Solved

How to detect and clean an SQL Injection

Posted on 2008-06-22
2
1,211 Views
Last Modified: 2008-10-27
Hi,

I believe that we have been hit with an SQL injection attack. At the top of our website page it has the following;

<script src=http://www.chinabnr.com/b.js></script>

Can you tell me how to detect and clean if this is the case.??

TIA

Lee
0
Comment
Question by:Lee025_
2 Comments
 
LVL 12

Expert Comment

by:patrikt
ID: 21844359
If it is realy comming from outside atack you have to fix all hole in your applications.
Every textbox without validataion can be hole to SQL if it is used insorrectly.
I can give you guiodelines for this but you have to do¨cleaning manualy.

As I know there is no automatic test tool, but somone may know about it.

Patrik
0
 
LVL 1

Accepted Solution

by:
rezen earned 500 total points
ID: 21849587
Same thing happened to me. Damn Chinese hackers!

What I did was run the SQL code here: http://alexduggleby.com/2008/05/09/off-topic-t-sql-replace-all-occurrences-in-all-columns-in-all-tables/

This allowed me to generate a sql script that parses all my tables and erases all the the injected text in all character storing columns.

NOTE:
The code on the guy's site is not entirely working. I had to erase a smiley tag and fix the comments. Once it ran, it generated all the update statements needed. Make sure you tweak the code to replace the '<script...' with an empty string: ''
Also note that this does not clean NTEXT columns, which are affected by the SQL Injection. What I did was convert all my NTEXT columns to VARCHAR(MAX) [supported in SQL Server 2005].

Good luck, and don't forget to fix your vulnerabilities.
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Oracle DB monitor SW 21 48
best counters for cpu high usage 3 30
Live Storage Vmotion VMs with shared VMDK 10 57
Get the latest status 8 31
I wrote this interesting script that really help me find jobs or procedures when working in a huge environment. I could I have written it as a Procedure but then I would have to have it on each machine or have a link to a server-related search that …
The Delta outage: 650 cancelled flights, more than 1200 delayed flights, thousands of frustrated customers, tens of millions of dollars in damages – plus untold reputational damage to one of the world’s most trusted airlines. All due to a catastroph…
Familiarize people with the process of retrieving data from SQL Server using an Access pass-thru query. Microsoft Access is a very powerful client/server development tool. One of the ways that you can retrieve data from a SQL Server is by using a pa…
Viewers will learn how to use the SELECT statement in SQL to return specific rows and columns, with various degrees of sorting and limits in place.

772 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question