meissenation
03-24-2012, 09:03 PM
I received two database error e-mails and both of them have the same content - I changed the text to red for the part I'm worried about. It looks like they were trying to inject base64 code inbetween the IMG tags.
I also noticed that the IP address does not match the IP address in the profile for HotRoddCamaro. I did a search of users by IP address with a depth of 2 and it didn't find any matches. I did notice the IP address is local and isn't a chinese address.
Was this someone doing something suspicious as it looks? Base64 in an img code? Just wondering if I should be doing an IP block.
Database error in vBulletin 4.1.10:
Invalid SQL:
INSERT INTO post
(showsignature, allowsmilie, htmlstate, username, userid, title, pagetext, iconid, visible, parentid, threadid, dateline, ipaddress, attach)
VALUES
(0, 1, 'on_nl2br', 'HotRoddCamaro', 3698, '', 'http://www.mifbody.com/vbulletin/image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAlYAAAMgCAIAAAB uy7sgAAAgAElEQVR4nOzd95dcR3Yn+/ ((EDITED DUE TO LENGTH LIMITATIONS)) /+ScueB3ztJQsCHh3QxeS8NdlRwXxK2GetjNHXWyuzVptcAPLWZ g0X2T6mXJVgat8vEyHSrTgQodqtLhEukvoN6Q7dL/A6UsvcdRywcjAAAAAElFTkSuQmCC', 0, 1, 725705, 44903, 1332284140, '24.231.198.41', 0);
MySQL Error : MySQL server has gone away
Error Number : 2006
Request Date : Tuesday, March 20th 2012 @ 10:55:40 PM
Error Date : Tuesday, March 20th 2012 @ 10:56:01 PM
Script : http://www.mifbody.com/vbulletin/newreply.php?do=postreply&t=44903
Referrer : http://www.mifbody.com/vbulletin/showthread.php?44903-New-Member/page2
IP Address : 24.231.198.41
Username : HotRoddCamaro
Classname : vB_Database
MySQL Version :
I also noticed that the IP address does not match the IP address in the profile for HotRoddCamaro. I did a search of users by IP address with a depth of 2 and it didn't find any matches. I did notice the IP address is local and isn't a chinese address.
Was this someone doing something suspicious as it looks? Base64 in an img code? Just wondering if I should be doing an IP block.
Database error in vBulletin 4.1.10:
Invalid SQL:
INSERT INTO post
(showsignature, allowsmilie, htmlstate, username, userid, title, pagetext, iconid, visible, parentid, threadid, dateline, ipaddress, attach)
VALUES
(0, 1, 'on_nl2br', 'HotRoddCamaro', 3698, '', 'http://www.mifbody.com/vbulletin/image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAlYAAAMgCAIAAAB uy7sgAAAgAElEQVR4nOzd95dcR3Yn+/ ((EDITED DUE TO LENGTH LIMITATIONS)) /+ScueB3ztJQsCHh3QxeS8NdlRwXxK2GetjNHXWyuzVptcAPLWZ g0X2T6mXJVgat8vEyHSrTgQodqtLhEukvoN6Q7dL/A6UsvcdRywcjAAAAAElFTkSuQmCC', 0, 1, 725705, 44903, 1332284140, '24.231.198.41', 0);
MySQL Error : MySQL server has gone away
Error Number : 2006
Request Date : Tuesday, March 20th 2012 @ 10:55:40 PM
Error Date : Tuesday, March 20th 2012 @ 10:56:01 PM
Script : http://www.mifbody.com/vbulletin/newreply.php?do=postreply&t=44903
Referrer : http://www.mifbody.com/vbulletin/showthread.php?44903-New-Member/page2
IP Address : 24.231.198.41
Username : HotRoddCamaro
Classname : vB_Database
MySQL Version :