KnowledgeHub
Questions
Tags
Users
Search
Alex Rivera
|
Logout
Edit Question
Title
Body
Did anybody know more information about this attack ? I recently got this script injected in my web sites By the way dont go on this web site since it's the source of the infection </title><script src=http://google-stats50.**fo/***.php> What kind of attack is it, SQL or CODE ? By the way dont go on this web site since it's the source of the infection The question is by what quind of attack this infectious attack occurs ? We found it, and was not like twitter attack, it's was by request parameters in a url and inject sql directly in the parameter. There is the SQL script produce by our sql team to clean your database who was infected /************************************************************************* SQL INJECTED DATABASE *************************************************************************/ DECLARE @dbName VARCHAR(200), @SqlString NVARCHAR(MAX), @SearchText VARCHAR(MAX), @SearchTextLike VARCHAR(MAX), @NbItems INT, @TableName VARCHAR(255), @ColoneName VARCHAR(255), @objId BIGINT, @tmpSqlString NVARCHAR(MAX), @CleanUp BIT, @RowCount BIGINT, @debug BIT, @Msg VARCHAR(MAX); SET @debug = 0; -- 1 = Additionnal prints SET @CleanUp = 0; -- 1 = Update tables SET @SearchText = '</title><script src=http://google-stats50.info/ur.php></script>'; SET @SearchTextLike = '%' + @SearchText + '%'; DECLARE @QueryResults TABLE (SqlString VARCHAR(MAX), TableName VARCHAR(255), ColoneName VARCHAR(255)); DECLARE @InfectedDB TABLE (InfectedDbName VARCHAR(255)); DECLARE @CleanedUpDB TABLE (DbName VARCHAR(255), Msg VARCHAR(MAX)); DECLARE @DbToValidate TABLE (DbName VARCHAR(255)); INSERT INTO @DbToValidate SELECT Name FROM sys.databases WHERE [state] = 0 AND Name NOT IN ('master
Tags (comma-separated)
Save Edits
Cancel