The Arcive of Official vBulletin Modifications Site.It is not a VB3 engine, just a parsed copy! |
|
#1
|
|||
|
|||
How to Stop SQL Queries from hackers?
Some guy keeps injecting random stuff into our root.
He recently injected a txt file that said "test.txt" How are people doing this and how to stop things like this from happening? |
#2
|
|||
|
|||
Well I understand there is a point. To solve this I'm all alone in first on the question mark in talking about the need to see the contents of the test.txt file. vbulletin sql injection system, usually being taken from search.php and index.php. CPU or ceiling, of course yaptırıyor pruning. pursuant to it can enter into the system.
|
#3
|
||||
|
||||
if you're getting files, it's probably not SQL, but writable (chmod 777) directories.
|
#4
|
||||
|
||||
You should have taken a look at your access_logs from that day to see if it really is sql injection. Then, take a look at your server logs to see who is logging in to your server. This should be done the day it happens though since sometimes hosts don't keep this information around for long.
|
|
|
X vBulletin 3.8.12 by vBS Debug Information | |
---|---|
|
|
More Information | |
Template Usage:
Phrase Groups Available:
|
Included Files:
Hooks Called:
|