AM Re: Help! Will hire if needed...
Banned

Posts: 19
Trades: 0
Yes,
i am agree with chrishirst. he have good ideas and i think you follow them. it's very helpful to you
john_opwin is offline
Reply With Quote
View Public Profile
 
Old 09-01-2008, 03:53 PM Re: Help! Will hire if needed...
Learning Newbie's Avatar
Defies a Status

Latest Blog Post:
Astounding Republican Paranoia
Posts: 5,662
Name: John Alexander
Trades: 0
Try changing hosts, and then let's try to figure out how to beat your hacker friend.
__________________

Please login or register to view this content. Registration is FREE


Please login or register to view this content. Registration is FREE
Learning Newbie is offline
Reply With Quote
View Public Profile
 
Old 09-08-2008, 02:37 PM Re: Help! Will hire if needed...
Junior Talker

Posts: 3
Trades: 0
Thank you all so much! I will pursue your advice and come back if more help is needed.
richauv is offline
Reply With Quote
View Public Profile
 
Old 09-13-2008, 05:35 PM Re: Help! Will hire if needed...
Junior Talker

Posts: 3
Trades: 0
I was given some good advice on the phpBB3 forum about settings I can change to prevent this type of attack, but my web host is still insisting that I fix the database before they reactivate the forum. Financial issues prevent me from switching right away and they've been helpful in other matters... Are there any steps I can take to repair remnants of this attack? How can I fix this database or is my web host pulling my leg? Once again, thanks so much!
richauv is offline
Reply With Quote
View Public Profile
 
Old 09-13-2008, 07:02 PM Re: Help! Will hire if needed...
chrishirst's Avatar
Missing! presumed drunk.

Posts: 41,517
Name: Chris Hirst
Location: Blackpool. UK
Trades: 0
They are pulling more than just your leg.

There is nothing to "fix" in the database because the attack is not directly to the DB server, it is being done via the forum search script, so it is the search script that needs "fixing".
And "normalising" the database is simply not something that you can do, unless you want to undertake completely rewriting the forum code.

The bots have probably moved on to a new set of victims by now as well.
__________________
Chris. ->> Links are advertising NOT optimising!! <<-
A foolish consistency is the hobgoblin of little minds
Thought for today:- I SEO the only industry where all the cowboys are Indians?
chrishirst is offline
Reply With Quote
View Public Profile Visit chrishirst's homepage!
 
Old 09-16-2008, 09:34 AM Re: Help! Will hire if needed...
Novice Talker

Posts: 10
Name: Chris
Trades: 0
I have looked for bots to see if I could get one to generate users on my forum to hopefully make it look a bit better for new users so they will talk more but I cant seem to find any, have no idea where these people get them from and what reason they would have to attack unless they are in competition
__________________

Please login or register to view this content. Registration is FREE

Please login or register to view this content. Registration is FREE

Please login or register to view this content. Registration is FREE
gimme4free is offline
Reply With Quote
View Public Profile
 
Reply     « Reply to Help! Will hire if needed...
 

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off





   
RSS Feed  Feeds: RSS   JS   XML
RSS Feed  Feeds for this forum: RSS   JS   XML



Page generated in 1.27943 seconds with 12 queries