Advertisement
Help Keep Boards Alive. Support us by going ad free today. See here: https://subscriptions.boards.ie/.
If we do not hit our goal we will be forced to close the site.

Current status: https://keepboardsalive.com/

Annual subs are best for most impact. If you are still undecided on going Ad Free - you can also donate using the Paypal Donate option. All contribution helps. Thank you.
https://www.boards.ie/group/1878-subscribers-forum

Private Group for paid up members of Boards.ie. Join the club.

SQl Injection i think

  • 19-10-2009 04:25PM
    #1
    Registered Users, Registered Users 2 Posts: 224 ✭✭


    Hi,

    I just came across a piece of script that has been put into my source code throughout the site...and not by me.

    Im not sure how they did it but im fearing this could get more serious and end up them hitting my db. Here is example(kind of) of the script im finding...


    <script src="Http://www.domainname.com/a/a.php></script&gt;

    HELP!!!!!!


Comments

  • Registered Users, Registered Users 2 Posts: 569 ✭✭✭ifah


    pm me your domain if you want me to take a look...... i can pass on some of my details if you like.


  • Closed Accounts Posts: 751 ✭✭✭JimmyCrackCorn!


    I assume your using a CMS

    Update it and go looking for reports of security holes.


  • Registered Users, Registered Users 2 Posts: 2,534 ✭✭✭FruitLover


    There's also the possibility of a worm on a developer's system capturing FTP/SSH/WebDAV login details.


  • Registered Users, Registered Users 2 Posts: 224 ✭✭The Mighty Dubs


    Hi, i have located the issue but need a hand to fix it.

    Basically the page has <!--#INCLUDE FILE="aaa.asp" --> files in it and i need to encode them. anybody know how i can do this...


  • Closed Accounts Posts: 751 ✭✭✭JimmyCrackCorn!


    Hi, i have located the issue but need a hand to fix it.

    Basically the page has <!--#INCLUDE FILE="aaa.asp" --> files in it and i need to encode them. anybody know how i can do this...

    Thats only part of your issue and you'll find it in the database if you search through it.

    The big issue is fixing how it was done.


  • Advertisement
Advertisement