• Sign in / Join

Login

Forgot your password?
Do not have an account ?Register here
X

Register

Have an account?Login here
X
  • Home
  • Blog
  • Image Gallery
  • News Archive
    • Hardware News
    • Gaming News
    • Affiliate News
Trending now

7 Things You NEED to do on…

Why You Can’t Add Storage to Your…

Steam Controller vs Steam Frame: Which One…

E-Day Is Finally Here! | Gears of…

Wireless control for your desk: Is the…

PS6 Leaks, Xbox PS5 Emulation & Steam…

Don’t Fall for the Steam Hardware Myth

Playing Minecraft Dungeons 2 For The First…

How Computers Actually Work: A Beginner’s Guide

Complete Alt Keyboard Code list

OCmodshop.com

  • Hardware
    • Audio
    • Cases
    • Coolers
    • Gadgets
    • Home Theater
    • Input Devices
    • Laptops
    • Memory (RAM)
    • Motherboards
    • Networking
    • Power Supplies
    • Processors (CPU)
    • Storage
    • Video Cards
  • Gaming
    • Gaming Accessories
    • Game Walkthroughs
    • PC Games
    • Xbox
    • Playstation
    • Nintendo
  • Articles
    • How-To Guides
    • Case Mod Projects
    • Software
    • Event Coverage
    • Movies
    • Interviews
  • Podcast
FacebookTwitterYoutubeSpotifyTwitchSteam
Blog

SQL Injection Attack

by Alan McCloskeyDecember 19, 2007August 25, 2014087
Share0

We had a SQL injection attack on 12/11.

 
They didn’t delete anything… but they did create a new table in the news database.  I looked it up and apparently they were trying out a popular script to see if it would work.
 
I’ve since updated all exposed parts of the site to have read-only access… so if someone does try to append SQL injection code then it won’t execute.
I need to scrub some SQL, but when I first tried replacing single quotes it messes up any single quotes from legitimate input boxes…

I don’t think I pissed anyone off… this script was probably just to see if it would work…

The new accounts should work fine… I’ve never had any intrusions on the .NET app, but the ASP apps seem to be a little more venerable.

I’m putting up a hardware firewall to close off ports, too…

Yeah, most of the form input stuff is cleaned… there are other ways to do a SQL injection (which I’m not going to post for obvious reasons). I was venerable by using the same full-access login for reading the database… now all public parts of the site use a read-only login. Hopefully that will stop any SQL injection attacks.

I’m not a security expert by any means, but limiting the access should nip that in the bud. Anyone who wanted to hack my SQL would really really have to know what they’re doing.

Post Views: 174
HackerSQLShare0
previous post
Turok for Xbox 360 Preview
next post
GMC Noblesse AVC-S7 HTPC Case Review
Alan McCloskey
Alan is a web architect, stand-up comedian, and your friendly neighborhood Grammar Nerd. You can stalk him on the Interwebs via Facebook and follow him on X @ocmodshop.

Related posts

Epicor Announces Support for SQL Server “Denali”

NewsJuly 13, 2011June 29, 2014

Veritas Backup Exec 9.1 Review

BrandonSeptember 1, 2004July 25, 2014

Latest podcast

Join the OCmodshop NewsletterJoin the newsletter!

Recent Posts

  • 7 Things You NEED to do on Your Steam Deck
  • Why You Can’t Add Storage to Your Phone Anymore
  • Steam Controller vs Steam Frame: Which One Actually Works?
  • E-Day Is Finally Here! | Gears of War Live Stream
  • Wireless control for your desk: Is the Ulanzi D100H worth it?
  • PS6 Leaks, Xbox PS5 Emulation & Steam Frame Analysis (1 MILLION VIEWS SPECIAL!) | Ocmodcast ep 21
  • Don’t Fall for the Steam Hardware Myth
  • Playing Minecraft Dungeons 2 For The First Time
OCmodshop.com
FacebookTwitterYoutubeSpotifyTwitchSteam
@2026 - ocmodshop.com. All Right Reserved.
  • About Us
  • Terms of Use / Privacy Policy
  • Copyrights
  • Our Rating System
  • Publish an Article on OCmodshop
  • Contest Rules
OCmodshop.com
FacebookTwitterYoutubeSpotifyTwitchSteam
  • Hardware
    • Audio
    • Cases
    • Coolers
    • Gadgets
    • Home Theater
    • Input Devices
    • Laptops
    • Memory (RAM)
    • Motherboards
    • Networking
    • Power Supplies
    • Processors (CPU)
    • Storage
    • Video Cards
  • Gaming
    • Gaming Accessories
    • Game Walkthroughs
    • PC Games
    • Xbox
    • Playstation
    • Nintendo
  • Articles
    • How-To Guides
    • Case Mod Projects
    • Software
    • Event Coverage
    • Movies
    • Interviews
  • Podcast
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}