1
Cuidiu
Hacking or MySQL Injection Attempt?
  • 2007/8/23 14:22

  • Cuidiu

  • Quite a regular

  • Posts: 358

  • Since: 2006/4/23


Suddenly I have a ton of the following in my error log from a variety of IPs.
modules/newbb/index.php+++++++++++++++++++++++Result:+%E8%F1%EF%EE%EB%FC%E7%F3%E5%EC+SOCKS+12.214.222.88:20107;%E7%E0%F0%E5%E3%E8%F1%F2%F0%E8%F0%EE%E2%E0%EB%E8%F1%FC;%E2%EE%F8%EB%E8;%F0%E5%E6%E8%EC+PM_LOGIN;%E2%EE%E7%EC%EE%E6%ED%EE,+%F0%E5%E3%E8%F1%F2%F0%E0%F6%E8%FF+%ED%E5+%F3%E4%E0%EB%E0%F1%FC+%28%E2%FB%F1%EB%E0%ED+%EA%EE%E4+%E0%EA%F2%E8%E2%E0%F6%E8%E8+/+%E8%F1%EF%EE%EB%FC%E7%F3%E5%F2%F1%FF+%E4%EE%EF%EE%EB%ED%E8%F2%E5%EB%FC%ED%E0%FF+%E7%E0%F9%E8%F2%E0+/+%F1%E1%EE%E9+%E2+%F0%E0%E1%EE%F2%E5+%F4%EE%F0%F3%EC%E0+/+...%29;

I haven't seen it before today. Is this an old vulnerability or something new?
[size=x-small]Working sites:
XOOPS 2.0.16 PHP 5.2.2, MySQL 5.0.24a-standard-log, Apache/2.0.54 (Unix)
XOOPS 2.2.4, PHP 4.3.10, MySQL 3.23.58, Apache/1.3.33 (Unix)[/size]

2
Mestophales
Re: Hacking or MySQL Injection Attempt?

I recently got hacked by an old version of the sadmind worm. and got similar log entries - it shut my site down and I endud up having to delete and start over

3
McDonald
Re: Hacking or MySQL Injection Attempt?
  • 2007/8/23 15:07

  • McDonald

  • Home away from home

  • Posts: 1072

  • Since: 2005/8/15


What versions (Xoops and Newbb) are you both using?

And, do you have the module Protector installed?

4
Cuidiu
Re: Hacking or MySQL Injection Attempt?
  • 2007/8/23 15:57

  • Cuidiu

  • Quite a regular

  • Posts: 358

  • Since: 2006/4/23


Quote:
McDonald wrote:
What versions (Xoops and Newbb) are you both using?

Most recent for both.

Quote:
And, do you have the module Protector installed?

Absolutely. No record was found in Protector for these attempts. I was surprised but thought perhaps it's not the level Protector would be concerned about OR it's a new vulnerability/hack and not yet documented. But I don't know much about Protector so...
[size=x-small]Working sites:
XOOPS 2.0.16 PHP 5.2.2, MySQL 5.0.24a-standard-log, Apache/2.0.54 (Unix)
XOOPS 2.2.4, PHP 4.3.10, MySQL 3.23.58, Apache/1.3.33 (Unix)[/size]

Login

Who's Online

160 user(s) are online (109 user(s) are browsing Support Forums)


Members: 0


Guests: 160


more...

Donat-O-Meter

Stats
Goal: $100.00
Due Date: Apr 30
Gross Amount: $0.00
Net Balance: $0.00
Left to go: $100.00
Make donations with PayPal!

Latest GitHub Commits