This is just for really geeky people. Last Friday, someone tried an SQL injection attack in the server to break into it – I’m sure the NSA is way too busy to care about me. The basic idea is you look for a poorly written Php script that takes user input and directly use it without “sanitizing” the data – the attacker tries to add extra SQL “stuff” at the end, initially to get the database to give up the format of its tables, and then to give up the data in those tables. The way I’ve done things, all that happens is I get an email showing me the attempted attack.
So for your viewing pleasure:
IP Address: 199.48.147.37
Remote Host: tor-exit-router37-readme.formlessnetworking.net
SQL Statement:
Select *,app_party.title as atitle from app_party
inner join party on app_party.party_id = party.party_id
inner join party_type on relation = party_type.party_role
where application_id = 1519855
This is where my unsafe script intended for this query to end – because I didn’t sanitize the application ID, they stuck in ths extra “stuff”
and(select 1 from(select count(*),concat((select (select (select distinct concat(0x7e,0x27,column_name,0x27,0x7e) from `information_schema`.columns where table_schema=0x776F72647072657373 and table_name=0x726164696F636861745F636F6D6D656E746D657461 limit 3,1)) from `information_schema`.tables limit 0,1),floor(rand(0)*2))x from `information_schema`.tables group by x)a) and 1=1 order by seq
It’s always something.
Poking around, this is a TOR exit point, which until recently I had banned – TOR is an anonymizer network run to allow people to do things like this that can’t be tracked back to the origin.
Oh, OK. I couldn’t reach the site earlier this evening. So, it wasn’t because you banned me for being a profligate, no-good fer nothing Poster?
oh, that was entirely different. We had a thunderstorm go through chicago around dinner time, and I haven’t gotten around to putting a UPS on the system.
It’s an eMachine and it rebooted to Windoze 7 which don’t know nothing about no linux web server. I then played around trying to get it to shrink the C: partition so I can have 500 GB of disk space for streamingradioguide so I can go crazy, but I failed in my attempt.
Poster? I thought you said Peskov…. as in Dmitri S. Peskov. Did you know that my Peskov is not in charge of plane tickets in Russia? I didn’t either until I read this:
“Dmitri S. Peskov, a spokesman for President Vladimir V. Putin of Russia, said late Sunday that Kremlin officials were not aware of Mr. Snowden’s flight plans.
“We have nothing to do with this story,” he said. “I am not in charge of tickets. I don’t approve or disapprove plane tickets. We are not the proper people to address this question to.”
That is so funny!!!
Earlier today, while cruising around some backcountry roads, I caught a news ‘burp’ that “HorseFace’ Kerry was complaining about the Ruskie (aka Putin) being disingenuous, and not being considerate of following the ‘rules’ by giving Snowden a helping hand to seek asylum in Ecuador.
LOL Yeah , a threat by ‘HorseFace’ .
Putin told Kerry to jump up and Kiss his arse!
LOL
parrott (lower case )
The TOR network is rebanned – buh-bye!
The anarchist is the best friend of the totalitarian. No freedom for you!
Thanks Derf. I have long been worried about TOR getting my personal information from your site- that it why I had spelled my name backwards here – for privacy. I understand that Retsdin did too. — TGBrL121s1CC
I’ll have you know that I spelled my name inside-out, oh Sheet! now I’ve given away everything. Ok, guys, it’s time to shred, burn and ‘move-on’. Oh, gawd! I just mentioned the name of my employer. Dangit.
OK, everyone here, pay no attention to my posts, or that the network mentioned above is actually known as, ROT.
I get a kick out of Kidz who reverse their names for their userid and seemed shocked you figured it out.
ThimsNayr: Hi!
EnotsTra: Hi, Ryan!
ThimsNayr: Huh? Do I know you?
If you like that, you may like the Crab Cannon on pages 206-211 in this book someone scanned. The formatting is a bit off with a few figures inserted in the middle, but it is an entire conversation that is the same in reverse as it is forward. It truly is a work of art from an interesting book, but the Crab Cannon can stand on its own.
http://www.futuretg.com/FTHumanEvolutionCourse/FTFreeLearningKits/01-MA-Mathematics,%20Economics%20and%20Preparation%20for%20University/001-MA01-HI00-High%20School%20Mathematics,%20Preparation%20and%20Recreational%20Science/13%20-%20Recreational%20Science/Douglas%20R.%20Hofstadter%20-%20Godel,%20Escher,%20Bach%20An%20Eternal%20Golden%20Braid.pdf
I’m still assessing what the attack was able to do. I may have to take it down for a few days. If you’re the cautious type and use the same password on the blog and/or the main server login, I would suggest changing it “just in case”. It looks like an automated script kiddy tool. Whether they’re smart enough or care enough to break encrypted passwords, I have no way of knowing.
Will do, Commander. I will run my encryption program for the third time this month for a new password. Actually, this comes at a good time as my assignments require a couple of days of ‘undercover’ work, and this fits the Bill (not my real name).
Okay Llib. I had you pegged for a lib spy.
here was the first probe which arrived via TOR on June 20th
Select *,app_party.title as atitle from app_party
inner join party on app_party.party_id = party.party_id
inner join party_type on relation = party_type.party_role
where application_id = 1519855\’ order by seq
DBcurr fcc
They tested to see if they could fake a close quote – because that threw an SQL, they knew the script was vulerable to attack
Totally related to nothing, other than my lack of attention to the server, since moving the eMachine to chicago, I never turned on log rotation – so the web server log file is currently 10 GB. No wonder I keep running out of disk space
Looking back at the attack, the sequence of events was too fast to be a human – it was just a random attack, probably just started because they found a URL in google with a php style parameter. I don’t see any followup – they didn’t try to grab anything sensitive – I’ve changed the passwords and clamped down on the security in addition to banning the entire TOR network. Things look good enough that I’m going to go eat dinner
Live was so much simpler when it was just Max and the Chief under the Cone of Silence.
Would you believe… 99 is still a hottie!
http://www.youtube.com/watch?v=gi6rVIZ0o0c
Not as hot as 69!
Indeed. A true enlightened spirit. Intelligence is sexy as all get out.