Thread: Major Additions - microAUCTIONS (Auction Classifieds)
View Single Post
  #51  
Old 01-02-2010, 08:14 AM
MaryTheG(r)eek MaryTheG(r)eek is offline
 
Join Date: Sep 2006
Location: Greece
Posts: 1,340
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

I'm so happy to say, that someone from IP: 77.54.237.148 is wasting his time to crash my microAUCTIONS in my demo installatin. Below you'll find some of his attempts:
Code:
SELECT * FROM vb4_microauctions_items WHERE active=1 AND sold=0 AND categoryid IN (5, 6, 7, 8, 9, 10, 11, 12, 13) AND (keywords LIKE '';$r = select * from vb4_user;$rr=mysql_fetch_array($r);print_r($rr);%' OR keywords LIKE '%';$r = select * from vb4_user;$rr=mysql_fetch_array($r);print_r($rr);%' OR keywords LIKE '%';$r = select * from vb4_user;$rr=mysql_fetch_array($r);print_r($rr);') ORDER BY ends ASC;
Code:
SELECT * FROM vb4_microauctions_items WHERE active=1 AND sold=0 AND categoryid IN (5, 6, 7, 8, 9, 10, 11, 12, 13) AND (keywords LIKE '';select * from vb4_user;mysql_fetch_array%' OR keywords LIKE '%';select * from vb4_user;mysql_fetch_array%' OR keywords LIKE '%';select * from vb4_user;mysql_fetch_array') ORDER BY ends ASC;
Code:
SELECT * FROM vb4_microauctions_items WHERE active=1 AND sold=0 AND categoryid IN (5, 6, 7, 8, 9, 10, 11, 12, 13) AND (keywords LIKE ';';select * from vb4_user;%' OR keywords LIKE '%;';select * from vb4_user;%' OR keywords LIKE '%;';select * from vb4_user;') ORDER BY ends ASC;
Code:
SELECT * FROM vb4_microauctions_items WHERE active=1 AND sold=0 AND categoryid IN (5, 6, 7, 8, 9, 10, 11, 12, 13) AND (keywords LIKE '';select * from vb4_user;%' OR keywords LIKE '%';select * from vb4_user;%' OR keywords LIKE '%';select * from vb4_user;') ORDER BY ends ASC;
Code:
SELECT * FROM vb4_microauctions_items WHERE active=1 AND sold=0 AND categoryid IN (1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17, 18, 19, 20, 21, 22, 23, 24, 25, 26, 27, 28, 29, 30, 31, 32, 34, 35, 36, 37, 38, 39, 40, 41, 42, 43, 44, 45, 46, 47, 48, 49, 51, 52, 53, 54, 55, 56, 57, 58, 59, 60, 61, 62, 63, 64, 65, 66, 67, 68, 69, 70, 71, 72, 73, 74, 75, 76, 77, 78, 79, 80, 81, 82, 83, 84, 85, 86, 87, 88, 89, 90, 91, 92, 93, 94, 95, 96, 97, 98, 99, 100, 101, 102, 103, 104, 105, 106, 107, 108, 109, 110, 111, 112, 113, 114, 115, 116, 117, 118, 119, 120, 121, 122, 123, 124, 125, 126, 127, 128, 129, 130, 131, 132, 133, 134, 135, 136, 137, 138, 139, 140, 141, 142, 143, 144, 145, 146, 147, 148, 149, 150, 151, 152, 153, 154, 155, 156, 157, 158, 159, 160, 161, 162, 163, 164, 165, 166, 167, 168, 169, 170, 171, 172, 173, 174, 175, 176, 177, 178, 179, 180, 181, 182, 183, 184, 185, 186, 187, 188, 189, 190, 191, 192, 193, 194, 195, 196, 197, 198, 199, 200, 201, 202, 203, 204, 205, 206, 207, 208, 209, 210, 211) AND (location LIKE '<script>alert('Hello World!')</script>%' OR location LIKE '%<script>alert('Hello World!')</script>%' OR location LIKE '%<script>alert('Hello World!')</script>') ORDER BY ends ASC;
Code:
SELECT * FROM vb4_microauctions_items WHERE active=1 AND sold=0 AND categoryid IN (5, 6, 7, 8, 9, 10, 11, 12, 13) AND (keywords LIKE '';select * from vb4_user%' OR keywords LIKE '%';select * from vb4_user%' OR keywords LIKE '%';select * from vb4_user') ORDER BY ends ASC;
Code:
SELECT * FROM vb4_microauctions_items WHERE active=1 AND sold=0 AND categoryid IN (5, 6, 7, 8, 9, 10, 11, 12, 13) AND (keywords LIKE '';drop table vb4_microauctions_items%' OR keywords LIKE '%';drop table vb4_microauctions_items%' OR keywords LIKE '%';drop table vb4_microauctions_items') ORDER BY ends ASC;
...and many others. Of course my demo is still active, but right now I'll get any legal action against him. If someone wants to try security, lets do it on his site.

Maria
Reply With Quote
 
X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.01143 seconds
  • Memory Usage 1,784KB
  • Queries Executed 11 (?)
More Information
Template Usage:
  • (1)SHOWTHREAD_SHOWPOST
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (7)bbcode_code
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)post_thanks_box
  • (1)post_thanks_button
  • (1)post_thanks_javascript
  • (1)post_thanks_navbar_search
  • (1)post_thanks_postbit_info
  • (1)postbit
  • (1)postbit_onlinestatus
  • (1)postbit_wrapper
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • reputationlevel
  • showthread
Included Files:
  • ./showpost.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/functions_bigthree.php
  • ./includes/class_postbit.php
  • ./includes/class_bbcode.php
  • ./includes/functions_reputation.php
  • ./includes/functions_post_thanks.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_postinfo_query
  • fetch_postinfo
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • showpost_start
  • bbcode_fetch_tags
  • bbcode_create
  • postbit_factory
  • showpost_post
  • postbit_display_start
  • post_thanks_function_post_thanks_off_start
  • post_thanks_function_post_thanks_off_end
  • post_thanks_function_fetch_thanks_start
  • post_thanks_function_fetch_thanks_end
  • post_thanks_function_thanked_already_start
  • post_thanks_function_thanked_already_end
  • fetch_musername
  • postbit_imicons
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • postbit_display_complete
  • post_thanks_function_can_thank_this_post_start
  • showpost_complete