PDA

View Full Version : Was this someone trying to hack?


meissenation
03-24-2012, 09:03 PM
I received two database error e-mails and both of them have the same content - I changed the text to red for the part I'm worried about. It looks like they were trying to inject base64 code inbetween the IMG tags.

I also noticed that the IP address does not match the IP address in the profile for HotRoddCamaro. I did a search of users by IP address with a depth of 2 and it didn't find any matches. I did notice the IP address is local and isn't a chinese address.

Was this someone doing something suspicious as it looks? Base64 in an img code? Just wondering if I should be doing an IP block.


Database error in vBulletin 4.1.10:

Invalid SQL:
INSERT INTO post
(showsignature, allowsmilie, htmlstate, username, userid, title, pagetext, iconid, visible, parentid, threadid, dateline, ipaddress, attach)
VALUES
(0, 1, 'on_nl2br', 'HotRoddCamaro', 3698, '', 'http://www.mifbody.com/vbulletin/image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAlYAAAMgCAIAAAB uy7sgAAAgAElEQVR4nOzd95dcR3Yn+/ ((EDITED DUE TO LENGTH LIMITATIONS)) /+ScueB3ztJQsCHh3QxeS8NdlRwXxK2GetjNHXWyuzVptcAPLWZ g0X2T6mXJVgat8vEyHSrTgQodqtLhEukvoN6Q7dL/A6UsvcdRywcjAAAAAElFTkSuQmCC', 0, 1, 725705, 44903, 1332284140, '24.231.198.41', 0);

MySQL Error : MySQL server has gone away
Error Number : 2006
Request Date : Tuesday, March 20th 2012 @ 10:55:40 PM
Error Date : Tuesday, March 20th 2012 @ 10:56:01 PM
Script : http://www.mifbody.com/vbulletin/newreply.php?do=postreply&t=44903
Referrer : http://www.mifbody.com/vbulletin/showthread.php?44903-New-Member/page2
IP Address : 24.231.198.41
Username : HotRoddCamaro
Classname : vB_Database
MySQL Version :

Reycer
03-24-2012, 09:22 PM
<a href="https://www.vbulletin.com/docs/html/troubleshoot_mysql_goneaway" target="_blank">https://www.vbulletin.com/docs/html/...mysql_goneaway</a>

meissenation
03-24-2012, 10:02 PM
Thanks, but it's not the fact that MySQL "went away" - it's that they put almost 1.5mb worth of text in the https://vborg.vbsupport.ru/ tags in what *looks* like some sort of injection attack with base64 code inbetween the IMG tags. The fact that there was so much code in there is why the server timed out, I understand that.

kh99
03-24-2012, 11:16 PM
It's possible I suppose. But it kind of looks like inline image data, although to be honest I don't know how you'd do that (or even if you're supposed to be able to do it in vbulletin). But since it looks like it's the post contents, I don't see how it could be used as an attack any more than anything else you could include in a post.

Adam H
03-24-2012, 11:20 PM
That normally happens when one of your members are trying to upload an infected image, most of the time they dont even know its infected .

One thing i normally do to stop this is adding "base64" to the censorship options which seems to stop it from being posted. You can also reduce the maximum characters for posts because these strings are often pretty long.

meissenation
03-24-2012, 11:36 PM
Thanks for the idea, Adam. Do you also think it's weird that the IP address does not match the known IP addresses for the username?

I'll add base64 to the censorship option though, I think that's a great idea.

Adam H
03-24-2012, 11:43 PM
Are you looking at the last known IP address on their profile or searching for all IP's used by that user ?

Also if you are using a reverse proxy make sure that IP address isnt your server IP, Although from what i can see the IP in that DB error from from Michigan

meissenation
03-25-2012, 01:27 AM
I tried both last known IP address and also searching for all IPs used by any user and it didn't find any matches. I agree with what you found - it's coming from Flushing, MI which would make sense since the site is Michigan-centric. Just don't know if it was a script kiddie trying something or what.