Advertisement

05.16.2008 at 06:14PM PDT, ID: 23410083
[x]
Attachment Details

SQL INJECTION REMOVAL

Asked by hibridassassin in SQL Server 2005, Databases Miscellaneous, MS SQL Server

Tags: MICROSOFT, SQL SERVER, 2005 Standard, SQL, SQL SERVER 2005 Standard

My website was compromised today and now every time I load a page from the database, the website download a Trojan horse to the user's computers.  At first I was not sure if it was the code on the site or the database but I did a restore on a back-up copy of my database and the problem was fixed.  Unfortunately, I have a week worth of data that I CANNOT lose on those tables otherwise I would just do a restore and be done with it.  Where should I look to try and find this malicious code?  For example, if I do a Select * query on a table, regardless of the table, the virus starts to download.  By the way, the virus file is not on my server, it downloads it from http://firestnamestea.cn/q.js after it executes that js file, it proceeds to download a ton of malware on the users computer.  The removal of the virus in the users computer is easy enough but where do can I look to find the malicious code in my SQL Server?  Thanks.Start Free Trial
[+][-]05.17.2008 at 12:57AM PDT, ID: 21588339

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]05.17.2008 at 01:42AM PDT, ID: 21588459

View this solution now by starting your 7-day free trial. Setting up your free trial is quick, easy, and secure. We will return you to this solution, unlocked, when you're done.

 

About this solution

Zones: SQL Server 2005, Databases Miscellaneous, MS SQL Server
Tags: MICROSOFT, SQL SERVER, 2005 Standard, SQL, SQL SERVER 2005 Standard
Sign Up Now!
Solution Provided By: cs97jjm3
Participating Experts: 2
Solution Grade: A
 
 
 
Loading Advertisement...
20080716-EE-VQP-32 / EE_QW_2_20070628