You are missing our premiere tool bar navigation system! Register and use it for FREE!

NukeCops  
•  Home •  Downloads •  Gallery •  Your Account •  Forums • 
Readme First
- Readme First! -

Read and follow the rules, otherwise your posts will be closed
Modules
· Home
· FAQ
· Buy a Theme
· Advertising
· AvantGo
· Bookmarks
· Columbia
· Community
· Donations
· Downloads
· Feedback
· Forums
· PHP-Nuke HOWTO
· Private Messages
· Search
· Statistics
· Stories Archive
· Submit News
· Surveys
· Theme Gallery
· Top
· Topics
· Your Account
Who's Online
There are currently, 42 guest(s) and 0 member(s) that are online.

You are Anonymous user. You can register for free by clicking here
Nuke Cops :: View topic - Protector saved us again, & again & again & ... [ ]
 Forum FAQ  •  Search  •   •  Memberlist  •  Usergroups   •  Register  •  Profile •    •  Log in to check your private messages  •  Log in

 
This forum is locked: you cannot post, reply to, or edit topics.  This topic is locked: you cannot edit posts or make replies.printer-friendly view
View previous topic Log in to check your private messages View next topic
Author Message
sandman229
Sergeant
Sergeant


Joined: Jul 28, 2003
Posts: 102

Location: Victorville, Ca.

PostPosted: Mon Jul 19, 2004 9:20 pm Reply with quoteBack to top

It seems several people have been trying to attack my wifes site. I've had 4 attacks the last two days. 2 from the same ISP.. They are trying the SQL injection. Hmmmm I don't have the code here with me at the moment.

Protector has banned them.

69.19.254.112
168.226.248.7
168.226.129.193
209.237.238.176

I'll post what they were sending tomorrow.

_________________
Sandman
Image
http://www.kittykorp.com and http://www.katpaws.com
Find all posts by sandman229View user's profileSend private messageSend e-mailVisit poster's websiteYahoo MessengerMSN MessengerICQ Number
sandman229
Sergeant
Sergeant


Joined: Jul 28, 2003
Posts: 102

Location: Victorville, Ca.

PostPosted: Tue Jul 20, 2004 12:58 am Reply with quoteBack to top

Here is what they sent:

modules.php?name=search&type=stories&query=f00bar&category=-1&categ= and 1=2 UNI0N select 0,0,aid,pwd,0,0,0,0,0,0 from nuke_authors/*

Thats 1.

modules.php?name=search&type=stories&query=f00bar&category=-1&categ= and 1=2 UNI0N select 0,0,aid,pwd,0,0,0,0,0,0 from nuke_authors/*

Thats 2

And there were others just like that..

_________________
Sandman
Image
http://www.kittykorp.com and http://www.katpaws.com
Find all posts by sandman229View user's profileSend private messageSend e-mailVisit poster's websiteYahoo MessengerMSN MessengerICQ Number
Evaders99
Site Admin
Site Admin


Joined: Aug 17, 2003
Posts: 12373


PostPosted: Tue Jul 20, 2004 7:25 pm Reply with quoteBack to top

I wouldn't post those here. Let more kiddies can easy access to them.

Anyway, these are known UNION attacks and are fixed in the Patched files.

_________________
Helping those that help themselves
Read FIRST or DIE!

"Fighting is terrible, but not as terrible as losing the will to fight."
Star Wars Rebellion Network - Need Help? Evaders Squadron Coding
Find all posts by Evaders99View user's profileSend private messageVisit poster's websiteAIM Address
evilshorty
Nuke Cadet
Nuke Cadet


Joined: Jul 20, 2004
Posts: 8


PostPosted: Tue Jul 20, 2004 7:31 pm Reply with quoteBack to top

well all that union is really doing is trying to overflow and bypass your databases....I keep up with alot of the vulnerabilities of nuke and SQL and it wouldnt take but a google search to get to these hacker sites which tell you to do these things...I wouldnt worry about it much. (posting it that is) but worry about people doing this Razz Laughing
Find all posts by evilshortyView user's profileSend private message
Darrell3831
Captain
Captain


Joined: Jan 05, 2004
Posts: 425


PostPosted: Wed Jul 21, 2004 3:20 am Reply with quoteBack to top

Quote:
overflow and bypass your databases


Hi,

I could be wrong, but it appears to me that they are trying to select your aid and password from your database. Not overflow it or bypass it.

Quote:
select 0,0,aid,pwd,0,0,0,0,0,0 from nuke_authors


When they try the buffer overflow error your email from Protector will be very long and contain a huge string of usually hexidecimal characters. That's the string they used to try and overflow it.

The buffer overflow hack is more a MySQL hack than a Nuke one.

Darrell

_________________
http://www.psy-center.com
Find all posts by Darrell3831View user's profileSend private messageVisit poster's website
evilshorty
Nuke Cadet
Nuke Cadet


Joined: Jul 20, 2004
Posts: 8


PostPosted: Wed Jul 21, 2004 12:37 pm Reply with quoteBack to top

Lol by databases I meant MySQL...this is rather new so people should watch out for anything along that line of code! Very Happy



*edit* ps.. it is a MySQL overflow/bypass exploit...want a link? Razz didnt think so Razz
Find all posts by evilshortyView user's profileSend private message
Darrell3831
Captain
Captain


Joined: Jan 05, 2004
Posts: 425


PostPosted: Thu Jul 22, 2004 4:30 am Reply with quoteBack to top

Quote:
*edit* ps.. it is a MySQL overflow/bypass exploit...want a link? didnt think so


EvilShorty,

The attack posted in this thread is known by most people as a UNION exploit. However your more than welcome to name it anything you like.

Quote:
modules.php?name=search&type=stories&query=f00bar&category=-1&categ= and 1=2 UNI0N select 0,0,aid,pwd,0,0,0,0,0,0 from nuke_authors/*


If you look at the syntax the attacker used here, you can see they are trying to piggyback an extended query via a UNION which SELECTS items from the nuke.authors table. Namely the aid and pw of records in the nuke.authors table.

On a succesful attck using this or similar exploits the attacker gets your aid and password. Then they can log into your admin section as you and change things on your site.

The MySQL buffer never overflows with this exploit. Even on systems that are vulnerable to buffer overflows.

The size of the MySQL buffer is thousands of characters long on most versions of MySQL. This entire query/hack is only a few characters long. There is no danger of overflowing any buffer in any version of MySQL that I know of with only a few characters.

If an attacker is probing your site to see if you have a version of MySQL that is vulnerable to buffer overflows they must pass enough characters in the query to actually overflow the buffer. You will know when you have had one of these exploits because the query string will be huge. Thousands of characters long.

If your query isent longer than the buffer on vulnerable version of MySQL nothing will happen.

The term bypass in your description is only remotely applicable in the sense that they are attempting to bypass your nuke security.

You had asked if I wanted a link earlier. I presume you meant to some place where a person has chosen to name a union exploit as a overflow/bypass exploit. That won't be necessary, but thanks for offering. I respect their right to name it anything they choose and concede to your assertion that they have.

Darrell
Find all posts by Darrell3831View user's profileSend private messageVisit poster's website
Display posts from previous:      
This forum is locked: you cannot post, reply to, or edit topics.  This topic is locked: you cannot edit posts or make replies.printer-friendly view
View previous topic Log in to check your private messages View next topic
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum



Powered by phpBB © 2001, 2005 phpBB Group

Ported by Nuke Cops © 2003 www.nukecops.com
:: FI Theme :: PHP-Nuke theme by coldblooded (www.nukemods.com) ::
Powered by · TOGETHER TEAM srl ITALY http://www.togetherteam.it · DONDELEO E-COMMERCE http://www.DonDeLeo.com
Web site engine's code is Copyright © 2002 by PHP-Nuke. All Rights Reserved. PHP-Nuke is Free Software released under the GNU/GPL license.
Page Generation: 0.199 Seconds - 286 pages served in past 5 minutes. Nuke Cops Founded by Paul Laudanski (Zhen-Xjell)
:: FI Theme :: PHP-Nuke theme by coldblooded (www.nukemods.com) ::