What an SQL injection attack looks like

This is just for really geeky people. Last Friday, someone tried an SQL injection attack in the server to break into it – I’m sure the NSA is way too busy to care about me. The basic idea is you look for a poorly written Php script that takes user input and directly use it without “sanitizing” the data – the attacker tries to add extra SQL “stuff” at the end, initially to get the database to give up the format of its tables, and then to give up the data in those tables. The way I’ve done things, all that happens is I get an email showing me the attempted attack.

So for your viewing pleasure:

IP Address: 199.48.147.37
Remote Host: tor-exit-router37-readme.formlessnetworking.net

SQL Statement:

Select *,app_party.title as atitle from app_party
inner join party on app_party.party_id = party.party_id
inner join party_type on relation = party_type.party_role
where application_id = 1519855

This is where my unsafe script intended for this query to end – because I didn’t sanitize the application ID, they stuck in ths extra “stuff”

and(select 1 from(select count(*),concat((select (select (select distinct concat(0x7e,0x27,column_name,0x27,0x7e) from `information_schema`.columns where table_schema=0x776F72647072657373 and table_name=0x726164696F636861745F636F6D6D656E746D657461 limit 3,1)) from `information_schema`.tables limit 0,1),floor(rand(0)*2))x from `information_schema`.tables group by x)a) and 1=1 order by seq

It’s always something.

Poking around, this is a TOR exit point, which until recently I had banned – TOR is an anonymizer network run to allow people to do things like this that can’t be tracked back to the origin.

This entry was posted in About the Guide. Bookmark the permalink.

20 Responses to What an SQL injection attack looks like

  1. Nidster says:

    Oh, OK. I couldn’t reach the site earlier this evening. So, it wasn’t because you banned me for being a profligate, no-good fer nothing Poster?

    • Art Stone says:

      oh, that was entirely different. We had a thunderstorm go through chicago around dinner time, and I haven’t gotten around to putting a UPS on the system.

      It’s an eMachine and it rebooted to Windoze 7 which don’t know nothing about no linux web server. I then played around trying to get it to shrink the C: partition so I can have 500 GB of disk space for streamingradioguide so I can go crazy, but I failed in my attempt.

    • CC1s121LrBGT says:

      Poster? I thought you said Peskov…. as in Dmitri S. Peskov. Did you know that my Peskov is not in charge of plane tickets in Russia? I didn’t either until I read this:

      “Dmitri S. Peskov, a spokesman for President Vladimir V. Putin of Russia, said late Sunday that Kremlin officials were not aware of Mr. Snowden’s flight plans.

      “We have nothing to do with this story,” he said. “I am not in charge of tickets. I don’t approve or disapprove plane tickets. We are not the proper people to address this question to.”

      • Nidster says:

        That is so funny!!!

        Earlier today, while cruising around some backcountry roads, I caught a news ‘burp’ that “HorseFace’ Kerry was complaining about the Ruskie (aka Putin) being disingenuous, and not being considerate of following the ‘rules’ by giving Snowden a helping hand to seek asylum in Ecuador.

  2. Art Stone says:

    The TOR network is rebanned – buh-bye!

    The anarchist is the best friend of the totalitarian. No freedom for you!

  3. CC1s121LrBGT says:

    Thanks Derf. I have long been worried about TOR getting my personal information from your site- that it why I had spelled my name backwards here – for privacy. I understand that Retsdin did too. — TGBrL121s1CC

  4. Art Stone says:

    I’m still assessing what the attack was able to do. I may have to take it down for a few days. If you’re the cautious type and use the same password on the blog and/or the main server login, I would suggest changing it “just in case”. It looks like an automated script kiddy tool. Whether they’re smart enough or care enough to break encrypted passwords, I have no way of knowing.

  5. Art Stone says:

    here was the first probe which arrived via TOR on June 20th

    Select *,app_party.title as atitle from app_party
    inner join party on app_party.party_id = party.party_id
    inner join party_type on relation = party_type.party_role
    where application_id = 1519855\’ order by seq
    DBcurr fcc

    They tested to see if they could fake a close quote – because that threw an SQL, they knew the script was vulerable to attack

  6. Art Stone says:

    Totally related to nothing, other than my lack of attention to the server, since moving the eMachine to chicago, I never turned on log rotation – so the web server log file is currently 10 GB. No wonder I keep running out of disk space

    Looking back at the attack, the sequence of events was too fast to be a human – it was just a random attack, probably just started because they found a URL in google with a php style parameter. I don’t see any followup – they didn’t try to grab anything sensitive – I’ve changed the passwords and clamped down on the security in addition to banning the entire TOR network. Things look good enough that I’m going to go eat dinner

  7. HPaws says:

    Live was so much simpler when it was just Max and the Chief under the Cone of Silence.

Leave a Reply