• Sign in / Join

Login

Forgot your password?
Do not have an account ?Register here
X

Register

Have an account?Login here
X
  • Home
  • Blog
  • Image Gallery
  • News Archive
    • Hardware News
    • Gaming News
    • Affiliate News
Trending now

Steam Frame, Digital Ownership, and You! |…

I Can’t Believe Shift At Midnight Exists..…

Halo Campaign Gets a Massive Upgrade (4K…

Halo: Campaign Evolved just dropped

Steam Frame is Coming – Here’s What…

Xbox Disc to Digital – What They’re…

Honey-Roasted Gaming news

The Reason Steam Frame Will Clobber Meta

800,000 Views on YouTube channel

New time for podcast

OCmodshop.com

  • Hardware
    • Audio
    • Cases
    • Coolers
    • Gadgets
    • Home Theater
    • Input Devices
    • Laptops
    • Memory (RAM)
    • Motherboards
    • Networking
    • Power Supplies
    • Processors (CPU)
    • Storage
    • Video Cards
  • Gaming
    • Gaming Accessories
    • Game Walkthroughs
    • PC Games
    • Xbox
    • Playstation
    • Nintendo
  • Articles
    • How-To Guides
    • Case Mod Projects
    • Software
    • Event Coverage
    • Movies
    • Interviews
  • Podcast
FacebookTwitterYoutubeTwitchSteam
Blog

SQL Injection Attack

by Alan McCloskeyDecember 19, 2007August 25, 2014010
Share0

We had a SQL injection attack on 12/11.

 
They didn’t delete anything… but they did create a new table in the news database.  I looked it up and apparently they were trying out a popular script to see if it would work.
 
I’ve since updated all exposed parts of the site to have read-only access… so if someone does try to append SQL injection code then it won’t execute.
I need to scrub some SQL, but when I first tried replacing single quotes it messes up any single quotes from legitimate input boxes…

I don’t think I pissed anyone off… this script was probably just to see if it would work…

The new accounts should work fine… I’ve never had any intrusions on the .NET app, but the ASP apps seem to be a little more venerable.

I’m putting up a hardware firewall to close off ports, too…

Yeah, most of the form input stuff is cleaned… there are other ways to do a SQL injection (which I’m not going to post for obvious reasons). I was venerable by using the same full-access login for reading the database… now all public parts of the site use a read-only login. Hopefully that will stop any SQL injection attacks.

I’m not a security expert by any means, but limiting the access should nip that in the bud. Anyone who wanted to hack my SQL would really really have to know what they’re doing.

Post Views: 16
HackerSQLShare0
previous post
Turok for Xbox 360 Preview
next post
GMC Noblesse AVC-S7 HTPC Case Review
Alan McCloskey
Alan is a web architect, stand-up comedian, and your friendly neighborhood Grammar Nerd. You can stalk him on the Interwebs via Facebook and follow him on X @ocmodshop.

Related posts

Epicor Announces Support for SQL Server “Denali”

NewsJuly 13, 2011June 29, 2014

Veritas Backup Exec 9.1 Review

BrandonSeptember 1, 2004July 25, 2014

Recent Posts

  • Steam Frame, Digital Ownership, and You! | Ocmodcast Episode 11
  • I Can’t Believe Shift At Midnight Exists.. This Game is INSANE
  • Halo Campaign Gets a Massive Upgrade (4K video)
  • Halo: Campaign Evolved just dropped
  • Steam Frame is Coming – Here’s What to Expect
OCmodshop.com
FacebookTwitterYoutubeTwitchSteam
@2026 - ocmodshop.com. All Right Reserved.
  • About Us
  • Terms of Use / Privacy Policy
  • Copyrights
  • Our Rating System
  • Publish an Article on OCmodshop
  • Contest Rules
OCmodshop.com
FacebookTwitterYoutubeTwitchSteam
  • Hardware
    • Audio
    • Cases
    • Coolers
    • Gadgets
    • Home Theater
    • Input Devices
    • Laptops
    • Memory (RAM)
    • Motherboards
    • Networking
    • Power Supplies
    • Processors (CPU)
    • Storage
    • Video Cards
  • Gaming
    • Gaming Accessories
    • Game Walkthroughs
    • PC Games
    • Xbox
    • Playstation
    • Nintendo
  • Articles
    • How-To Guides
    • Case Mod Projects
    • Software
    • Event Coverage
    • Movies
    • Interviews
  • Podcast
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}