Membership is FREE – with unlimited access to all features, tools, and discussions. Premium accounts get benefits like banner ads and newsletter exposure. ✅ Signature links are now free for all. 🚫 No AI-generated (LLM) posts allowed. Share your own thoughts and experience — accounts may be terminated for violations.

SQL Injection Problem

Status
Not open for further replies.
Joined
May 23, 2007
Posts
871
Reaction score
15
I'm not sure if it's been around long, but there is a big SQL injection thing doing the rounds at the moment, which is infecting lots of database driven websites.

It links back to a javascript page which tries some cross site scripting form this site: www fengnima cn

A quick protection is to add the following two lines to your hosts file (put the dots back in!):

127.0.0.1 www fengnima cn
127.0.0.1 fengnima.cn

you might want to check your database files...
 
Last edited:
I'm fully aware of this bot :( It's very clever in the way it does it.

I've seen it inject script from many different domains, fengnima is just 1 of many I'm afraid.
 
I've got a really persistent portscan hacker on one of my servers. So bad I've had to disable perl. These people are a bloody pest. Somehow gets mysql privileges. It's down to a hole in a php script I think. phpbb was a big culprit at one time. Anyway, it's not on my dropsystem server thank goodness.
 
The one I'm aware of creates a parameter using an @ and it uses the declare statement so I assume it would only affect mssql, however there are stills loads of bots that break out of the SQL statement using an apostrophe which would affect MySQL and other databases.
 
Status
Not open for further replies.

Rule #1: Be Respectful

Do not insult any other member. Be polite and do business. Thank you!

Members online

No members online now.

Premium Members

Latest Comments

New Threads

Domain Forum Friends

Lastest Listings

Our Mods' Businesses

*the exceptional businesses of our esteemed moderators
General chit-chat
Help Users
  • No one is chatting at the moment.
  • Siusaidh AcornBot:
    Siusaidh has left the room.
      Siusaidh AcornBot: Siusaidh has left the room.
      Top Bottom