Oh no! Where's the JavaScript?
Your Web browser does not have JavaScript enabled or does not support JavaScript. Please enable JavaScript on your Web browser to properly view this Web site, or upgrade to a Web browser that does support JavaScript.
Not a member yet? Click here to register.
Forgot Password?

An Attack from China?

Asked Modified Viewed 2,930 times
M
Masy
M
Masy 10
  • Newbie, joined since
  • Contributed 4 posts on the community forums.
  • Started 1 thread in the forums
  • Started this discussions
asked
Newbie

I'm using the guest tracking panel from the skpacman.

On the 16 of juli 2012 with the ip-address: 114.227.10.78 the following url/uri's came in:

07:01:47: '/photogallery.php?album_id=6%20and%201=1%20and%20='
07:01:46: '/photogallery.php?album_id=6%20%61%6E%64%20%31%3D%32'
07:01:45: '/photogallery.php?album_id=6%20%61%6E%64%20%31%3D%31'
07:01:44: '/photogallery.php?album_id=6%20and%20char124%2Buser%2Bchar124=0%20and%20%25='
07:01:43: '/photogallery.php?album_id=6%20and%20char124%2Buser%2Bchar124=0'
07:01:41: '/photogallery.php?album_id=6%20and%20char124%2Buser%2Bchar124=0%20and%20='

The ip-address is from "Chinanet Jiangsu Province Network"... Ehh???
And looking at the time-table -just seconds-: Nobody can copy and past that fast...
It is a programm or robot working, crawling...

I checked up my database and with FTP my PHPFusion files on my providers root, checking out the file-dates on the 2012-07-16. Nothing did change...

==============
Tip against attacks:
Change the dates of all the PHPFusion-files once a month to that date. So all the files have the same date. If after that one file has another date, it is time to examine that file...
==============

So, I think the above was an attack, trying to corrupt my database...

But what nobody can tell me is what the codes in these url/uri's mean? What is that **** all about?

Like to hear some more...

Greetings,
Masy from the Netherlands
0 replies

5 posts

P
PolarFox
P
  • Veteran Member, joined since
  • Contributed 1,633 posts on the community forums.
  • Started 29 threads in the forums
answered
Veteran Member

Any files/data-s changed?
0 replies
M
Martijn78
M
euhh...
  • Member, joined since
  • Contributed 107 posts on the community forums.
  • Started 25 threads in the forums
answered
Member

We've had an attack from Romania. 640 files where changed on 13-11-2012 around 01.00 am...

Sinowal-malware.... No database hack...
0 replies
G
Geri
G
Geri 10
  • Junior Member, joined since
  • Contributed 24 posts on the community forums.
  • Started 7 threads in the forums
answered
Junior Member

i deleted photogallery.php, thankyou for the warning
0 replies
P
PolarFox
P
  • Veteran Member, joined since
  • Contributed 1,633 posts on the community forums.
  • Started 29 threads in the forums
answered
Veteran Member

Nothing suspicious, without correct logs.
0 replies
C
Craig
C
Craig 14
  • Fusioneer, joined since
  • Contributed 4,462 posts on the community forums.
  • Started 212 threads in the forums
answered
Fusioneer

Just do a block on China unless you really need Chinese visitors.
0 replies

Labels

None yet

Statistics

  • Views 0 views
  • Posts 5 posts
  • Votes 0 votes
  • Topic users 5 members

5 participants

M
M
euhh...
  • Member, joined since
  • Contributed 107 posts on the community forums.
  • Started 25 threads in the forums
C
C
Craig 14
  • Fusioneer, joined since
  • Contributed 4,462 posts on the community forums.
  • Started 212 threads in the forums
P
P
  • Veteran Member, joined since
  • Contributed 1,633 posts on the community forums.
  • Started 29 threads in the forums
G
G
Geri 10
  • Junior Member, joined since
  • Contributed 24 posts on the community forums.
  • Started 7 threads in the forums
M
M
Masy 10
  • Newbie, joined since
  • Contributed 4 posts on the community forums.
  • Started 1 thread in the forums
  • Started this discussions

Notifications

Track thread

You are not receiving notifications from this thread.

Related Questions

Not yet