Page 1 of 3 123 LastLast
Results 1 to 10 of 23
  1. #1

    Default Someone's attempt to sql inject my site - not!!! Hahahaha


    Please open this link on your browsers.

    You'll see some commands sent by someone who's trying to MYSQL INJECT my site.
    I already prepared for it... I really appreciate his efforts.

    this url address ------> fanonychan.com/bulletin.php?id=88

    I didn't remove the messages, I like everybody to see how things goes. hahahaha!!!!

    LESSON:
    Always make trace logs on your databases.


    here is the log:



    As you can see, the time difference is very close... difference is 1 minute. You'll see that he is changing I.P. addresses within those two minutes. While he's performing SQL commands, and the same time, he's chaning I.P. addresses. He is using 2 IP addresses. That means he is using 2 PCs at that time.

    It seems my database didn't have any damages.

  2. #2
    Thats why you should use hard passcode for your databases and cpanel

    Dugay na na nga problems sa Mysql with linux uy.

    @ BGSA Web Hosting Services

  3. #3
    Dodie.. who inject it? hehehehe... maybe some bot out there

  4. #4
    Quote Originally Posted by RU9halogen View Post
    Dodie.. who inject it? hehehehe... maybe some bot out there
    Whatever it is human or bot....

    The way i see it, it's a human attempting to perform, see the IP addresses.

  5. #5
    ka hambogero pud nimo dodie sure ka dili na ma injectan imo website? you must be a god hahahahaha

  6. #6
    sure ka dods? Hehehehe, naa ko patirahon sa imong site, just give me a go signal, para masugdan dayon? Hehehehe

  7. #7
    hhhmmmm... thanks guys to the recent events of my stupid site. I made this site also for this purpose.
    I did some tweaking, I traced all my logs into it. I did notice some actions I haven't trapped all.... sorry for that. hahaha

    This is a good step to improve website development. yay!!!!

    @CHAOSORB
    If you can inject it, let me know... I'll improve the trapping, if it is successful, I'd be happy to share it to you and everyone.
    You have until Wednesday, don't go beyond that.

    let's help together improving our sites
    Report here, this is a new learning!!!! yey

  8. #8
    @ChaosOrb Please inject, I want you to test this. You have until Wednesday, then report back here.


    As of now on this site.......to enforce all input strings into valid numbers.

    example:
    $getsamplevar=(double)$getsamplevar;

    explaination:
    '1somethingsomething' will transform into '1'

    '1' is a valid numerical to 1

    '1' and 1 are not equal. But they are equal during convertion.


    is_numerical() php internal function
    With the help of this function, I can check that if it s a valid number.

  9. #9
    LOL!~~~~! wala ko ka gets.. nsa e inject?

  10. #10
    yep unsa na? hehe
    Last edited by r0mm3L; 02-08-2009 at 11:19 AM.

  11.    Advertisement

Page 1 of 3 123 LastLast

Similar Threads

 
  1. need someone to fix/repair my psp
    By tikong008 in forum Gizmos & Gadgets (Old)
    Replies: 6
    Last Post: 02-09-2009, 07:47 PM
  2. Planning to put photos under my site's name
    By edblogs in forum Websites & Multimedia
    Replies: 7
    Last Post: 03-20-2008, 09:47 AM
  3. How to determine if my site is blocked from google?
    By har86vey in forum Websites & Multimedia
    Replies: 1
    Last Post: 03-13-2008, 11:46 AM
  4. Replies: 2
    Last Post: 12-17-2007, 03:59 AM
  5. Why's the default link to my site is changed to disney.com?
    By Empress_Of_Drac in forum Support Center
    Replies: 2
    Last Post: 05-23-2006, 05:25 AM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
about us
We are the first Cebu Online Media.

iSTORYA.NET is Cebu's Biggest, Southern Philippines' Most Active, and the Philippines' Strongest Online Community!
follow us
#top