Jump to content

Can I find out if someone is doing a SQL injection attack?


Recommended Posts

I have a classifieds script that I run that has a few thousand entries.  The last 2 nights.. out of nowhere, several of my categories (different ones each night) went from over 100 results to 0.  I'm not running any cron jobs of any kind.  I have no idea how these entries just disappeared. 

 

Is there a way I can tell if someone is running sql injection attacks on my site?  Can I check for sql vulnerabilities in my script?  Any other advice as to how I might figure out what's going on?  I host with hostgator.  Is there some auditing I could employ on mysql.. or the site itself? 

 

Many thanks for any suggestions. 

Have you checked your Apache logs for abnormalities? Are you logging MySQL queries anywhere?

 

Install SQLInjectMe for Firefox, and run it against any forms you have on your site. It will non-destructively run tests and report any vulnerabilities it finds.

thx pikachu.  I'll look into installing that addon at home later.  I tried here and it won't work with the latest version of firefox (much like every freaking add-on i ever try to use in firefox). 

 

Thanks for the great tip though.  I've not viewed any logs either.. but I'll definitely start looking into how to do this with hostgator (haven't done much with server admin stuff so it will all be new). 

 

Thanks again!

This thread is more than a year old. Please don't revive it unless you have something important to add.

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Restore formatting

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.