![]() |
woke up to this WordPress hack - any ideas?
guys submitted a whole lotta stuff to a members area blog on of our sologirls writes her diary on
Comment: [email protected]" and "1"="1 any idea what this is? their held for mod so np but I still like to know. thanks :thumbsup OH and the obligatory pic :) http://dutchteengalleries.com/bb/70/images/4.jpg |
Quote:
|
I think the use of quotes is an attempt to see if you are open for MYSQL injection. I could be wrong.
EDIT: Sands hit it before me. I suck. |
Nice obligatory pic. ;)
|
all comments lemme post a few
[email protected] and 1=1 66535 -1.0 "" acunetix_wvs_invalid_filename ../../../../../../../../etc/passwd |
Quote:
he commented like 40-50 times some .AR IP no member |
Quote:
I wouldn't freak out about it. Just take some safety precautions, and you'll be fine. :thumbsup |
Quote:
The first one looks like an SQL injection vulnerability test or fragment of a failed SQL injection. Seems they're trying a few other attack vectors too. |
I totally missed the question...
|
I'm not an expert, but I imagine the latest WP is pretty damned invulnerable to simple injection attacks. Looks like they are trying to find default password files and obvious sql vulnerabilities.
Probably some script kiddies. |
thanks all guys
ill send this to mojo they do backups all the time though - so np at all still anything to prevent something funny is welcome :) |
Quote:
The "1"="1" makes any SQL query you do evaluate to true which gives the hacker access to all data in the SQL database. |
Quote:
|
If its a members area blog as you say, it should be easy to find. Or at least know what username, IP and CC used
|
no comment on the hack attempt, but i like the pic ;)
|
nice pic for sure
|
Very cute girl..
Shut down comments for a few days |
Quote:
The php code written in the site script allows the exploit. |
Anyway kudos for the tits.
|
All times are GMT -7. The time now is 04:53 PM. |
Powered by vBulletin® Version 3.8.8
Copyright ©2000 - 2025, vBulletin Solutions, Inc.
©2000-, AI Media Network Inc