• Sign in / Join

Login

Forgot your password?
Do not have an account ?Register here
X

Register

Have an account?Login here
X
  • Home
  • Blog
  • Image Gallery
  • News Archive
    • Hardware News
    • Gaming News
    • Affiliate News
Trending now

Disc Rot Is Real and Here’s Why…

The OCmodcast now on Spotify

AYN Thor Hands On The DS Successor…

Steam Frame vs Meta Quest 3 Specs…

Ending Physical Games Redefines Piracy, Windows Gaming…

Your Game Discs Will Self Destruct

These Forgotten Xbox Games Are Now On…

Transform Standard Video to Smooth High Frame…

Microsoft’s own AI datacenters may be the…

You Can Play 3D Games on Steam…

OCmodshop.com

  • Hardware
    • Audio
    • Cases
    • Coolers
    • Gadgets
    • Home Theater
    • Input Devices
    • Laptops
    • Memory (RAM)
    • Motherboards
    • Networking
    • Power Supplies
    • Processors (CPU)
    • Storage
    • Video Cards
  • Gaming
    • Gaming Accessories
    • Game Walkthroughs
    • PC Games
    • Xbox
    • Playstation
    • Nintendo
  • Articles
    • How-To Guides
    • Case Mod Projects
    • Software
    • Event Coverage
    • Movies
    • Interviews
  • Podcast
FacebookTwitterYoutubeSpotifyTwitchSteam
Blog

SQL Injection Attack

by Alan McCloskeyDecember 19, 2007August 25, 2014026
Share0

We had a SQL injection attack on 12/11.

 
They didn’t delete anything… but they did create a new table in the news database.  I looked it up and apparently they were trying out a popular script to see if it would work.
 
I’ve since updated all exposed parts of the site to have read-only access… so if someone does try to append SQL injection code then it won’t execute.
I need to scrub some SQL, but when I first tried replacing single quotes it messes up any single quotes from legitimate input boxes…

I don’t think I pissed anyone off… this script was probably just to see if it would work…

The new accounts should work fine… I’ve never had any intrusions on the .NET app, but the ASP apps seem to be a little more venerable.

I’m putting up a hardware firewall to close off ports, too…

Yeah, most of the form input stuff is cleaned… there are other ways to do a SQL injection (which I’m not going to post for obvious reasons). I was venerable by using the same full-access login for reading the database… now all public parts of the site use a read-only login. Hopefully that will stop any SQL injection attacks.

I’m not a security expert by any means, but limiting the access should nip that in the bud. Anyone who wanted to hack my SQL would really really have to know what they’re doing.

Post Views: 54
HackerSQLShare0
previous post
Turok for Xbox 360 Preview
next post
GMC Noblesse AVC-S7 HTPC Case Review
Alan McCloskey
Alan is a web architect, stand-up comedian, and your friendly neighborhood Grammar Nerd. You can stalk him on the Interwebs via Facebook and follow him on X @ocmodshop.

Related posts

Epicor Announces Support for SQL Server “Denali”

NewsJuly 13, 2011June 29, 2014

Veritas Backup Exec 9.1 Review

BrandonSeptember 1, 2004July 25, 2014

Latest podcast

Recent Posts

  • Disc Rot Is Real and Here’s Why Deniers Are Wrong | OCmodcast 13
  • The OCmodcast now on Spotify
  • AYN Thor Hands On The DS Successor Nobody Expected
  • Steam Frame vs Meta Quest 3 Specs – The Real Differences
  • Ending Physical Games Redefines Piracy, Windows Gaming Getting Worse | OCmodcast Episode 12
  • Your Game Discs Will Self Destruct
  • These Forgotten Xbox Games Are Now On PC
  • Transform Standard Video to Smooth High Frame Rate
OCmodshop.com
FacebookTwitterYoutubeSpotifyTwitchSteam
@2026 - ocmodshop.com. All Right Reserved.
  • About Us
  • Terms of Use / Privacy Policy
  • Copyrights
  • Our Rating System
  • Publish an Article on OCmodshop
  • Contest Rules
OCmodshop.com
FacebookTwitterYoutubeSpotifyTwitchSteam
  • Hardware
    • Audio
    • Cases
    • Coolers
    • Gadgets
    • Home Theater
    • Input Devices
    • Laptops
    • Memory (RAM)
    • Motherboards
    • Networking
    • Power Supplies
    • Processors (CPU)
    • Storage
    • Video Cards
  • Gaming
    • Gaming Accessories
    • Game Walkthroughs
    • PC Games
    • Xbox
    • Playstation
    • Nintendo
  • Articles
    • How-To Guides
    • Case Mod Projects
    • Software
    • Event Coverage
    • Movies
    • Interviews
  • Podcast
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}