![]() |
|
|||||||
| Register | FAQ | Members List | Downloads | Calendar | Today's Posts | Search | Webmaster Resources | Webmaster Blogs |
![]() |
|
|
LinkBack | Thread Tools | Display Modes |
|
|||||
|
Today I have already released a security solution at iwt, but now i will post one for here as well. You need to know that it was developped in the last ten minutes, but very effective. The basic would be the same as it was posted at iwt with less modification.
The sql injection is very popular hacking method but there is one common thing in these type of attacks. According to this resource, the URL contains a string which cause a bad manipulation of the sql database, for instance the 'UNION SELECT', 'DROP TABLE', 'TRUNCATE TABLE' sql commands as the part of the requested url. For instance my directory was hacked requesting this string Quote:
1. Create a php file i would call this validator.php with the following content. PHP Code:
2. Create our logfile the blacklist which is called in my example bannolnilog.txt (to ban in Hungarian) chmod 644. Upload it to the root folder as you did it with the validator.php file. 3. We have the validator and the logfile so we need to create the message.php I use this censored content as message PHP Code:
4 We already have everything, the message the logfile and the validator, all we need to do is to place the invitation of the validator file to the very front of your script. PHP Code:
![]()
__________________
█Time may come when you will need a shopping cart █digitális mérleg keresőoptimalizálás Last edited by Bagi Zoltán; 12-28-2007 at 02:05 PM. Reason: completed the code |
|
|||||
|
Great tutorial Bagi - rep added
![]() I will be digging this post when I get home as I can no longer access digg from work
__________________
Last edited by gkd_uk; 12-28-2007 at 02:18 PM. |
|
|||||
|
Thank iou Imran, meanwhile i completed the script with some other different malicious sql commands.
__________________
█Time may come when you will need a shopping cart █digitális mérleg keresőoptimalizálás |
|
|||||
|
That is great Bagi! Thank you very much, this may come to good use and I have added you rep for your efforts.
Thanks, Meti |
|
|||||
|
I can see how this works internally (the script and stopping injections), but how do you
implement it? I am a member of the WordPress Dev. email list, and a member just posted that his WordPress was attacked with this type of hack. His Host informed him of a few details, but not much else. He lost all data in the db! So how do we use your script for protection? |
|
|||||
|
Martin, you have a certain script. Before the connection would established to the database, in the case of wordpress this is the 1.st row of the given header.php in the template files you need to make the validator run using this
Quote:
![]()
__________________
█Time may come when you will need a shopping cart █digitális mérleg keresőoptimalizálás |
|
|||||
|
Excellent Bagi, You are a king of Kings
![]() |
|
|||||
|
Don't think that Resonate, i only should have learned instead of script hacking
![]()
__________________
█Time may come when you will need a shopping cart █digitális mérleg keresőoptimalizálás |
|
|||||
|
Quote:
![]() |
|
|||||
|
Please post your finding Bagi! I'm going to use this on one or two of my blogs that get
allot of spam. Not that this is a spam deterrent, but those sites seem to be "targeted" - and a hack attack would be the next avenue for those people! |
![]() |
| Bookmarks |
| Webmaster Resources |
|
• UK WW SEO Tools • Find UK Hosts |
| The Forum Rules |
|
• Forum Rules - MUST READ |
| Site Of the Month |
![]() Nominate site of the month |
|
|